Two Six Technologies is actively seeking a Software Vulnerability Analyst to join our Trusted Electronics and Effects team in Linthicum, Maryland. The team is composed of intelligent individuals, passionate about binary patch diffing, root-cause vulnerability analysis, and software security validation. The team is growing and looking for someone with a vulnerability analysis and reverse engineering background who has an understanding of how to analyze software patches, verify security fixes, and confirm vulnerability mitigation across target systems. If you are actively using Ghidra, IDA Pro, BinDiff, and dynamic analysis tools, the team wants to talk to you!
What you will do
Evaluate software and firmware patches to perform binary patch diffing and root-cause vulnerability analysis in support of national security research missions.
Work under minimal supervision with latitude for independent judgment to confirm patch integrity and ensure security fixes completely address target vulnerabilities.
Document detailed analytical findings, validate security fixes, and assist with integrating AI-assisted software verification tools into security analysis workflows.
What you will need (basic qualifications)
Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience).
Demonstrated experience in static and dynamic reverse engineering, binary patch diffing (e.g., BinDiff, Diaphora), and software vulnerability analysis.
Hands-on proficiency with disassembly tools (Ghidra, IDA Pro, or Binary Ninja) and software debuggers (GDB, WinDbg).
Proven track record performing root-cause analysis on software vulnerabilities and validating patch mitigation effectiveness.
Strong programming and scripting skills in C, C++, and Python within Linux environments.
Ability to provide on-site support in Linthicum, Maryland daily
Nice to have (preferred)
Experience applying AI/ML models or LLM frameworks to software code analysis, vulnerability discovery, or patch verification.
Familiarity with dynamic instrumentation frameworks (Frida, DynamoRIO) or automated fuzzing engines.
Knowledge of operating system security mitigations (ASLR, DEP, CFI, Stack Canaries) and common vulnerability patterns (CWEs).
Security Clearance:
Active TS/SCI clearance with Polygraph required
#LI-ZS1
#LI-ONSITE
Numbers & Facts
Location
Linthicum, MD
Skills
Analysis Skillsunmatched
Artificial Intelligence (AI)unmatched
C Programming Languageunmatched
C++ Programming Languageunmatched
Computer Engineeringunmatched
Computer Firmwareunmatched
Computer Programmingunmatched
Computer Scienceunmatched
Computer Securityunmatched
Disassemblersunmatched
Dynamic Analysisunmatched
Electronicsunmatched
Fuzz Testingunmatched
GDB (Gnu Debugger)unmatched
IDA Prounmatched
Instrumentationunmatched
Internet Securityunmatched
Linux Operating Systemunmatched
On Site Supportunmatched
Python Programming/Scripting Languageunmatched
Reverse Engineeringunmatched
Root Cause Analysisunmatched
Scripting (Scripting Languages)unmatched
Security Analysisunmatched
Security Patchesunmatched
Software Debuggingunmatched
Software Evaluationunmatched
Software Patchesunmatched
Software Validationunmatched
WinDbgunmatched
Workflow Analysisunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.