Posted 14 days ago
Description
Meet The Team
As a member ofTalos, you will supportgroundbreakingdetection and mitigation technologies.You will work towards keeping yourself abreast of the latestindustry threat creation and defense techniques, and you willdevelop proof-of-concept solutions, provide domainexpertiseand guide implementation tofacilitatesuccessfulsecurity posture in ofCisco’s products.
If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this job is for you!
Your Impact
Security research including development of tools for vulnerability analysis and mitigation.
Development of static and run-time analysis tools to figure out root cause and input conditions related toa vulnerability.
Vulnerability triage and proof of concept exploit development to support the creation of detection content.
Writedetailed technical reports, summaries, and testing methodologies
Research emerging technologies, protocols, and testing methodologies
Develop proof of concept exploits fortesting vulnerability mitigations
Perform patch analysis to find and trigger vulnerabilities.
Reverseengineerbinary applications, protocols, and formats.
Analyze vulnerabilities and emerging security threats and technologies.
Provide critical security focusedexpertiseto engineering organizations
Minimum Qualifications
10+ years of experience in vulnerability research or a closely related areasuch asexploitor mitigation developmenton Linux Systems
5+ years’ experience with C/C++, and a scripting language (e.g., Python), and assembly (e.g., x86/x64, ARM, etc.)
Preferred Qualifications
Bachelor’s degree or equivalent in Computer Science, Electrical Engineering, Cyber Security, or other tech-related degree
Experience withLinux internals
Experience with binary auditing and reverse engineering, and with related tools such as IDA Pro, Binary Ninja,Ghidra, etc. and with plugin development.
Experience with common vulnerabilities and methods of exploitation, such as memory corruption, web application exploitation, file format vulnerabilities, protocol-based weaknesses, etc.
Knowledge of common file formats,network protocol structures, and enterprise networking architecture
Ability to work independently with minimum supervision and to addressadditionaltasks as the need arises.