Software Vulnerability Analyst
Overview of Opportunity
Two Six Technologies is actively seeking a Software Vulnerability Analyst to join our Trusted Electronics and Effects team in Linthicum, Maryland. The team is composed of intelligent individuals, passionate about binary patch diffing, root-cause vulnerability analysis, and software security validation. The team is growing and looking for someone with a vulnerability analysis and reverse engineering background who has an understanding of how to analyze software patches, verify security fixes, and confirm vulnerability mitigation across target systems. If you are actively using Ghidra, IDA Pro, BinDiff, and dynamic analysis tools, the team wants to talk to you!
What you will do
Evaluate software and firmware patches to perform binary patch diffing and root-cause vulnerability analysis in support of national security research missions.
Work under minimal supervision with latitude for independent judgment to confirm patch integrity and ensure security fixes completely address target vulnerabilities.
Document detailed analytical findings, validate security fixes, and assist with integrating AI-assisted software verification tools into security analysis workflows.
What you will need (basic qualifications)
Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience).
Demonstrated experience in static and dynamic reverse engineering, binary patch diffing (e.g., BinDiff, Diaphora), and software vulnerability analysis.
Hands-on proficiency with disassembly tools (Ghidra, IDA Pro, or Binary Ninja) and software debuggers (GDB, WinDbg).
Proven track record performing root-cause analysis on software vulnerabilities and validating patch mitigation effectiveness.
Strong programming and scripting skills in C, C++, and Python within Linux environments.
Ability to provide on-site support in Linthicum, Maryland daily
Nice to have (preferred)
Experience applying AI/ML models or LLM frameworks to software code analysis, vulnerability discovery, or patch verification.
Familiarity with dynamic instrumentation frameworks (Frida, DynamoRIO) or automated fuzzing engines.
Knowledge of operating system security mitigations (ASLR, DEP, CFI, Stack Canaries) and common vulnerability patterns (CWEs).
Security Clearance:
Active TS/SCI clearance with Polygraph required
#LI-ZS1
#LI-ONSITE
Two Six Technologies is committed to providing competitive and comprehensive compensation packages that reflect the value we place on our employees and their contributions. We believe in rewarding skills, experience, and performance. Our offerings include but are not limited to, medical, dental, and vision insurance, life and disability insurance, retirement benefits, paid leave, tuition assistance and professional development.
The projected salary range listed for this position is annualized. This is a general guideline and not a guarantee of salary. Salary is one component of our total compensation package and the specific salary offered is determined by various factors, including, but not limited to education, experience, knowledge, skills, geographic location, as well as contract specific affordability and organizational requirements.
Salary Range
$147,867—$221,801 USD