> Markdown version of [/jobs/ext/1280720-junior-vulnerability-researcher-cloud-containers](https://www.wearedevelopers.com/jobs/ext/1280720-junior-vulnerability-researcher-cloud-containers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Vulnerability Researcher (Cloud & Containers) - **Company:** CACI International Inc. - **Location:** Florham Park, NJ, United States - **Experience:** Starter - **Salary:** $79,400.0 - $162,700.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, C++ (Programming Language), Cloud Computing, Cloud Computing Security, Software Debugging, Distributed Systems, Firmware, Fuzz Testing, Python (Programming Language), Linux Kernel, Packet Analyzer, Program Analysis, Reverse Engineering, Software Engineering, Wireshark, Scripting, Kubernetes, IDA Pro, Oracle Cloud Infrastructure, Vulnerability Analysis - **Published:** July 15, 2026 - **Apply:** https://dejobs.org/x/x/35B7A8E23AA941BFBBBDE90F9D69C507/job/ ## About the Role Required: An active Top Secret clearance. 3-5 years of professional experience in vulnerability research, reverse engineering, or systems-level software development. Proficiency in Go, Rust, or C/C++ and strong scripting skills in Python3 . Experience with disassembly and decompilation tools such as IDA Pro, Ghidra, or Binary Ninja . Working knowledge of Linux kernel internals , specifically regarding container isolation (namespaces/cgroups). Hands-on experience with debugging tools like GDB and packet analysis tools like Wireshark . Familiarity with container orchestration (Kubernetes) and the OCI runtime specification. Demonstrated ability to conduct independent technical research and document complex findings. Desired: An active SCI clearance. Previous experience with fuzzing frameworks and vulnerability discovery in distributed systems. Understanding of x86 or ARM assembly language. Experience with cloud provider security (AWS, Azure, or GCP). Relevant security certifications or a history of participation in advanced CTF competitions. ## Description We are seeking a Vulnerability Researcher with a strong background in systems-level engineering and a passion for cloud security. This role is for a practitioner who has moved beyond the basics and is ready to take ownership of research tasks within the "DNA of the cloud." You will apply your knowledge of container internals and binary analysis to hunt for escapes and logic flaws in Kubernetes environments. You will work as part of a high-performing team, executing complex vulnerability research and developing automated tools to secure national cybersecurity infrastructure., Execute research into OCI runtimes (runc, crun) and Linux kernel primitives (namespaces, cgroups) to identify breakout and privilege escalation paths. Perform static and dynamic analysis on compiled binaries (Go, Rust, or C++) to map logic and identify potential security vulnerabilities. Develop and maintain custom fuzzing harnesses (e.g., AFL++, libFuzzer) to stress-test gRPC interfaces and microservice components. Use symbolic and concolic execution tools (e.g., Angr, Manticore) to automate the discovery of complex execution paths. Analyze containerized environments and system initialization logic to identify and document potential attack surfaces. Write custom Python3 scripts to automate research workflows, including firmware unpacking and memory analysis. Generate detailed technical reports and documentation for discovered vulnerabilities and research methodology. ## Related Videos - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)