> Markdown version of [/jobs/ext/1282942-senior-vulnerability-researcher-cloud-containers](https://www.wearedevelopers.com/jobs/ext/1282942-senior-vulnerability-researcher-cloud-containers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Vulnerability Researcher (Cloud & Containers) - **Company:** CACI International Inc. - **Location:** Florham Park, NJ, United States - **Experience:** Expert - **Salary:** $113,200.0 - $237,800.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, C++ (Programming Language), Cloud Computing, Software Debugging, Distributed Systems, Python (Programming Language), Linux Kernel, Program Analysis, Istio, Containerization, Kubernetes, IDA Pro, Linkerd (Service Mesh), Oracle Cloud Infrastructure, Vulnerability Analysis, Microservices - **Published:** July 15, 2026 - **Apply:** https://dejobs.org/x/x/57F8282317F848EF88CC727352D7FCD7/job/ ## About the Role We are seeking a Senior Vulnerability Researcher with deep expertise in cloud-native architecture, container runtimes, and advanced binary analysis. This role is ideal for a low-level expert who thrives on technical ambiguity and enjoys hunting for vulnerabilities within the "DNA of the cloud." You will use automated reasoning and manual deep-dives to uncover escapes and logic flaws in Kubernetes infrastructure, playing a key role in evaluating the security of critical distributed systems and contributing directly to national cybersecurity efforts., Required : An active Top Secret clearance. 7+ years of professional experience in vulnerability research, software exploitation, or low-level engineering. Expert-level proficiency in Go, Rust, and C/C++. Strong command of Python3 for scripting and automation of research tasks. Deep understanding of x86/ARM assembly and memory corruption primitives. Proven track record of finding vulnerabilities in distributed systems, virtualization layers, or container runtimes. Hands-on experience with disassembly and decompilation tools (e.g., IDA Pro, Ghidra, Binary Ninja) and debugging tools (GDB). Detailed understanding of Linux kernel internals, specifically namespaces, cgroups, and the container execution model. Experience with automated bug-hunting techniques, including fuzzing and symbolic/concolic execution. Desired: An active SCI clearance is highly desired. Experience with Kubernetes security architecture and service mesh implementations (Istio, Linkerd). Familiarity with hardware-assisted isolation technologies and TEEs (Trusted Execution Environments). Ability to build scalable security tooling and infrastructure to support analysis workflows in a team setting. Background in cloud provider security (AWS, Azure, or GCP) and underlying hypervisor technology. ## Description Conduct deep-dive research into OCI runtimes (runc, crun) and Linux kernel primitives (namespaces, cgroups, eBPF) to identify breakout and privilege escalation paths. Perform static and dynamic analysis on compiled binaries (Go, Rust, C++) using IDA Pro, Ghidra, or Binary Ninja to map undocumented logic and potential security issues. Build and maintain custom fuzzing harnesses (e.g., AFL++, libFuzzer) to stress-test gRPC interfaces, service mesh components, and microservices. Utilize concolic execution tools (e.g., Angr, Manticore) to automate the discovery of complex execution paths and bypass security checks. Investigate edge-case behaviors in containerized environments and low-level system initialization logic to reveal hidden attack surfaces. Develop custom tools and scripts (primarily in Python3) to automate research workflows, protocol decoding, and memory analysis. Document findings clearly and translate technical complexity into actionable reports for security and engineering teams. ## Related Videos - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [From Build to Breach: Hacking Kubernetes Through the Supply Chain](https://www.wearedevelopers.com/videos/100183-from-build-to-breach-hacking-kubernetes-through-the-supply-chain) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)