> Markdown version of [/jobs/ext/2696447-software-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/2696447-software-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Vulnerability Analyst - **Company:** Greenhouse Software, Inc. - **Location:** Linthicum Heights, MD, United States - **Salary:** $147,867.0 - $221,801.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Artificial Intelligence, C++ (Programming Language), Cyber Security, Computer Engineering, Python (Programming Language), Linux System Administration, Machine Learning, Reverse Engineering, WinDBg, Software Verification, Information Technology, IDA Pro, Software Coding, Operating System Security, GPT, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://job-boards.greenhouse.io/twosixtechnologies/jobs/6179491004 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience). * Demonstrated experience in static and dynamic reverse engineering, binary patch diffing (e.g., BinDiff, Diaphora), and software vulnerability analysis. * Hands-on proficiency with disassembly tools (Ghidra, IDA Pro, or Binary Ninja) and software debuggers (GDB, WinDbg). * Proven track record performing root-cause analysis on software vulnerabilities and validating patch mitigation effectiveness. * Strong programming and scripting skills in C, C++, and Python within Linux environments. * Ability to provide on-site support in Linthicum, Maryland daily Nice to have (preferred) * Experience applying AI/ML models or LLM frameworks to software code analysis, vulnerability discovery, or patch verification. * Familiarity with dynamic instrumentation frameworks (Frida, DynamoRIO) or automated fuzzing engines. * Knowledge of operating system security mitigations (ASLR, DEP, CFI, Stack Canaries) and common vulnerability patterns (CWEs). Security Clearance: * Active TS/SCI clearance with Polygraph required ## Description * Evaluate software and firmware patches to perform binary patch diffing and root-cause vulnerability analysis in support of national security research missions. * Work under minimal supervision with latitude for independent judgment to confirm patch integrity and ensure security fixes completely address target vulnerabilities. * Document detailed analytical findings, validate security fixes, and assist with integrating AI-assisted software verification tools into security analysis workflows., Website LinkedIn Profile Are you eligible for a DoD security clearance?* Select... For more information on clearances, review this document. Security Clearance * Select... Desired Salary* Select... Have you worked for Two Six Technologies or an affiliate in the past? If so, please provide the name of the team you supported and dates of employment.* Are you a current or former direct employee of any government institutions (including any governmental entities at the federal/national, state/provincial, and local levels and including publicly funded institutions)?* Select... Are you currently bound by any non-compete or employment agreement?* Select... How did you hear about us?* If you were referred by an Employee, please list their name. Please provide your Legal Name * Are you legally authorized to work in the United States?* Select... Do you now, or will you in the future, require company sponsorship for an employment visa? (e.g. H-1B, E-3, TN status)* Select... Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. As set forth in Two Six Technologies's Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law. Gender* Select... Are you Hispanic/Latino?* Select... Race & Ethnicity Definitions If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows: A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability. A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service. An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense. An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985. Veteran Status* Select... ## Related Videos - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) - [Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) - [Speak, Code, Deploy: Transforming Developer Experience with Voice Commands](https://www.wearedevelopers.com/videos/1159-speak-code-deploy-transforming-developer-experience-with-voice-commands) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers)