CyberSecurity Researcher
Must-have:CloudMobileSecurity
Security Researcher
The Security Researcher will conduct security research, vulnerability discovery, penetration testing, and security evaluations across IoT devices, embedded systems, networking equipment, mobile devices, cloud services, and software applications.
The role involves identifying and validating security vulnerabilities, developing proof-of-concept demonstrations, performing root cause analysis, and contributing to product security certifications and compliance assessments.
Key Responsibilities
- Conduct security research and security assessments across IoT, embedded, networking, mobile, cloud, and software platforms.
- Perform penetration testing using black-box, grey-box, and white-box methodologies.
- Identify, analyse, and validate vulnerabilities through reverse engineering, fuzzing, protocol analysis, and proof-of-concept development.
- Develop security testing methodologies, tools, and automation to enhance assessment capabilities.
- Conduct root cause analysis and document technical findings.
- Prepare clear technical reports and communicate findings to clients, vendors, and stakeholders.
Requirements
- Understanding of networking, operating systems, and core cybersecurity concepts.
- Experience in security testing, reverse engineering, vulnerability research, CTFs, bug bounty programmes, academic research, or personal security projects.
- Familiarity with tools such as Burp Suite, Wireshark, Nmap, Ghidra, Binwalk, Frida, IDA Pro , or equivalent.
- Strong analytical and problem-solving skills, with the ability to independently investigate technical security issues.
- Strong technical writing and communication skills, including the ability to explain findings to both technical and non-technical stakeholders.
Desirable Experience
- Vulnerability discovery, validation, responsible disclosure, or CVE-related work.
- Development of proof-of-concept exploits, demonstrations, or security research tools.
- Experience with IoT devices, embedded systems, networking equipment, mobile devices, or cloud-connected products.
- Firmware extraction, firmware analysis, and reverse engineering.
- Knowledge of ARM, MIPS, or RISC-V architectures.
- Web application, API, mobile, wireless, network, or firmware security assessments.
- Experience with fuzzing, protocol analysis, threat modelling, or security tooling.
- Security research publications, conference presentations, open-source contributions, CTF achievements, or recognised vulnerability acknowledgements.