Staff Cyber Software Engineer at Northrop Grumman
Cincinnati, OH
$177,000–$265,600from the description
Jun 28, 2026
Cincinnati, OH
Jul 21, 2026
What this job asks for AI summary
A senior vulnerability research role focused on reverse engineering embedded systems, analyzing user and kernel mode drivers, and building proof-of-concept exploits from research findings. The work sits within offensive cyber operations, requiring deep familiarity with disassembly tools, fuzzing techniques, and low-level programming. Suited to experienced engineers with a strong background in C/C++ and binary analysis who can obtain a Top Secret clearance.
Senior level · 7+ years · Cincinnati, OH · Bachelor's required · Top Secret clearance · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $114,300 (middle half $82,600–$139,670). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (13)
The posting title says 'Senior level Vulnerability Research Engineer' but the Basic Qualifications header reads 'Staff Cyber Software Engineer' — the title framing is Senior, but the qualifications block label suggests Staff. The role has been classified as Senior based on the title and the nature of the work; the Staff label in the qualifications header appears to be a copy-paste artifact.
The experience requirement is tiered: B.S. + 12 years, M.S. + 10 years, or Ph.D. + 7 years. The minimum (Ph.D. path) is 7 years, which is used for the overall years minimum; the most common path (B.S.) requires 12 years.
The degree requirement is set to Bachelor's as the minimum formal degree stated; however, the JD accepts equivalent advanced degrees with fewer years, and a Ph.D. path is also offered.
The clearance field reflects the JD's stated requirement to 'obtain and maintain a Top-Secret clearance to start.' An active TS clearance is listed under Preferred Qualifications.
The SOC is a close call between 15-1212 (Information Security Analysts) and 15-1252 (Software Developers). The role centers on vulnerability research, reverse engineering, and exploit development — offensive security work — which aligns with 15-1212, but significant software/tool development is also expected.
Fuzzing tools (AFL++, taint analysis, PIN, Dynamic Memory Instrumentation) are listed as a single requirement with interchangeable options; AFL++ is used as the primary name with the others as alternatives.
Disassembler tools (IDA Pro, Ghidra, Binary Ninja, radare2) are listed as a single requirement; IDA Pro is used as the primary name with the others as alternatives.
Assembly language experience (x86, x64, ARM, MIPS) is listed under Preferred Qualifications.
Low-level debug tools (gdb, WinDbg, OllyDbg) are listed under Preferred Qualifications.
Emulation tools (Renode, QEMU) are listed under Preferred Qualifications.
The Certified Reverse Engineering Analyst (CREA) certification is listed under Preferred Qualifications but is a certification rather than a named technology tool, so it is omitted from the skills list per extraction rules.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): reverse engineering, exploit development, kernel mode development.
Requires a Top Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.