X-Day Offensive Research (XOR) Vulnerability Researcher
On-siteJersey City, New Jersey, United States
Job Summary
Design and execute risk-driven assessments, including penetration tests, technical controls evaluations, and resiliency simulations, while developing assessment methodologies and tools aligned with regulatory requirements. Conduct in-depth vulnerability research and exploit development across operating systems, mobile devices, web applications, and enterprise software by reverse engineering binaries with IDA Pro, Ghidra, or Binary Ninja to uncover novel attack surfaces. Perform N-day vulnerability analysis, patch diffing, and proof-of-concept validation using fuzzers, disassemblers, and debuggers to identify complex classes such as use-after-free and heap spraying. Collaborate with cross-functional teams to produce comprehensive reports detailing findings, risk assessments, and remediation recommendations for vulnerability triage and patch prioritization. Leverage threat intelligence to enhance the firm's assessment strategy and engage with industry peers to share indicators of compromise.
Required Qualifications
- 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises.
- Track record of discovered vulnerabilities (CVEs) in high-profile targets in at least one of the following categories: operating systems, mobile devices, web applications, browsers, edge devices, or enterprise software.
- Proven hands-on experience in vulnerability research, proof-of-concept exploit development, coordinated vulnerability disclosure, and mitigating security vulnerabilities in open-source projects.
- Expertise in advanced analysis frameworks leveraging symbolic execution techniques and dynamic binary instrumentation to identify, triage, and exploit complex software vulnerabilities.
- Hands-on proficiency exploiting complex vulnerability classes – including use-after-free, double free, type confusion – and applying advanced exploitation techniques such as heap spraying and controlled memory corruption to achieve reliable code execution.
- Strong understanding of the internals of at least two operating systems throughout user mode and kernel mode (Microsoft Windows, GNU/Linux, Android, macOS, or iOS).
- Experience auditing large C/C++, Java, and .NET codebases combining automated static analyzers with manual review to trace data and control flow, uncover memory-safety, injection, and deserialization vulnerabilities and produce proof-of-concept code.
- Extensive reverse engineering expertise on x86/x64 and ARM/ARM64 binaries, employing IDA Pro, Ghidra, Binary Ninja, WinDbg, GDB, and RR for deep static/dynamic analysis and root cause vulnerability discovery.
- Knowledge of US financial services sector cybersecurity or resiliency organization practices, operational risk management processes, principles, regulations, threats, risks, and incident response methodologies.
- Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents.
- Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels.
Desired Qualifications
- Bachelor's degree in computer science, or PhD in a related technical field, or an equivalent combination of education and/or experience in a related field.
- 5+ years of experience in vulnerability research and exploit development.
- Experience using fuzzing tools such as LibFuzzer, LibAFL, AFL++, OSS-Fuzz, and Syzkaller.
- Experience using program analysis tools such as LLVM, Angr, KLEE, Intel Pin, DynamoRIO, and Frida.
- Experience emulating embedded platforms for live debugging.
- Experience with kernel and low-level operating system development.
- Deep Linux internals knowledge (SELinux, AppArmor, Seccomp, eBPF, containers, VMs).
- Deep Windows internals knowledge (KASLR, DSE, SSDT, IDT, SMEP, SMAP, PXN, KPP, KDP, VBS, HVCI, KMCI, UMCI).
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.