ServiceNow Vulnerability Response Engineer
Openkyber
Job Description As an X-Day Offensive Research (XOR) Vulnerability Researcher - Assessments & Exercises at OpenKyber in the Cybersecurity & Technology Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology.
In this role, you will design and deploy risk-driven assessments (or manage a highly-skilled team that does) and inform analysis to clearly outline root causes. We are seeking a dedicated, self-motivated vulnerability researcher to tackle the complex demands of our mission. Working closely with fellow researchers and defense teams, you will investigate challenging targets, uncover novel attack surfaces, and develop innovative solutions that enhance our security posture.
The ideal candidate combines deep technical curiosity with a strong background in reverse engineering, static analysis, and dynamic analysis, and thrives in a highly collaborative, research-driven environment.
Job responsibilitiesDesign and execute testing and simulations - such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations - and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements.
Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation.
Conduct in-depth vulnerability research and exploit development across a broad range of categories, including operating systems, mobile devices, web applications, browsers, edge devices, and enterprise software.
Reverse engineer binaries using tools such as IDA Pro, Ghidra, or Binary Ninja to identify novel attack surfaces and develop proof-of-concept exploits.
Use common vulnerability research toolsets such as fuzzers, disassemblers, debuggers, and code browsers for static and dynamic analysis.
Perform N-day vulnerability analysis, patch diffing, and proof-of-concept exploit validation.
Collaborate with cross-functional teams to develop comprehensive reports - including detailed findings, risk assessments, and remediation recommendations - supporting vulnerability triage, patch prioritization, and the sharing of indicators of compromise (IOCs) in service of the firm's mission requirements.
Leverage threat intelligence and security research to stay ahead of emerging threats, vulnerabilities, industry best practices, and regulations, applying this knowledge to enhance the firm's assessment strategy and risk management, and engaging with peers and industry groups that share threat intelligence analytics.
Document research findings, proof-of-concepts, and technical workflows to enable knowledge sharing and repeatability.
Required qualifications, capabilities, and skills5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises.
Track record of discovered vulnerabilities (CVEs) in high-profile targets in at least one of the following categories: operating systems, mobile devices, web applications, browsers, edge devices, or enterprise software.
Proven hands-on experience in vulnerability research, proof-of-concept exploit development, coordinated vulnerability disclosure, and mitigating security vulnerabilities in open-source projects.
Expertise in advanced analysis frameworks leveraging symbolic execution techniques and dynamic binary instrumentation to identify, triage, and exploit complex software vulnerabilities.
Hands-on proficiency exploiting complex vulnerability classes - including use-after-free, double free, type confusion - and applying advanced exploitation techniques such as heap spraying and controlled memory corruption to achieve reliable code execution.
Strong understanding of the internals of at least two operating systems throughout user mode and kernel mode (Microsoft Windows, GNU/Linux, Android, macOS, or iOS).
Experience auditing large C/C++, Java, and .NET codebases combining automated static analyzers with manual review to trace data and control flow, uncover memory-safety, injection, and deserialization vulnerabilities and produce proof-of-concept code.
Extensive reverse engineering expertise on x86/x64 and ARM/ARM64 binaries, employing IDA Pro, Ghidra, Binary Ninja, WinDbg, GDB, and RR for deep static/dynamic analysis and root cause vulnerability discovery.
Knowledge of US financial services sector cybersecurity or resiliency organization practices, operational risk management processes, principles, regulations, threats, risks, and incident response methodologies.
Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents.
Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels.
Preferred qualifications, capabilities, and skillsBachelor's degree in computer science, or PhD in a related technical field, or an equivalent combination of education and/or experience in a related field.
5+ years of experience in vulnerability research and exploit development.
Experience using fuzzing tools such as LibFuzzer, LibAFL, AFL++, OSS-Fuzz, and Syzkaller.
Experience using program analysis tools such as LLVM, Angr, KLEE, Intel Pin, DynamoRIO, and Frida.
Experience emulating embedded platforms for live debugging.
Experience with kernel and low-level operating system development.
Deep Linux internals knowledge (SELinux, AppArmor, Seccomp, eBPF, containers, VMs).
Deep Windows internals knowledge (KASLR, DSE, SSDT, IDT, SMEP, SMAP, PXN, KPP, KDP, VBS, HVCI, KMCI, UMCI).
#CTC About Us OpenKyber, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions.
We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more.
Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success.
We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law.
We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamThe Cybersecurity & Technology Controls group at OpenKyber aligns the firm's cybersecurity, access management, controls and resiliency teams.
The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls.
The group's number one priority is to enable the business by keeping the firm safe, stable and resilient.
High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters.
Users in these roles are subject to enhanced pre-hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
For applications and inquiries, contact:View email address on us.fitly.work
$107.9k - $195.05k
...seeking an experienced Senior Systems Engineer to support an exciting Air Force Life... ...and availability requirements. Primary Responsibilities:Ability to travel to support customer... ...Python).Familiarity with ITSM tools like ServiceNow and Atlassian Jira Service Management....ServicenowFull time$87.1k - $157.45k
...Sector at Leidos is seeking a Linux System Engineer to support a fast-paced program with... ..., we'd like to talk with you.Primary Responsibilities:Install, configure, maintain, and... ...playbooksFamiliarity with ITSM platforms such as ServiceNow and Jira Service ManagementDABAOPP1If...ServicenowFull time$95.86k - $208.27k
...Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice.Responsibilities:Support the delivery, configuration, and... ...solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); automate PAM tasks using scripting and APIs (such...ServicenowH1bLocal area$58.1k - $95.9k
...Position Overview The Change Management Engineer designs, implements, and governs ITIL-... ...and supporting ITSM tooling. Key Responsibilities Design and maintain ITIL-based... ...application changes. Use ITSM tools such as ServiceNow or similar platforms to log, track,...ServicenowContract workWork experience placementWork at office$50k
...is currently seeking a Junior Telecoms Engineer. This is a remote position.... ...4 Job-Specific Essential Duties and Responsibilities: Provide day-to-day operational support... ...Experience supporting ITSM tools (e.g., ServiceNow) for ticket tracking and documentation...ServicenowContract workRemote work$123.4k - $176.3k
...established design control processes and good engineering practices. This job family programs... ...of intelligent automation. Responsibilities Lead deployment of AI agents such as... ...enterprise platforms like Salesforce, ServiceNow, Microsoft, where agents take actions...ServicenowTemporary workLocal areaImmediate startFlexible hours$90.4k - $168.2k
...Security Services organization.Responsibilities:Utilize your expertise in... ...assessments to identify vulnerabilities and insecure configurations... ...certifications include XSOAR Engineer, CISSP, CCSP, CCSK, GSEC,... ...scripting or automation, and ServiceNow is a plusExcellent verbal/...ServicenowH1bLocal area- ...Inside Systems Engineer We are looking for an Inside Systems Engineer to work closely... ...customers or Fortinet partners. Responsibilities Assess customer project requirements... ...issues, threats, attacks, and vulnerabilities Principles of cyber threat management...
$123.27k - $167.3k
...CommVault Systems Engineer (Data Protection / Backup) Employment Type: Full-Time, Experienced... ..., and environments to ensure a timely response to backup, restore, and data... ...related tasks which include documentation, vulnerability scan review, assessment support, patch...Full timeFlexible hours$128.1k - $239.6k
...security testing and compliance, vulnerability management, and overall... ...risk management. Key responsibilities SME (subject matter expert... ...findings to Jira/ServiceNow Conduct regular security... ...including security architects, engineers, developers and product owners...ServicenowSummer holidayLocal areaFlexible hoursShift work- ...efficiency, reporting accuracy, and user experience. Develop ServiceNow workflows and integrations that support ITSM, request... ...with strategic objectives and measurable outcomes. Key Responsibilities* Desired Skill Set Workflow automation and process orchestration...Servicenow
$61.9k - $141k
Implementation EngineerThe Opportunity:Maintain responsibility for completing site surveys and creating structured designs for the customer... ...voice, data, security, and audio and visual systems. Design engineered drawings, specifications, reports, and other technical...Full timeContract workPart timeFor subcontractorWork at officeLocal areaRemote work- Position: Forensic Engineer Contractor Location: Oklahoma City, OKJob Id: 1653 # of... ...professional Civil or Structural Engineer inOklahoma City, OK. Key Responsibilities Include:Site studies evaluating damages to materials or...For contractors
- ...hyperscale environments, and we solve those challenges with engineering depth and practical execution.We keep things simple here. We... ...customer feedback and sales requirements. The Design Engineer is responsible for managing all aspects of assigned projects.What You’ll...Full timeContract work
- ...their families so they can focus on contributing to the fullest.Job Profile Summary:The Senior Completions Engineer, working under general supervision, is responsible for planning and documentation of moderately complex activities such as new well completions,...Full timeWork experience placement
$186.9k - $267.7k
...Security Business Group (SBG) is looking for a Forward Deployed Engineer in a customer-facing role that focuses on technical... ...engineering contexts without losing fidelity on either side.Key Responsibilities:• Lead the technical relationship on a named set of large and...Full timeTemporary workLocal areaRemote workFlexible hours$90.3k - $189.6k
...Enterprise Services Cyber Security Team is seeking a Cybersecurity Engineer. As a member of the Cyber Security Team you will work to... ...best practices and are compliant with applicable guidelines.Responsibilities:Work in a team‑centric environment to support defensive and offensive...Contract workWork experience placementFlexible hours$86.9k - $198k
...world needs into technical specifications makes you an integral part of delivering a customer focused engineering solution. The Cybersecurity PKI Engineer will be responsible for developing and maintaining secure, scalable, and highly available PKI solutions aligned with...Full timeContract workPart timeWork at officeLocal areaRemote work- ...right to join HNTB Corporation! We are currently seeking a design engineer to join our Municipal Transportation Section for our Central... ..., and wellness programs. This opportunity entails being responsible for producing and modifying design calculations, technical reports...Full timeWork at officeLocal areaFlexible hours
- ...: Long Term No of positions: 3 Ability to travel up to 50%. Responsibilities Senior Engagement Managers (EMs) lead and drive large and complex... ...and resolution. Experience working collaboratively. ServiceNow certifications in aligned workflow. Applies AI tools to streamline...ServicenowRemote work
$126.95k - $248.21k
...Amazon Connect, NICE CXone, Five9, Genysys, ServiceNow) to advise public agencies on... ...matched to defined governance, policies and responsible AI controls typical for public agencies... ....What You’ll Need:Bachelor's degree in Engineering, IT, Accounting/Finance, Planning, Business...ServicenowFull time$67.8k - $142.2k
...technology processes meet both internal and external standards.Responsibilities:Coordinate, facilitate, and support IT SOX compliance... ...evidence requests, remediation validation).Experience using ServiceNow IRM or other GRC/compliance management platforms.-What You Can...ServicenowContract workWork experience placementFlexible hours$94.1k - $132.5k
...The Problem Manager is responsible for identifying, analyzing, and resolving problems within the IT infrastructure to prevent incidents... ...certification CASTLE-NET IT environment familiarity ServiceNow or similar ticketing system expertise Federal contracting...ServicenowPermanent employmentContract workWork at office$95k - $130k
...Responsible for resolving more complex incident and problem management issues related to program operations. Identifies and uncovers... ...preferred. Strong skills using Service Management tools (e.g., ServiceNow).. Strong in: ITIL change management, ServiceNow, CAB...ServicenowContract workWork at office$67.8k - $142.2k
...experience and ensuring data integrity, controls, and performance.Responsibilities:Facilitate the process to collect and define client... ...user stories, process modeling, test management, Azure DevOps, ServiceNow (or equivalent).Ability to read functional specs, debug trace...ServicenowContract workWork experience placementFlexible hours$45 per hour
...Industrial, is currently seeking a reliable, experienced Electrical Engineer to work full time for SJS Executives supporting a Veteran’s... ...with federal government employees and service members. Responsibilities will include: Responsible for the preparation of...Hourly payFull time$153k - $207k
Senior Project Engineer (Project Engineer)Company:The Boeing CompanyThe Boeing B-52J Commercial Engine Replacement Program (CERP) Aircraft... ..., initiatives, and challenges. The project engineer will be responsible for one or more projects and will provide technical, business,...Permanent employmentFull timeInterim roleWork at officeImmediate startRelocationVisa sponsorshipWork visaFlexible hoursShift workDay shift- ...background check is required of successful candidates.Essential Responsibilities:Know and understand safety policiesContract document... ...with estimators and PM’sCoordination with Owner, Architect and Engineers as directed by the PM.Contract and Purchase order managementChange...Full timeContract work
$40k
...Code: TCS217, T1, Band 4 Job-Specific Essential Duties and Responsibilities: Support configuration, change, and release management... ...and records accurately. Familiarity with ITSM tools (e.g., ServiceNow). Basic understanding of configuration and change management...ServicenowContract workRemote work$60k
...enterprise IT services contract. This role is responsible for monitoring and reporting on service... ...Information Systems, Computer Science, Engineering, or a related field. ~5+ years of... ...frameworks. Familiarity with ServiceNow, SharePoint, or similar enterprise reporting...ServicenowContract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ServiceNow Vulnerability Response Engineer. Be the first to apply!



