X-Day Offensive Research (XOR) Vulnerability Researcher
Next Frontier Capital
As an X-Day Offensive Research (XOR) Vulnerability Researcher - Assessments & Exercises at JPMorganChase in the Cybersecurity & Technology Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. In this role, you will design and deploy risk-driven assessments (or manage a highly-skilled team that does) and inform analysis to clearly outline root causes.
We are seeking a dedicated, self-motivated vulnerability researcher to tackle the complex demands of our mission. Working closely with fellow researchers and defense teams, you will investigate challenging targets, uncover novel attack surfaces, and develop innovative solutions that enhance our security posture. The ideal candidate combines deep technical curiosity with a strong background in reverse engineering, static analysis, and dynamic analysis, and thrives in a highly collaborative, research-driven environment.
Job responsibilities
- Design and execute testing and simulations – such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations – and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements.
- Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation.
- Conduct in-depth vulnerability research and exploit development across a broad range of categories, including operating systems, mobile devices, web applications, browsers, edge devices, and enterprise software.
- Reverse engineer binaries using tools such as IDA Pro, Ghidra, or Binary Ninja to identify novel attack surfaces and develop proof-of-concept exploits.
- Use common vulnerability research toolsets such as fuzzers, disassemblers, debuggers, and code browsers for static and dynamic analysis.
- Perform N-day vulnerability analysis, patch diffing, and proof-of-concept exploit validation.
- Collaborate with cross-functional teams to develop comprehensive reports – including detailed findings, risk assessments, and remediation recommendations – supporting vulnerability triage, patch prioritization, and the sharing of indicators of compromise (IOCs) in service of the firm's mission requirements.
- Leverage threat intelligence and security research to stay ahead of emerging threats, vulnerabilities, industry best practices, and regulations, applying this knowledge to enhance the firm's assessment strategy and risk management, and engaging with peers and industry groups that share threat intelligence analytics.
- Document research findings, proof-of-concepts, and technical workflows to enable knowledge sharing and repeatability.
Required qualifications, capabilities, and skills
- 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises.
- Track record of discovered vulnerabilities (CVEs) in high-profile targets in at least one of the following categories: operating systems, mobile devices, web applications, browsers, edge devices, or enterprise software.
- Proven hands‑on experience in vulnerability research, proof-of-concept exploit development, coordinated vulnerability disclosure, and mitigating security vulnerabilities in open-source projects.
- Expertise in advanced analysis frameworks leveraging symbolic execution techniques and dynamic binary instrumentation to identify, triage, and exploit complex software vulnerabilities.
- Hands‑on proficiency exploiting complex vulnerability classes – including use‑after‑free, double free, type confusion – and applying advanced exploitation techniques such as heap spraying and controlled memory corruption to achieve reliable code execution.
- Strong understanding of the internals of at least two operating systems throughout user mode and kernel mode (Microsoft Windows, GNU/Linux, Android, macOS, or iOS).
- Experience auditing large C/C++, Java, and .NET codebases combining automated static analyzers with manual review to trace data and control flow, uncover memory-safety, injection, and deserialization vulnerabilities and produce proof-of-concept code.
- Extensive reverse engineering expertise on x86/x64 and ARM/ARM64 binaries, employing IDA Pro, Ghidra, Binary Ninja, WinDbg, GDB, and RR for deep static/dynamic analysis and root cause vulnerability discovery.
- Knowledge of US financial services sector cybersecurity or resiliency organization practices, operational risk management processes, principles, regulations, threats, risks, and incident response methodologies.
- Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents.
- Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels.
Preferred qualifications, capabilities, and skills
- Bachelor’s degree in computer science, or PhD in a related technical field, or an equivalent combination of education and/or experience in a related field.
- 5+ years of experience in vulnerability research and exploit development.
- Experience using fuzzing tools such as LibFuzzer, LibAFL, AFL++, OSS-Fuzz, and Syzkaller.
- Experience using program analysis tools such as LLVM, Angr, KLEE, Intel Pin, DynamoRIO, and Frida.
- Experience emulating embedded platforms for live debugging.
- Experience with kernel and low-level operating system development.
- Deep Linux internals knowledge (SELinux, AppArmor, Seccomp, eBPF, containers, VMs).
- Deep Windows internals knowledge (KASLR, DSE, SSDT, IDT, SMEP, SMAP, PXN, KPP, KDP, VBS, HVCI, KMCI, UMCI).
#CTC
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
The Cybersecurity & Technology Controls group at JPMorganChase aligns the firm’s cybersecurity, access management, controls and resiliency teams. The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls. The group’s number one priority is to enable the business by keeping the firm safe, stable and resilient.
High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters. Users in these roles are subject to enhanced pre-hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
We are seeking a dedicated, self-motivated vulnerability researcher to tackle the complex demands of our mission
#J-18808-Ljbffr- JPMorganChase is seeking an X-Day Offensive Research Vulnerability Researcher to advance the firm’s cybersecurity posture through risk-driven assessments and innovative vulnerability discovery. You will investigate targets, develop PoC exploits, and produce detailed reports...Suggested
- ...Vulnerability & Malware Researcher (Reverse Engineer) Partner Forces is a management consulting firm helping... ..., vulnerability research, offensive security, or a related technical cybersecurity... ...... Experience researching zero‑day vulnerabilities or advanced...Suggested
- ...The Company Legion X is a cyber services company headquartered in Reston, VA that... ...custom cyber solutions through applied research, prototyping, and engineering services.... ...the most interesting and impactful cyber vulnerability research we can find. We take on tasks...SuggestedLocal areaRemote workRelocationHome officeFlexible hours
- ...Mid-Level Vulnerability Researcher Zetier is seeking Mid-Level Vulnerability Researchers to analyze and counter malicious software and develop... ...Experience developing/defeating mitigations (ASLR, DEP, N^X) Developed defeats of common anti-RE techniques (obfuscation...Suggested
- Legion X is seeking a Vulnerability Researcher to turn discovered vulnerabilities into PoCs across firmware and software. You will analyze binaries on architectures like x86 and ARM, identify vulnerabilities, and document your findings for both technical and non-technical...SuggestedRemote job
- ...on the lookout for experienced and passionate vulnerability researchers to join our team. If you have a background in offensive security and think collaborating on high-... ...invitation to interview. Perks and benefits: ~25 days paid vacation + federal holidays ~ Annual...Permanent employmentRemote work
- Stanley Reid & Company is looking for a Vulnerability Researcher to join their team in the Arlington, VA area. The role emphasizes deep expertise... ...vulnerability research, reverse engineering, and related offensive security disciplines. The position requires experience in...
- ...We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze,... ...engineering, vulnerability research, or offensive security. ~ Strong understanding of... ...Experience researching zero-day vulnerabilities or advanced exploitation...Full time
- ...nonprofit engineering, applied research, and advanced technology... ...seeking to hire a Senior Firmware Vulnerability Researcher to tackle the... ...thrives at the intersection of offensive and defensive security research... ...requires a minimum of 3 days on site each week.Preferred Qualifications...InternshipLocal area3 days per week
$150k - $300k
...support this mission, we are seeking a self-motivated Senior Vulnerability Researcher who is ready to solve some of the most challenging... ...exploitation (VE) skills to support a variety of defensive and offensive cyber requirements. As a senior member of our team, you will...Contract work- ...data and technology. We are seeking a self-motivated Senior Vulnerability Researcher who is ready to solve some of the most challenging... ...exploitation (VE) skills to support critical defensive and offensive cyber requirements. As a senior member of our team, you will...Contract work
- ...Stanley Reid & Company is seeking a Vulnerability Researcher for a hybrid role based in Arlington, VA, requiring Top Secret clearance. The position focuses on vulnerability research, firmware reverse engineering, protocol analysis, and CNO development in a national security...
- ...Vulnerability Researcher - Hybrid - Top Secret ~ Arlington, VA Our client is a growing Cyber company that provides Vulnerability Research, CNO Development, and other engineering services to the federal government and commercial clients. They were founded by an...Home officeFlexible hours
- Stanley Reid & Company seeks a Principal Vulnerability Researcher for a hybrid role in Arlington, VA. The position requires TS/SCI clearance and expertise in vulnerability research, reverse engineering, and related fields. The ideal candidate will have hands-on experience...
- Vulnerability Researcher - Hybrid - CI Poly Arlington, VA We are seeking a Vulnerability Researcher to join a team focused on Vulnerability Research, CNO Development, Reverse Engineering, and Penetration Testing. The position is located in Arlington, VA and offers a hybrid...
- Our client has deep expertise in Vulnerability Research, CNO Development, Reverse Engineering, and Penetration Testing. They support the defense and intelligence communities along with commercial clients. Founded by engineers, they have their own fixed, firm contract,...Contract work
- Principal Embedded Vulnerability Researcher About the job Principal Embedded Vulnerability Researcher *** Client WILL sponsor Top Secret Clearance! *** Location : On-Site, Arlington, VA, USA Type : Permanent/Full-Time Employment Description :TopCleared Recruitingis seeking...Permanent employmentFull timeTemporary workImmediate startRemote workFlexible hours
- stanleyreid is seeking a Vulnerability Researcher for a hybrid role in Arlington, VA. The position focuses on vulnerability research, firmware reverse engineering, and protocol analysis for federal and commercial clients. This hybrid on-site role requires Top Secret clearance...Flexible hours
- A leading cybersecurity recruiting firm is seeking a Principal Embedded Vulnerability Researcher to counter malicious software and develop critical cyber capabilities. Candidates must possess extensive experience in reverse engineering C/C++ programs and assembly languages...Flexible hours
- Stanley Reid & Company is seeking a Vulnerability Researcher to join their team in a hybrid Arlington, VA setting. The role requires expertise in vulnerability research, reverse engineering, and development across multiple platforms, with compensation aligned to technical...
- TS/SCI w POLY Required About the Role: We need Linux VRers to conduct reverse engineering, vulnerability research, and exploitation on Linux applications. Focus on native apps across architectures like ARM and MIPS to identify and mitigate security risks. Required Qualifications...
- Stanley Reid & Company is assisting in recruiting a Principal Vulnerability Researcher for Arlington, VA with hybrid schedule and a Top Secret or higher clearance. The role focuses on vulnerability research, reverse engineering, and advanced analysis for defense, intelligence...
- Stanley Reid & Company in Arlington, VA is seeking a Vulnerability Researcher to join a team focused on vulnerability research, CNO development, reverse engineering, and penetration testing. The role is hybrid and requires Top Secret clearance or higher. The ideal candidate...
- Stanley Reid & Company is seeking a Vulnerability Researcher to join their team in a hybrid role based in Arlington, VA. The position focuses on vulnerability research, with capabilities in reverse engineering, assembly languages, Python, and debugging/decompilation tools...
- ...Partner Forces is seeking a highly technical Vulnerability & Malware Researcher (Reverse Engineer) to support a federal client, analyzing malware, vulnerabilities, and attacker techniques to improve detection and defense. You will perform static and dynamic analyses...
- ...Responsibilities Lead technical planning, task prioritization, and schedule management for reverse engineering and vulnerability research assignments. Reverse engineer wireless and embedded communications systems to identify security weaknesses and assess operational...Full time
$154.26k - $231.39k
...support our customers in building a safer global future. Overview Opportunity Two Six Technologies is actively seeking a Lead Vulnerability Researcher to join our Communication Systems team in Arlington, Virginia. The team is composed of intellectual individuals,...Local area- Two Six Technologies is seeking a Lead Vulnerability Researcher to join the Communication Systems team in Arlington, Virginia. The role focuses on reverse engineering wireless and embedded systems to uncover vulnerabilities and develop PoC exploits, using IDA Pro, Binary...
$127.08k - $277.2k
...remote work at Penn State, see Notice to Out of State Applicants. POSITION SPECIFICSWe are searching for a self-motivated Vulnerability Researcher to join our Cyberspace Operations Research Department in Reston, VA of the Applied Research Laboratory (ARL) at Penn State...Full timeFor contractorsWork experience placementRemote workWork from home- ...where we push the boundaries of software and firmware reverse engineering to uncover vulnerabilities in wireless and embedded systems. As part of our elite team of security researchers, you’ll work alongside CNO developers and hardware engineers, conducting cutting‑edge...Contract workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to X-Day Offensive Research (XOR) Vulnerability Researcher. Be the first to apply!
- security researcher McLean, VA
- court researcher McLean, VA
- human factors researcher McLean, VA
- researcher McLean, VA
- music researcher McLean, VA
- data collection researcher McLean, VA
- machine learning researcher McLean, VA
- design researcher McLean, VA
- undergraduate research McLean, VA
- operations research McLean, VA




