X-Day Offensive Research Vulnerability Researcher

JPMorgan Chase

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Jersey City, NJ
Posted
70 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $179k
$118k most similar roles pay here $231k

This listing doesn't post a salary. Most similar roles pay $144,750–$214,000.

Based on 239 similar postings.

Employer

About JPMorgan Chase

JPMorgan Chase & Co. is a global financial services firm and one of the largest banks in the world, offering investment banking, commercial banking, asset management, and consumer financial services.

JPMorgan Chase currently has 1117 open roles on FindRole.

Listed pay typically runs $186,160–$215,000 across 7 roles with salary data.

Most-posted roles

View all roles at JPMorgan Chase

At a glance

TL;DR · X-Day Offensive Research Vulnerability Researcher

As an X-Day Offensive Research (XOR) Vulnerability Researcher within the Cybersecurity & Technology Controls line of business, you will proactively identify risks and vulnerabilities in people, processes, and technology. You will design and execute risk-driven assessments, including penetration tests, cyber exercises, and resiliency simulations to improve security posture. Your daily work involves conducting in-depth vulnerability research and exploit development across operating systems, mobile devices, web applications, and enterprise software. You will perform reverse engineering using IDA Pro, Ghidra, or Binary Ninja, utilize fuzzers like AFL++ and Syzkaller, and employ program analysis tools such as Angr and Frida. The role focuses on solving complex security challenges by analyzing memory-safety issues, performing patch diffing, and developing proof-of-concept exploits to address systemic risks within the financial services sector while ensuring compliance with regulatory requirements.

What you'll do

  • Design and execute penetration tests, cyber exercises, and resiliency simulations to identify risks in people, processes, and technology.
  • Conduct in-depth vulnerability research and exploit development across operating systems, mobile devices, web applications, and enterprise software.
  • Reverse engineer binaries using tools like IDA Pro or Ghidra to identify novel attack surfaces and develop proof-of-concept exploits.
  • Perform N-day vulnerability analysis, patch diffing, and validation of proof-of-concept exploits.
  • Utilize fuzzers, disassemblers, and debuggers for static and dynamic analysis of complex software vulnerabilities.
  • Evaluate the effectiveness of security controls and identify opportunities to automate control evaluations.
  • Produce comprehensive reports including risk assessments, remediation recommendations, and indicators of compromise for cross-functional teams.
  • Document research findings and technical workflows to ensure knowledge sharing and repeatability across the organization.

What we're looking for

  • 5+ years of experience in cybersecurity or resiliency with skills to plan and coordinate offensive security testing.
  • Track record of discovered vulnerabilities (CVEs) in operating systems, mobile devices, web applications, browsers, edge devices, or enterprise software.
  • Proven hands-on experience in vulnerability research, proof-of-concept exploit development, and coordinated vulnerability disclosure.
  • Expertise in advanced analysis frameworks using symbolic execution and dynamic binary instrumentation to identify and exploit complex vulnerabilities.
  • Proficiency exploiting complex vulnerability classes like use-after-free and type confusion using heap spraying and controlled memory corruption.
  • Strong understanding of the internals of at least two operating systems across user and kernel modes.
  • Experience auditing large C/C++, Java, and .NET codebases to uncover memory-safety, injection, and deserialization vulnerabilities.
  • Extensive reverse engineering expertise on x86/x64 and ARM/ARM64 binaries using tools like IDA Pro, Ghidra, Binary Ninja, WinDbg, GDB, and RR.

More like this

Similar roles

Senior Vulnerability Researcher

Booz Allen Hamilton

Fort Meade, MD 50 days ago $86,900$198,000
Reverse Engineering Vulnerability Assessment Exploitation Development Python Perl Java Bash PowerShell Windows Linux DevOps CI/CD Git Jenkins Docker Agile Scrum Android iOS
6+ yrs exp

Microelectronics Vulnerability Researcher

Booz Allen Hamilton

Huntsville, AL 81 days ago $86,800$198,000
C C++ Python Reverse Engineering IDA Pro Ghidra Embedded Systems Side-channel Analysis Fault Injection Differential Power Analysis Correlation Power Analysis Electromagnetic Analysis Glitching Oscilloscopes Logic Analyzers JTAG i2C FPGA Cryptography Signals Processing
3+ yrs exp

Principal Security Researcher

Microsoft

Redmond, WA 37 days ago $142,800$274,800
Vulnerability Research Large Language Models AI Agents Fuzzing Static Analysis Dynamic Analysis Reverse Engineering Symbolic Execution Taint Analysis C/C++ C# Java JavaScript TypeScript Python SARIF Threat Modeling
6+ yrs exp

Offensive Hardware Security Researcher

Nvidia

Santa Clara, CA 77 days ago $184,000$287,500
ARM RISCV Verilog C SoC ASIC Firmware SDL Threat Modeling Side-channel Analysis TEE TrustZone Confidential Computing Symbolic Execution Fuzzing JTAG ChipWhisperer IDA Pro Ghidra Machine Learning
6+ yrs exp

Senior Offensive Security Engineer, Vulnerability Operations

Nvidia

Remote (Austin, TX) +1 9 days ago $224,000$356,500
LLM Python Red Teaming Penetration Testing Kubernetes Exploit Development Vulnerability Research SAST DAST Fuzzing GitOps OpenShift prompt-injection defense Multi-agent Orchestration Offensive Security
10+ yrs exp Remote