M9 Solutions

Senior Vulnerability Researcher – Windows / CNE

ArlingtonFull timeSenior$160,000 - $220,000 / yearPosted 19 days ago
Apply on M9 Solutions →

Sign into see who you know at M9 Solutions.

M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations that desire improved performance and modern, sustainable change. M9 has provided quality IT services and support to more than 30 Federal Agencies and multiple commercial customers nationwide. Our capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software Development, and Finance & Accounting.  M9 Solutions is seeking a Senior Vulnerability Researcher – Windows / CNE to work on-site in support of a government contract for a client located in Arlington, VA. An active TS/SCI clearance is required. Responsibilities Lead advanced vulnerability research on Windows operating systems, applications, and core OS components (including kernel and drivers). Analyze, reverse engineer, and understand complex vulnerabilities to support CNE/CNO missions. Use tools such as IDA Pro, Ghidra, Binary Ninja, and WinDbg/x64dbg for in‐depth binary analysis and debugging, including creating or extending custom tooling when needed. Own end‐to‐end research on difficult, poorly documented Windows targets with minimal guidance, from scoping and experimentation through proof‐of‐concept. Develop and document technical approaches, findings, and PoCs to validate vulnerabilities and exploitation paths. Continuously explore and prototype novel techniques for vulnerability discovery and exploitation on modern, mitigated Windows platforms. Collaborate with mission and engineering teams to translate research into operational capabilities. Act as the senior technical point of contact and subject‐matter expert for Windows vulnerability, exploitation, and OS‐internals questions. Required Skills and Qualifications Active TS/SCI clearance. 3+ years in vulnerability research, exploit development, or CNE‐focused reverse engineering, with a sustained focus on Windows (user and kernel mode) rather than general app security or pen‐testing. Deep, practical understanding of Windows internals (kernel architecture, drivers, memory management, system calls, process/thread models, and security mechanisms). Strong CNE/CNO background; experience leveraging vulnerabilities in support of real‐world operations or mission environments. Demonstrated track record solving very hard, low‐level technical problems with minimal guidance, including on research efforts where many others have struggled to make progress. Demonstrated experience discovering and exploiting non‐trivial vulnerabilities in modern, mitigated Windows environments (e.g., ASLR, DEP, CFG, virtualization‐based security). Hands‐on experience with reverse engineering and debugging tools (IDA Pro, Ghidra, Binary Ninja, WinDbg, x64dbg, etc.). Fluency in x86/x64 assembly and strong C/C++ skills, plus scripting experience (e.g., Python) for automa...