1

Exploitation Engineer Jobs (NOW HIRING)

Exploitation Analyst

Annapolis, MD · On-site

$115K - $240K/yr

Belay Technologies is seeking multiple Exploitation Analysts (EAs) to support a critical mission ... Relevant experience must be in computer or information systems design/development, programming ...

Showing results 21-40

Exploitation Engineer information

See salary details

$44K

$106.4K

$173.5K

How much do exploitation engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for exploitation engineer in the United States is $106,386.00, according to ZipRecruiter salary data. Most workers in this role earn between $76,000.00 and $132,500.00 per year, depending on experience, location, and employer.

What does an exploitation engineer do?

An Exploitation Engineer identifies, develops, and optimizes security vulnerabilities in software, hardware, or networks to assess risks and improve defenses. They analyze systems for weaknesses, create proof-of-concept exploits, and collaborate with security teams to enhance protections. Often working in cybersecurity research, penetration testing, or red team operations, they simulate real-world cyber threats to strengthen overall security. This role requires deep knowledge of exploit development, reverse engineering, and programming languages like C, Python, and Assembly.

What does a typical day look like for an exploitation engineer, and with whom do they collaborate most frequently?

A typical day for an Exploitation Engineer involves researching and identifying security vulnerabilities, developing and testing proof-of-concept exploits, and documenting findings for technical teams or clients. You’ll regularly collaborate with penetration testers, security analysts, software developers, and sometimes incident response teams to ensure that discovered vulnerabilities are properly understood and appropriately addressed. Communication is often a key part of the job, as you’ll need to clearly explain technical concepts and risk impacts to both technical and non-technical stakeholders. This multidisciplinary collaboration helps organizations proactively improve their security posture.

What are the key skills and qualifications needed to thrive in the exploitation engineer position, and why are they important?

To thrive as an Exploitation Engineer, you need deep expertise in vulnerability research, exploit development, reverse engineering, and a strong understanding of operating systems and network protocols, often supported by a degree in computer science or a related field. Familiarity with tools like IDA Pro, Ghidra, Metasploit, debuggers, scripting languages, and relevant certifications such as OSCP or GXPN is highly valued. Analytical thinking, strong problem-solving abilities, and effective communication skills help set top candidates apart. These combined technical and interpersonal capabilities are essential for discovering security weaknesses, collaborating with teams, and developing reliable proof-of-concept exploits in complex environments.

More about Exploitation Engineer jobs

What cities are hiring for Exploitation Engineer jobs?

Cities with the most Exploitation Engineer job openings:

What states have the most Exploitation Engineer jobs?

States with the most job openings for Exploitation Engineer jobs include:

What are popular job titles related to Exploitation Engineer jobs?

For Exploitation Engineer jobs, the most frequently searched job titles are:

Infographic showing various Exploitation Engineer job openings in the United States as of September 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $106,386 per year, or $51.1 per hour.

Windows Driver Exploitation Engineer APPLIED AI VR WINDOWS New York, NY / On Site →

Manhattan, NY • On-site

Other

Posted 13 days ago


Job description

Zealot is deploying AI systems at the center of western cyber operations , backed by tier-1 US VCs and industry leaders. Our team includes alumni of Anthropic, xAI, and Anduril. Soon live with close U.S. allies abroad.

APPLIED AI VR WINDOWS

Compensation 100K-195K + skin in the game equity

Location New York, NY On Site

Stage Early-stage startup backed by tier 1 investors. Small, growing team with exceptionally high ownership.

  • + Discover and exploit vulnerabilities in Windows kernel-mode and user-mode drivers.
  • + Research attack surfaces across WDDM display drivers, network miniport drivers, filesystem filter drivers, and third-party kernel extensions.
  • + Develop exploit primitives for privilege escalation, sandbox escape, and kernel code execution.
  • + Build automated tooling for Windows driver analysis, fuzzing, and vulnerability triage.
  • + Deep experience with Windows kernel internals: I/O manager, object manager, memory manager.
  • + Proven track record of driver vulnerability research (CVEs, ZDI submissions, or offensive work).
  • + Strong x86/x64 reverse engineering and exploit development skills.
  • + Proficiency with WinDbg, IDA/Ghidra, and driver analysis frameworks.
  • + Strong C/C++ skills for kernel-level development and exploitation.
Nice to Have
  • + Experience with Hyper-V and virtualization-based security (VBS) attack surfaces.
  • + Familiarity with Windows driver fuzzing (kAFL, what the fuzz, custom harnesses).
  • + Experience with BYOVD (Bring Your Own Vulnerable Driver) attack techniques.
  • + Knowledge of Windows Defender / EDR kernel-mode components.
  • + Experience building with LLMs and AI agents.
  • + Published research or conference talks on Windows kernel security.
  • + Deeply technical and motivated to find the bugs that matter at the kernel level.
  • + Clearly interested in stepping away from purely manual research and moving toward the development of AI systems.
  • + Building something massive matters more to you than comfort, titles, or predictability.
  • + You want to be early at a company that will change an industry, and you're ready to do what that actually takes.

Note to recruiting firms: Windows driver vulnerability research is the core requirement. Kernel exploitation experience is essential. Familiarity with modern Windows security mitigations is a strong plus.

Ready?

#J-18808-Ljbffr