1

Salaried Exploit Development Jobs in New York (NOW HIRING)

Product Development

New York, NY · On-site

$125K - $190K/yr

... exploit product extension opportunities (4) Oversee the product range; review the product line to ... Compensation Details The salary range for this role is $125,000-$190,000. This is the lowest to ...

Product Development

New York, NY · Hybrid

$125K - $190K/yr

... exploit product extension opportunities (4) Oversee the product range; review the product line to ... Compensation Details The salary range for this role is $125,000-$190,000. This is the lowest to ...

Vice President of Finance

Secaucus, NJ · On-site +1

$225K - $275K/yr

... exploit AI technology. KEY RESPONSIBILITIES: • Financial Planning, Analysis & Reporting • ... The base salary will depend on numerous factors such as: experience and qualifications for the role ...

Vice President of Finance

Secaucus, NJ · On-site

$225K - $275K/yr

Leadership and People Development · Maintain a strong focus on process improvement opportunities ... The base salary will depend on numerous factors such as: experience and qualifications for the role ...

... to exploit metabolic dependencies in cancer. We discovered a targetable metabolic vulnerability ... Participates in the development of performance standards, selection of methodology and ...

next page

Showing results 1-20

Salaried Exploit Development information

What are some typical challenges encountered by professionals in salaried exploit development roles?

Professionals in salaried exploit development roles often face challenges such as staying current with rapidly evolving security technologies and patch cycles. They must continuously research new vulnerabilities and develop creative solutions to bypass updated security mechanisms, which can be highly demanding. Collaborating closely with security analysts and other developers is essential to ensure responsible disclosure and risk management. Additionally, balancing project deadlines with the need for meticulous testing and documentation can be a significant challenge in this field.

What is the difference between Salaried Exploit Development vs Penetration Tester?

AspectSalaried Exploit DevelopmentPenetration Tester
CredentialsSecurity certifications, programming skillsSecurity certifications, testing experience
Work EnvironmentResearch labs, security firms, internal teamsClient sites, corporate environments, consulting firms
Industry UsageCybersecurity, offensive securityCybersecurity, vulnerability assessment

Salaried Exploit Developers focus on creating and testing exploits for security research or defensive purposes, often working in labs or R&D settings. Penetration Testers simulate attacks to identify vulnerabilities in client systems. While both roles require security knowledge and technical skills, Exploit Developers primarily develop exploits, whereas Penetration Testers perform assessments and reporting. Understanding these differences helps clarify career paths and employer expectations in cybersecurity.

What is a Salaried Exploit Developer?

A Salaried Exploit Developer is a cybersecurity professional who is employed by an organization to research, identify, and develop software exploits—ways to take advantage of vulnerabilities in computer systems or applications. Unlike freelance or independent security researchers, salaried exploit developers work as part of a security team, often within penetration testing firms, defense contractors, or tech companies. Their work can involve both offensive (discovering vulnerabilities to test defenses) and defensive (helping to patch or mitigate vulnerabilities) tasks. These roles require strong programming skills, a deep understanding of operating systems, and knowledge of security protocols. Salaried Exploit Developers may also be involved in responsible disclosure of vulnerabilities to affected vendors.

What are the key skills and qualifications needed to thrive as a Salaried Exploit Developer, and why are they important?

To thrive as a Salaried Exploit Developer, you need deep expertise in computer science, reverse engineering, vulnerability analysis, and low-level programming, often backed by a degree in computer science or related field. Familiarity with tools like IDA Pro, Ghidra, debuggers, and operating system internals is crucial, and certifications such as OSCP or OSCE can be advantageous. Creativity, persistence, and strong problem-solving abilities are standout soft skills in this role. These qualifications are essential for identifying, developing, and responsibly handling software exploits in a secure and ethical manner.
What are the most commonly searched types of Exploit Development jobs in New York? The most popular types of Exploit Development jobs in New York are:
What cities in New York are hiring for Salaried Exploit Development jobs? Cities in New York with the most Salaried Exploit Development job openings:

Adjunct Faculty - Cybersecurity (Scripting, Penetration Testing & Web Security)

Touro University New York

Manhattan, NY • On-site

$6.5K/wk

Part-time

Re-posted 16 days ago


Job description

Overview
GST is seeking an Adjunct Faculty member for Cybersecurity (Scripting, Penetration Testing & Web Security) to teach graduate-level cybersecurity courses in scripting, penetration testing, and web application security. The ideal candidate combines academic expertise with hands-on industry experience and can deliver applied, workforce-aligned instruction that prepares students for real-world cybersecurity roles.
Responsibilities
  • Teach assigned graduate cybersecurity courses in an asynchronous online format with required in-person engagement
  • Design and facilitate hands-on labs aligned to industry tools and real-world scenarios
  • Guide students through applied cybersecurity workflows including automation, offensive security techniques, and vulnerability analysis
  • Provide timely, actionable feedback on assignments, labs, and assessments
  • Support development of professional documentation, reporting, and communication skills
  • Maintain and update course materials within the learning management system (LMS)
  • Align instruction with current industry practices, certifications, and workforce expectations

Instructional Scope
Scripting for Cybersecurity
  • Teach core scripting concepts across multiple languages (e.g., Python, Bash, PowerShell) with an emphasis on comparing approaches to solve the same problem
  • Develop student competency in automating administrative and security tasks, including file handling, log parsing, and system operations
  • Cover scripting for networking tasks (socket communication, API interaction) and database operations
  • Introduce secure coding practices and debugging techniques
  • Emphasize real-world use cases such as incident response automation, data processing, and systems management

Penetration Testing
  • Deliver instruction aligned to industry-recognized penetration testing methodologies and Hack The Box certification frameworks (e.g., CPTS-level content)
  • Cover the full penetration testing lifecycle: reconnaissance, enumeration, vulnerability analysis, exploitation, privilege escalation, lateral movement, and post-exploitation
  • Include hands-on labs targeting network, web application, Active Directory, and hybrid/cloud environments
  • Teach tool usage (e.g., Nmap, Metasploit, BloodHound, credential attacks) alongside methodology and decision-making
  • Emphasize operational tradecraft, reporting, risk assessment, and communication of findings to stakeholders

Web Security
  • Deliver instruction aligned to Hack The Box web security certification frameworks (e.g., CWEE or equivalent pathways)
  • Teach how modern web applications function, including HTTP/S protocols, session management, authentication, and backend integrations
  • Cover identification and validation of vulnerabilities such as injection flaws, broken authentication, access control issues, and input validation weaknesses
  • Utilize tools such as Burp Suite, OWASP ZAP, and proxy-based analysis for hands-on testing
  • Emphasize attacker mindset, exploit development basics, and secure design principles
  • Incorporate lab-based scenarios simulating real-world web application attack surfaces

Qualifications
Education/Experience
  • Master's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a closely related field from an accredited institution required.
  • Doctoral degree in a related field preferred.
  • Minimum of 3-5 years of professional experience in cybersecurity, penetration testing, application security, or scripting/automation

Travel
  • Must be willing to commute to 3 Times Sq. for live synchronous classes at least 7 times a semester
  • Courses are delivered primarily in an asynchronous online format, requiring consistent online presence and facilitation

Working Conditions
  • Use of a computer
  • Need to sit or stand for 3-hour class

Maximum Salary
USD $6,500.00/Course
Minimum Salary
USD $5,200.00/Course