1

Vulnerability Researcher Contractor Jobs in Virginia

Required Qualifications In addition to meeting all baseline technical requirements for contractor ... Vulnerability Research (VR) * Reverse Engineering (RE) * Exploit development and exploitation

Required Qualifications In addition to meeting all baseline technical requirements for contractor ... Vulnerability Research (VR) * Reverse Engineering (RE) * Exploit development and exploitation

iOS Vulnerability Engineer (Software)

Tysons, VA · On-site

$140K/yr

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

iOS Vulnerability Engineer (Software)

Reston, VA · On-site

$145K/yr

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

next page

Showing results 1-20

Vulnerability Researcher Contractor information

What are the key skills and qualifications needed to thrive as a vulnerability researcher contractor?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a vulnerability researcher contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What does a vulnerability researcher contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

What are popular job titles related to Vulnerability Researcher Contractor jobs in Virginia? For Vulnerability Researcher Contractor jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Vulnerability Researcher Contractor jobs in Virginia look for? The top searched job categories for Vulnerability Researcher Contractor jobs in Virginia are:
What cities in Virginia are hiring for Vulnerability Researcher Contractor jobs? Cities in Virginia with the most Vulnerability Researcher Contractor job openings:

Senior Vulnerability Researcher - Windows / CNE

M9 Solutions

Arlington, VA • On-site

$160K - $220K/yr

Other

Re-posted 23 days ago


Job description

M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations that desire improved performance and modern, sustainable change. M9 has provided quality IT services and support to more than 30 Federal Agencies and multiple commercial customers nationwide. Our capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software Development, and Finance & Accounting.
M9 Solutions is seeking a Senior Vulnerability Researcher - Windows / CNE to work on-site in support of a government contract for a client located in Arlington, VA. An active TS/SCI clearance is required.
Responsibilities
  • Lead advanced vulnerability research on Windows operating systems, applications, and core OS components (including kernel and drivers).
  • Analyze, reverse engineer, and understand complex vulnerabilities to support CNE/CNO missions.
  • Use tools such as IDA Pro, Ghidra, Binary Ninja, and WinDbg/x64dbg for in?depth binary analysis and debugging, including creating or extending custom tooling when needed.
  • Own end?to?end research on difficult, poorly documented Windows targets with minimal guidance, from scoping and experimentation through proof?of?concept.
  • Develop and document technical approaches, findings, and PoCs to validate vulnerabilities and exploitation paths.
  • Continuously explore and prototype novel techniques for vulnerability discovery and exploitation on modern, mitigated Windows platforms.
  • Collaborate with mission and engineering teams to translate research into operational capabilities.
  • Act as the senior technical point of contact and subject?matter expert for Windows vulnerability, exploitation, and OS?internals questions.

Required Skills and Qualifications
  • Active TS/SCI clearance.
  • 3+ years in vulnerability research, exploit development, or CNE?focused reverse engineering, with a sustained focus on Windows (user and kernel mode) rather than general app security or pen?testing.
  • Deep, practical understanding of Windows internals (kernel architecture, drivers, memory management, system calls, process/thread models, and security mechanisms).
  • Strong CNE/CNO background; experience leveraging vulnerabilities in support of real?world operations or mission environments.
  • Demonstrated track record solving very hard, low?level technical problems with minimal guidance, including on research efforts where many others have struggled to make progress.
  • Demonstrated experience discovering and exploiting non?trivial vulnerabilities in modern, mitigated Windows environments (e.g., ASLR, DEP, CFG, virtualization?based security).
  • Hands?on experience with reverse engineering and debugging tools (IDA Pro, Ghidra, Binary Ninja, WinDbg, x64dbg, etc.).
  • Fluency in x86/x64 assembly and strong C/C++ skills, plus scripting experience (e.g., Python) for automation, tooling, and PoCs.
  • Strong analytical mindset and ability to clearly communicate complex technical findings to both technical and non?technical stakeholders.

Full-Time Employee Compensation
  • M9 Solutions' pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include, but are not limited to, responsibilities of the position, education, experience, knowledge, skills, abilities, as well as internal equity, location, alignment with market data, applicable bargaining agreement (if any), or other law.
  • M9 Benefits -

Salary Range
$160,000 - $220,000 USD
M9 Solutions, LLC (M9) is a Federal sub-contractor and we comply with all applicable federal laws prohibiting discrimination in employment, including Title VII of the Civil Rights Act of 1964. We also adhere to the affirmative action requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, ensuring equal opportunity for veterans and individuals with disabilities. Please click to complete M9's Voluntary Self-Identification Form and then email it to . If you need accommodation during the application process or encounter difficulties using our website, please contact our Human Resources Department at or
M9 Solutions is a proud participant in the Virginia Values Veterans (V3) program and supports the Military Medics and Corpsmen (MMAC) initiative, demonstrating our commitment to hiring and supporting veterans, transitioning service members, military spouses, and dependents.
With 15+ years of proven delivery and growth, M9 Solutions is a unique small business with credible past performance and key capabilities offering project management services, solution architects, business analysts, program managers, technical architects, and technical consultants. M9 was recognized as an Inc. 5000 Fastest-Growing Private Companies in 2021, 2020, 2019, 2018, 2017, 2016, and 2012. M9 Solutions believes that work should be fun, rewarding, and something everyone can be excited about. We offer a competitive compensation package and value diverse perspectives in driving the vision of the company.