1

Windows Malware Reverse Engineer Jobs in New Jersey

... malware mitigation. - Automate security analysis, administration and remediation procedures ... TCP/IP, computer networking, routing and switching - Experience in Linux/UNIX and Windows based ...

Showing results 21-40

Windows Malware Reverse Engineer information

What does a Windows Malware Reverse Engineer do?

A Windows Malware Reverse Engineer analyzes malicious software designed to target Windows operating systems. Their primary tasks include dissecting malware to understand how it works, identifying its behavior and purpose, and determining how it infects systems. They use specialized tools and techniques such as disassemblers, debuggers, and virtual environments to safely analyze and decode malware. The insights gained help develop detection methods, improve cybersecurity defenses, and assist in incident response.

What are the key skills and qualifications needed to thrive as a Windows Malware Reverse Engineer?

To thrive as a Windows Malware Reverse Engineer, you need strong knowledge of Windows internals, assembly programming, and malware analysis techniques, usually backed by a degree in computer science or cybersecurity. Proficiency with tools like IDA Pro, Ghidra, OllyDbg, and familiarity with common malware frameworks and relevant certifications such as GIAC Reverse Engineering Malware (GREM) are typically required. Attention to detail, analytical thinking, and strong problem-solving abilities are essential soft skills for unraveling complex threats. These competencies are crucial for identifying, understanding, and mitigating advanced malware threats that target Windows environments.

What are some common challenges faced by Windows Malware Reverse Engineers, and how can they be addressed?

Windows Malware Reverse Engineers often face challenges such as dealing with heavily obfuscated code, rapidly evolving malware techniques, and anti-analysis mechanisms designed to thwart reverse engineering efforts. These challenges require staying up-to-date with the latest tools, regularly practicing with new malware samples, and collaborating with peers to share insights. Building a strong foundation in Windows internals, assembly language, and using debuggers or disassemblers like IDA Pro or Ghidra can help overcome these obstacles and improve overall analysis efficiency.

What is the difference between Windows Malware Reverse Engineer vs Cybersecurity Analyst?

AspectWindows Malware Reverse EngineerCybersecurity Analyst
Required CredentialsKnowledge of reverse engineering, malware analysis, programming skills, certifications like GREM or GREMSecurity certifications like CISSP, CEH, or Security+; broader cybersecurity knowledge
Work EnvironmentSpecialized labs, malware analysis environments, often in security firms or R&D teamsSecurity operations centers, corporate IT teams, or government agencies
Industry UsagePrimarily in cybersecurity, malware research, threat intelligenceAcross industries for threat detection, incident response, and security policy enforcement

While both roles require cybersecurity knowledge, Windows Malware Reverse Engineers focus on dissecting malicious software to understand its mechanics, whereas Cybersecurity Analysts monitor and respond to security threats across organizations. The roles often overlap in skills but differ in daily tasks and focus areas.

Can you reverse engineer malware?

A Windows Malware Reverse Engineer specializes in analyzing malicious software to understand its behavior, origin, and impact. This process involves using tools like debuggers and disassemblers, and requires strong knowledge of assembly language, operating systems, and cybersecurity principles. Reverse engineering malware is a complex task that demands technical skill, patience, and adherence to legal and ethical standards.

How much do Windows Malware Reverse Engineers make?

Windows Malware Reverse Engineers typically earn between $80,000 and $130,000 annually, depending on experience, location, and employer. Advanced skills in reverse engineering tools and malware analysis can lead to higher salaries, especially in cybersecurity-focused organizations.

What are popular job titles related to Windows Malware Reverse Engineer jobs in New Jersey?

For Windows Malware Reverse Engineer jobs in New Jersey, the most frequently searched job titles are:

What job categories do people searching Windows Malware Reverse Engineer jobs in New Jersey look for?

The top searched job categories for Windows Malware Reverse Engineer jobs in New Jersey are:

What cities in New Jersey are hiring for Windows Malware Reverse Engineer jobs?

Cities in New Jersey with the most Windows Malware Reverse Engineer job openings:

Infographic showing various Windows Malware Reverse Engineer job openings in New Jersey as of August 2026, with employment types broken down into 89% Full Time, 6% Part Time, and 5% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorganChase

Jersey City, NJ

$156K - $260K/yr

Full-time

Medical, Retirement

Re-posted 19 days ago


Job description

JOB DESCRIPTION

As an X-Day Offensive Research (XOR) Vulnerability Researcher - Assessments & Exercises at JPMorganChase in the Cybersecurity & Technology Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. In this role, you will design and deploy risk-driven assessments (or manage a highly-skilled team that does) and inform analysis to clearly outline root causes.

We are seeking a dedicated, self-motivated vulnerability researcher to tackle the complex demands of our mission. Working closely with fellow researchers and defense teams, you will investigate challenging targets, uncover novel attack surfaces, and develop innovative solutions that enhance our security posture. The ideal candidate combines deep technical curiosity with a strong background in reverse engineering, static analysis, and dynamic analysis, and thrives in a highly collaborative, research-driven environment.
Job responsibilities 

  • Design and execute testing and simulations – such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations – and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements.
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation.
  • Conduct in-depth vulnerability research and exploit development across a broad range of categories, including operating systems, mobile devices, web applications, browsers, edge devices, and enterprise software.
  • Reverse engineer binaries using tools such as IDA Pro, Ghidra, or Binary Ninja to identify novel attack surfaces and develop proof-of-concept exploits.
  • Use common vulnerability research toolsets such as fuzzers, disassemblers, debuggers, and code browsers for static and dynamic analysis.
  • Perform N-day vulnerability analysis, patch diffing, and proof-of-concept exploit validation.
  • Collaborate with cross-functional teams to develop comprehensive reports – including detailed findings, risk assessments, and remediation recommendations – supporting vulnerability triage, patch prioritization, and the sharing of indicators of compromise (IOCs) in service of the firm's mission requirements.
  • Leverage threat intelligence and security research to stay ahead of emerging threats, vulnerabilities, industry best practices, and regulations, applying this knowledge to enhance the firm's assessment strategy and risk management, and engaging with peers and industry groups that share threat intelligence analytics.
  • Document research findings, proof-of-concepts, and technical workflows to enable knowledge sharing and repeatability.

Required qualifications, capabilities, and skills

  • 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises.
  • Track record of discovered vulnerabilities (CVEs) in high-profile targets in at least one of the following categories: operating systems, mobile devices, web applications, browsers, edge devices, or enterprise software.
  • Proven hands-on experience in vulnerability research, proof-of-concept exploit development, coordinated vulnerability disclosure, and mitigating security vulnerabilities in open-source projects.
  • Expertise in advanced analysis frameworks leveraging symbolic execution techniques and dynamic binary instrumentation to identify, triage, and exploit complex software vulnerabilities.
  • Hands-on proficiency exploiting complex vulnerability classes – including use-after-free, double free, type confusion – and applying advanced exploitation techniques such as heap spraying and controlled memory corruption to achieve reliable code execution.
  • Strong understanding of the internals of at least two operating systems throughout user mode and kernel mode (Microsoft Windows, GNU/Linux, Android, macOS, or iOS).
  • Experience auditing large C/C++, Java, and .NET codebases combining automated static analyzers with manual review to trace data and control flow, uncover memory-safety, injection, and deserialization vulnerabilities and produce proof-of-concept code.
  • Extensive reverse engineering expertise on x86/x64 and ARM/ARM64 binaries, employing IDA Pro, Ghidra, Binary Ninja, WinDbg, GDB, and RR for deep static/dynamic analysis and root cause vulnerability discovery.
  • Knowledge of US financial services sector cybersecurity or resiliency organization practices, operational risk management processes, principles, regulations, threats, risks, and incident response methodologies.
  • Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents.
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels.

Preferred qualifications, capabilities, and skills 

  • Bachelor's degree in computer science, or PhD in a related technical field, or an equivalent combination of education and/or experience in a related field.
  • 5+ years of experience in vulnerability research and exploit development.
  • Experience using fuzzing tools such as LibFuzzer, LibAFL, AFL++, OSS-Fuzz, and Syzkaller.
  • Experience using program analysis tools such as LLVM, Angr, KLEE, Intel Pin, DynamoRIO, and Frida.
  • Experience emulating embedded platforms for live debugging.
  • Experience with kernel and low-level operating system development.
  • Deep Linux internals knowledge (SELinux, AppArmor, Seccomp, eBPF, containers, VMs).
  • Deep Windows internals knowledge (KASLR, DSE, SSDT, IDT, SMEP, SMAP, PXN, KPP, KDP, VBS, HVCI, KMCI, UMCI).

#CTC

ABOUT US
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans


ABOUT THE TEAM
The Cybersecurity & Technology Controls group at JPMorganChase aligns the firm's cybersecurity, access management, controls and resiliency teams. The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls. The group's number one priority is to enable the business by keeping the firm safe, stable and resilient.

High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters. Users in these roles are subject to enhanced pre-hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.