Legato, LLC recruiters ([email protected]) would love to speak with you regarding the following position: Windows CNO Developer in Dulles, VA. Security Clearance Required: TS/SCI minimum. This role involves researching, identifying, and characterizing Windows kernel vulnerabilities, including privilege escalation, sandbox escapes, and persistence mechanisms. You will design, develop, and maintain CNO/CNE tools and capabilities targeting Windows platforms (kernel and user mode), from proof-of-concept to operational-grade capability. The position requires performing advanced reverse engineering of Windows binaries, drivers, and system components to understand behavior, exploitability, and mitigation paths using tools like IDA Pro, Ghidra, and WinDbg. You will develop kernel-mode and user-mode code in C/C++ and Assembly to implement implants, loaders, and exploit chains, with a focus on reliability and stealth. Creating and testing exploitation techniques for complex Windows targets, including bypasses for modern protections (ASLR, DEP, CFG, kernel mitigations), in partnership with cyber research teams is also a key responsibility. Integrating CNO capabilities into mission frameworks and tasking/dataflow pipelines, including configuration, logging, and secure communications, is expected. Conducting debugging and troubleshooting of low-level software in lab and operational-like environments, including crash triage and performance analysis, is part of the role. You will collaborate closely with analysts, operators, and other engineers to align capabilities with mission requirements and provide technical guidance on feasibility and trade-offs. Producing clear technical documentation (designs, CONOPs, usage guides) and contributing to secure coding standards and internal best practices are also required.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed
Number of Employees
1-10 employees