About the job
M9 Solutions is committed to delivering exceptional IT services and solutions to the Federal Government. We mobilize the right talent, skills, clearance levels, and technologies to assist organizations in achieving enhanced performance and sustainable change. With a proven track record of providing quality IT services to over 30 Federal Agencies and numerous commercial clients nationwide, our expertise includes digital transformation, software development, cloud migration, cybersecurity, data analytics, and IT talent solutions.
M9 Solutions is actively seeking an experienced Windows CNO Developer to join our team on-site in support of a government contract in Arlington, VA. An active TS/SCI clearance is mandatory for this role.
Key Responsibilities:
- Research, identify, and analyze Windows kernel vulnerabilities, including privilege escalation, sandbox escapes, and persistence mechanisms.
- Design, develop, and maintain CNO/CNE tools targeting Windows platforms (both kernel and user mode) from proof-of-concept to operational-grade capabilities.
- Conduct advanced reverse engineering of Windows binaries, drivers, and system components to assess behavior, exploitability, and mitigation strategies using tools such as IDA Pro, Ghidra, and WinDbg.
- Create kernel-mode and user-mode code in C/C++ and Assembly to implement implants, loaders, and exploit chains, focusing on reliability and stealth.
- Develop and test exploitation techniques for complex Windows targets, including modern protection bypasses (ASLR, DEP, CFG, kernel mitigations) in collaboration with cyber research teams.
- Integrate CNO capabilities into mission frameworks and tasking/dataflow pipelines, ensuring configuration, logging, and secure communications.
- Execute debugging and troubleshooting of low-level software in lab and operational-like environments, including crash triage and performance analysis.
- Work closely with analysts, operators, and other engineers to ensure capabilities align with mission requirements, providing technical guidance on feasibility and trade-offs.
- Produce comprehensive technical documentation (designs, CONOPs, usage guides) and contribute to secure coding standards and internal best practices.

