Security Researcher - Linux Kernel

Apply Now

Position Summary

In this offense-focused role, you will research and develop exploits against a variety of Linux kernels: upstream, distribution, as well as grsecurity's own security-enhanced kernels. Proof-of-concept exploits will be developed for published vulnerabilities, and fully-developed exploits will be written to demonstrate grsecurity's defense capabilities.

This is an exciting position for the right candidate obsessed with Linux kernel security to dig deep into the current mainstream state of security as well as getting a peek into what exploitation will look like in the next decade.

Essential Functions

  • Develop proof-of-concept exploits for published vulnerabilities
  • Work with our team to evaluate/iterate on proposed defenses
  • Develop next-generation attacks against grsecurity kernels to inform future defenses
  • Assist in development of content for Customer Knowledge Base, blog posts
  • Speak publicly at conferences on results of research

Education and Qualifications

  • Bachelor's or higher level degree in Computer Science/Engineering, OR a large corpus of published code
  • Expert in C development and specification
  • Experience in C++ development/exploitation
  • Familiarity with git, binutils, GCC, Clang
  • 5+ years experience in exploit development and security research, with 3+ years focused on the Linux kernel
  • Knowledge of common mistakes and vulnerabilities in the Linux kernel
  • Experience in exploiting speculation-based side channels
  • Strong x86 reverse-engineering/assembly skills
  • Deep low-level knowledge of x86 and one or more of ARM/ARM64/PowerPC
  • Excellent verbal and written communication skills
  • Publisher of public blog posts, speaker at security conferences
  • Self-motivated and eager to learn

Benefits

  • Remote employment available
  • Flexible working hours
  • Annual bonus program
  • Training budget
  • US-only: generous 401(k) matching program - 100% up to 6% of salary, immediate vesting
  • Health/dental/vision insurance
  • Private offices available in Lancaster PA
  • Working in an R&D-heavy company driving the state of the art in security
  • Conference travel (when in-person is possible again)
  • Opportunity to grow your security research talents to impact the next generation of security defenses