Trenchant (L3Harris)
Posted 2w ago

Android Kernel - Exploit Developer

Trenchant (L3Harris)
United States
RemoteFull Time
Responsibilities
  • developing exploits
  • analyzing kernels
  • stabilizing exploits
Requirements
  • Proven track record delivering Android or Linux kernel exploits
  • Expert kernel memory
  • Concurrency
  • Allocator and SLUB exploitation knowledge
  • Strong ARM64 reverse-engineering
  • Familiarity with Android GKI, Binder and SELinux
Technical tools mentioned
AndroidLinuxARM64Android GKIBinderSELinux

Job description

We are hiring an exploit developer who has already shipped Android or Linux kernel exploits that work outside a laboratory-perfect setup.

This is a senior individual-contributor role for someone who can take a weak or unstable primitive, model the allocator and concurrency behaviour around it, work through modern mitigations and deliver a robust exploit with clear assumptions and failure modes.

What you’ll work on

- Zero-day and N-day Android kernel vulnerabilities across vendor kernels and device-specific drivers.

- Use-after-free, out-of-bounds access, reference-counting flaws, races, type confusion and logic vulnerabilities.

- Allocator shaping, object replacement, cross-cache techniques, page reuse, reclaim strategies and controlled race amplification.

- Control-flow-independent and data-only exploitation where traditional hijacking is not the best path.

- Target adaptation across kernel branches, Android releases, OEM configurations, SoCs and patch levels.

- Integration with browser and userspace researchers on complete exploit chains.

What you’ll deliver

- Reliable local-privilege-escalation or kernel-code-execution exploit components for modern Android targets.

- Reusable primitives for information disclosure, controlled read/write, object overlap, credential manipulation or equivalent goals.

- Target-aware exploit packages with setup, fingerprinting, diagnostics, cleanup and regression coverage.

- Explicit reliability data, environmental assumptions and known failure modes.

- New techniques for hardened kernels, unstable races or constrained vendor attack surfaces.

What we’re looking for

- A substantial record of delivering working Android or Linux kernel exploits — not only finding bugs or producing crashes.

- Expert knowledge of kernel memory management, object lifetimes, concurrency, locking, scheduling and common driver architectures.

- Advanced SLUB and kernel-heap exploitation experience, including modern cross-cache or page-level techniques.

- Strong ARM64 reverse engineering and debugging skills across source-available and partially proprietary components.

- Practical knowledge of Android GKI, vendor modules, Binder, SELinux and mobile driver attack surfaces.

- Deep familiarity with KASLR, PAN/PXN, CFI, PAC/BTI where relevant, hardened usercopy, refcount hardening and memory-tagging constraints.

- The discipline to turn probabilistic exploitation into maintainable, testable delivery.

Strong signals

- Exploits delivered across several Android OEMs, SoCs or kernel families.

- Original exploitation techniques demonstrated through published research or production-grade exploit delivery.

- Experience with Binder, GPU, multimedia, networking, filesystem, DMA-BUF or OEM driver targets.

- Kernel fuzzing, crash triage, patch analysis and rapid exploitability assessment.

- A history of solving difficult stabilisation and mitigation-bypass problems for other senior engineers.

How we work

- Fully remote, with high autonomy and direct collaboration with vulnerability researchers and exploit developers.

- We care about reliable capability and reproducible engineering, not flashy one-off demos.

- N-day experience is valuable when it demonstrates advanced adaptation and exploitation depth. Public credits are welcome but not required.

About Trenchant (L3Harris)

Specialized cyber division providing offensive security and vulnerability research.

Similar jobs

Exploit Developer roles
4mo
Save
Mark Applied
Hide
Sr. Exploit Developer
Maryland or United States
RemoteFull Time
VulnCheck
VulnCheck: Provides real-time vulnerability and exploit intelligence data.
Experience in reverse engineering and exploit development; remote work with small teams; ability to produce initial access exploits or demonstrate example exploit code.
Suricata, Snort, YARA, Shodan, Census, FOFA, ZoomEye, Go-exploit
1y
Save
Mark Applied
Hide
Exploit Developer - All Levels
Annapolis Junction, Maryland, United States
OnsiteFull Time
Interclypse
Interclypse: Provides software engineering and cybersecurity solutions for government agencies.
BS in computer engineering/science; Python and C/C++; experience with Linux/Windows/iOS/Android; assembly; software lifecycles; networking; reverse engineering; mobile/embedded development.
Python, C/C++, Linux, Windows, iOS, Android, Assembly, Networking, Reverse Engineering
6y
Save
Mark Applied
Hide
Exploit Developer - TS/SCI Full Scope Polygraph
Columbia, Maryland, United States
OnsiteFull Time
GRIMM
GRIMM: Provides advanced cybersecurity research, engineering, and consulting services.
2+ YOEMinimum 2 years of experience in exploit development, vulnerability analysis, and programming. Must have a Bachelor Degree in a related field.
JavaScript, C Programming, ARM Assembly, IDA Pro, Binary Ninja, Ghidra
2w
Save
Mark Applied
Hide
Threat Emulation and Exploit Engineer
Dallas or Charlotte or Malvern or Plano
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
5+ YOERequires 5+ years of related experience, including 3 years in threat analysis, a related undergraduate degree or equivalent, and offensive security experience in penetration testing, vulnerability analysis, web security, adversary emulation, and threat intelligence.
2w
Save
Mark Applied
Hide
Threat Emulation and Exploit Engineer
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
5+ YOE5+ years related experience with 3+ years in threat analysis; undergraduate degree or equivalent; experience in offensive security, penetration testing, vulnerability analysis, adversary emulation; OSCP/OSWA preferred; strong collaboration skills.