Skip to content
← Back to job listings

Android Kernel - Exploit Developer

Trenchant · Remote

Diagnostics / LaboratoryRemoteQuick applyfull-time1 day ago

About The Role

We are hiring an exploit developer who has already shipped Android or Linux kernel exploits that work outside a laboratory-perfect setup.

This is a senior individual-contributor role for someone who can take a weak or unstable primitive, model the allocator and concurrency behaviour around it, work through modern mitigations and deliver a robust exploit with clear assumptions and failure modes.

What you’ll work on

  • Zero-day and N-day Android kernel vulnerabilities across vendor kernels and device-specific drivers.
  • Use-after-free, out-of-bounds access, reference-counting flaws, races, type confusion and logic vulnerabilities.
  • Allocator shaping, object replacement, cross-cache techniques, page reuse, reclaim strategies and controlled race amplification.
  • Control-flow-independent and data-only exploitation where traditional hijacking is not the best path.
  • Target adaptation across kernel branches, Android releases, OEM configurations, SoCs and patch levels.
  • Integration with browser and userspace researchers on complete exploit chains.

What you’ll deliver

  • Reliable local-privilege-escalation or kernel-code-execution exploit components for modern Android targets.
  • Reusable primitives for information disclosure, controlled read/write, object overlap, credential manipulation or equivalent goals.
  • Target-aware exploit packages with setup, fingerprinting, diagnostics, cleanup and regression coverage.
  • Explicit reliability data, environmental assumptions and known failure modes.
  • New techniques for hardened kernels, unstable races or constrained vendor attack surfaces.

What we’re looking for

  • A substantial record of delivering working Android or Linux kernel exploits — not only finding bugs or producing crashes.
  • Expert knowledge of kernel memory management, object lifetimes, concurrency, locking, scheduling and common driver architectures.
  • Advanced SLUB and kernel-heap exploitation experience, including modern cross-cache or page-level techniques.
  • Strong ARM64 reverse engineering and debugging skills across source-available and partially proprietary components.
  • Practical knowledge of Android GKI, vendor modules, Binder, SELinux and mobile driver attack surfaces.
  • Deep familiarity with KASLR, PAN/PXN, CFI, PAC/BTI where relevant, hardened usercopy, refcount hardening and memory-tagging constraints.
  • The discipline to turn probabilistic exploitation into maintainable, testable delivery.

Strong signals

  • Exploits delivered across several Android OEMs, SoCs or kernel families.
  • Original exploitation techniques demonstrated through published research or production-grade exploit delivery.
  • Experience with Binder, GPU, multimedia, networking, filesystem, DMA-BUF or OEM driver targets.
  • Kernel fuzzing, crash triage, patch analysis and rapid exploitability assessment.
  • A history of solving difficult stabilisation and mitigation-bypass problems for other senior engineers.

How we work

  • Fully remote, with high autonomy and direct collaboration with vulnerability researchers and exploit developers.
  • We care about reliable capability and reproducible engineering, not flashy one-off demos.
  • N-day experience is valuable when it demonstrates advanced adaptation and exploitation depth. Public credits are welcome but not required.

This listing was posted by a verified recruiter at Trenchant. Report this listing