← Back to job listings
T
Android Kernel - Exploit Developer
Trenchant · Remote
About The Role
We are hiring an exploit developer who has already shipped Android or Linux kernel exploits that work outside a laboratory-perfect setup.
This is a senior individual-contributor role for someone who can take a weak or unstable primitive, model the allocator and concurrency behaviour around it, work through modern mitigations and deliver a robust exploit with clear assumptions and failure modes.
What you’ll work on
- Zero-day and N-day Android kernel vulnerabilities across vendor kernels and device-specific drivers.
- Use-after-free, out-of-bounds access, reference-counting flaws, races, type confusion and logic vulnerabilities.
- Allocator shaping, object replacement, cross-cache techniques, page reuse, reclaim strategies and controlled race amplification.
- Control-flow-independent and data-only exploitation where traditional hijacking is not the best path.
- Target adaptation across kernel branches, Android releases, OEM configurations, SoCs and patch levels.
- Integration with browser and userspace researchers on complete exploit chains.
What you’ll deliver
- Reliable local-privilege-escalation or kernel-code-execution exploit components for modern Android targets.
- Reusable primitives for information disclosure, controlled read/write, object overlap, credential manipulation or equivalent goals.
- Target-aware exploit packages with setup, fingerprinting, diagnostics, cleanup and regression coverage.
- Explicit reliability data, environmental assumptions and known failure modes.
- New techniques for hardened kernels, unstable races or constrained vendor attack surfaces.
What we’re looking for
- A substantial record of delivering working Android or Linux kernel exploits — not only finding bugs or producing crashes.
- Expert knowledge of kernel memory management, object lifetimes, concurrency, locking, scheduling and common driver architectures.
- Advanced SLUB and kernel-heap exploitation experience, including modern cross-cache or page-level techniques.
- Strong ARM64 reverse engineering and debugging skills across source-available and partially proprietary components.
- Practical knowledge of Android GKI, vendor modules, Binder, SELinux and mobile driver attack surfaces.
- Deep familiarity with KASLR, PAN/PXN, CFI, PAC/BTI where relevant, hardened usercopy, refcount hardening and memory-tagging constraints.
- The discipline to turn probabilistic exploitation into maintainable, testable delivery.
Strong signals
- Exploits delivered across several Android OEMs, SoCs or kernel families.
- Original exploitation techniques demonstrated through published research or production-grade exploit delivery.
- Experience with Binder, GPU, multimedia, networking, filesystem, DMA-BUF or OEM driver targets.
- Kernel fuzzing, crash triage, patch analysis and rapid exploitability assessment.
- A history of solving difficult stabilisation and mitigation-bypass problems for other senior engineers.
How we work
- Fully remote, with high autonomy and direct collaboration with vulnerability researchers and exploit developers.
- We care about reliable capability and reproducible engineering, not flashy one-off demos.
- N-day experience is valuable when it demonstrates advanced adaptation and exploitation depth. Public credits are welcome but not required.
This listing was posted by a verified recruiter at Trenchant. Report this listing
JobSpring