Skip to main content

Browser - Vulnerability Researcher

RemoteWorldwide
Published
Role
Security
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Experienced browser vulnerability researcher who has already found and exploited production-browser bugs. Needs deep Chromium/V8 internals, C/C++ debugging, reverse engineering, source-audit skills, and practical exploit development under modern mitigations.

Core skills

ChromiumV8Browser exploitation

Required skills

CC++Reverse engineering

Optional skills

WebKitFirefoxCustom browser buildsSanitizersSource instrumentationTargeted fuzzing harnesses

What you'll do

  • Renderer-reachable attack surfaces in Chromium, with room to work on WebKit or Firefox where relevant.
  • Memory-corruption and logic vulnerabilities in V8, Blink, WebAssembly, DOM bindings, parsers, media, graphics and adjacent C/C++ components.
  • Exploitation under modern constraints including pointer compression, heap isolation, control-flow protections and the V8 Sandbox (formerly commonly referred to as the Ubercage).
  • Variant analysis, patch diffing and adjacent-code research rather than stopping after a single bug.
  • Collaboration with sandbox, platform and kernel researchers when a renderer issue is part of a larger chain.
  • Original browser vulnerabilities with a clear root cause and reliable reproduction.
  • Working exploit primitives or chain components that survive realistic release-build mitigations.
  • Minimised test cases, exploitability analysis, affected-version notes and reproducible research environments.
  • Readable exploit code and technical documentation that another senior researcher can pick up and extend.
  • Tooling that improves fuzzing, instrumentation, crash triage, variant hunting or exploit-development speed.

What they require

  • A proven record of delivering browser vulnerabilities or exploit components against modern browser releases.
  • Deep practical knowledge of Chromium internals, ideally including both the renderer and V8.
  • Strong C/C++ debugging, reverse engineering and source-audit skills.
  • Hands-on experience turning use-after-free, type confusion, out-of-bounds access or related bug classes into useful primitives.
  • A real understanding of the V8 Sandbox security model and how it changes exploitation strategy.
  • The judgement to distinguish an interesting crash from a chainable, operationally meaningful vulnerability.
  • The ability to work independently and finish difficult research without constant direction.
  • Preferred: Browser CVEs, Pwn2Own-level work or comparable real-world exploit delivery.
  • Preferred: Exploit-chain work across Android, iOS, macOS, Windows or Linux.
  • Preferred: Research on JITs, garbage-collected heaps, cross-language ownership.
  • Preferred: A history of raising the technical level of other experienced researchers.
  • Public credits are useful but not required.

Benefits

  • Fully remote, with high autonomy and direct access to other senior researchers and exploit developers.

An established offensive-security organisation with a large team of senior and principal-level vulnerability researchers and exploit developers.

Cybersecurity
Salary not disclosed