Please mention DailyRemote when applying
We are hiring an exploit developer who has already shipped Android or Linux kernel exploits that work outside a laboratory-perfect setup.
This is a senior individual-contributor role for someone who can take a weak or unstable primitive, model the allocator and concurrency behaviour around it, work through modern mitigations and deliver a robust exploit with clear assumptions and failure modes.
What you’ll work on
- Zero-day and N-day Android kernel vulnerabilities across vendor kernels and device-specific drivers.
- Use-after-free, out-of-bounds access, reference-counting flaws, races, type confusion and logic vulnerabilities.
- Allocator shaping, object replacement, cross-cache techniques, page reuse, reclaim strategies and controlled race amplification.
- Control-flow-independent and data-only exploitation where traditional hijacking is not the best path.
- Target adaptation across kernel branches, Android releases, OEM configurations, SoCs and patch levels.
- Integration with browser and userspace researchers on complete exploit chains.
What you’ll deliver
- Reliable local-privilege-escalation or kernel-code-execution exploit components for modern Android targets.
- Reusable primitives for information disclosure, controlled read/write, object overlap, credential manipulation or equivalent goals.
- Target-aware exploit packages with setup, fingerprinting, diagnostics, cleanup and regression coverage.
- Explicit reliability data, environmental assumptions and known failure modes.
- New techniques for hardened kernels, unstable races or constrained vendor attack surfaces.
What we’re looking for
- A substantial record of delivering working Android or Linux kernel exploits — not only finding bugs or producing crashes.
- Expert knowledge of kernel memory management, object lifetimes, concurrency, locking, scheduling and common driver architectures.
- Advanced SLUB and kernel-heap exploitation experience, including modern cross-cache or page-level techniques.
- Strong ARM64 reverse engineering and debugging skills across source-available and partially proprietary components.
- Practical knowledge of Android GKI, vendor modules, Binder, SELinux and mobile driver attack surfaces.
- Deep familiarity with KASLR, PAN/PXN, CFI, PAC/BTI where relevant, hardened usercopy, refcount hardening and memory-tagging constraints.
- The discipline to turn probabilistic exploitation into maintainable, testable delivery.
Strong signals
- Exploits delivered across several Android OEMs, SoCs or kernel families.
- Original exploitation techniques demonstrated through published research or production-grade exploit delivery.
- Experience with Binder, GPU, multimedia, networking, filesystem, DMA-BUF or OEM driver targets.
- Kernel fuzzing, crash triage, patch analysis and rapid exploitability assessment.
- A history of solving difficult stabilisation and mitigation-bypass problems for other senior engineers.
How we work
- Fully remote, with high autonomy and direct collaboration with vulnerability researchers and exploit developers.
- We care about reliable capability and reproducible engineering, not flashy one-off demos.
- N-day experience is valuable when it demonstrates advanced adaptation and exploitation depth. Public credits are welcome but not required.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!