Trenchant

Android Kernel - Exploit Developer

Trenchant

IT Services and IT Consulting · 2-10 employees

2 d ago
Remote Senior (5-10 yrs) Full-time
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Develop robust, reliable Android and Linux kernel exploits for zero-day and N-day vulnerabilities. Collaborate with researchers to deliver target-aware exploit packages including diagnostics, cleanup, and regression coverage.

What they look for

Android Kernel Linux Kernel Exploit Development ARM64 Reverse Engineering Memory Management Kernel Heap Exploitation SLUB Vulnerability Research Binder SELinux Debugging CFI KASLR PAC/BTI Driver Development

Requirements

Requires a substantial record of delivering working Android or Linux kernel exploits and expert knowledge of kernel memory management and concurrency. Candidates must possess advanced ARM64 reverse engineering skills and deep familiarity with modern kernel mitigations.

Full description

We are hiring an exploit developer who has already shipped Android or Linux kernel exploits that work outside a laboratory-perfect setup.

This is a senior individual-contributor role for someone who can take a weak or unstable primitive, model the allocator and concurrency behaviour around it, work through modern mitigations and deliver a robust exploit with clear assumptions and failure modes.

What you’ll work on

- Zero-day and N-day Android kernel vulnerabilities across vendor kernels and device-specific drivers.

- Use-after-free, out-of-bounds access, reference-counting flaws, races, type confusion and logic vulnerabilities.

- Allocator shaping, object replacement, cross-cache techniques, page reuse, reclaim strategies and controlled race amplification.

- Control-flow-independent and data-only exploitation where traditional hijacking is not the best path.

- Target adaptation across kernel branches, Android releases, OEM configurations, SoCs and patch levels.

- Integration with browser and userspace researchers on complete exploit chains.

What you’ll deliver

- Reliable local-privilege-escalation or kernel-code-execution exploit components for modern Android targets.

- Reusable primitives for information disclosure, controlled read/write, object overlap, credential manipulation or equivalent goals.

- Target-aware exploit packages with setup, fingerprinting, diagnostics, cleanup and regression coverage.

- Explicit reliability data, environmental assumptions and known failure modes.

- New techniques for hardened kernels, unstable races or constrained vendor attack surfaces.

What we’re looking for

- A substantial record of delivering working Android or Linux kernel exploits — not only finding bugs or producing crashes.

- Expert knowledge of kernel memory management, object lifetimes, concurrency, locking, scheduling and common driver architectures.

- Advanced SLUB and kernel-heap exploitation experience, including modern cross-cache or page-level techniques.

- Strong ARM64 reverse engineering and debugging skills across source-available and partially proprietary components.

- Practical knowledge of Android GKI, vendor modules, Binder, SELinux and mobile driver attack surfaces.

- Deep familiarity with KASLR, PAN/PXN, CFI, PAC/BTI where relevant, hardened usercopy, refcount hardening and memory-tagging constraints.

- The discipline to turn probabilistic exploitation into maintainable, testable delivery.

Strong signals

- Exploits delivered across several Android OEMs, SoCs or kernel families.

- Original exploitation techniques demonstrated through published research or production-grade exploit delivery.

- Experience with Binder, GPU, multimedia, networking, filesystem, DMA-BUF or OEM driver targets.

- Kernel fuzzing, crash triage, patch analysis and rapid exploitability assessment.

- A history of solving difficult stabilisation and mitigation-bypass problems for other senior engineers.

How we work

- Fully remote, with high autonomy and direct collaboration with vulnerability researchers and exploit developers.

- We care about reliable capability and reproducible engineering, not flashy one-off demos.

- N-day experience is valuable when it demonstrates advanced adaptation and exploitation depth. Public credits are welcome but not required.