Base Career helps you apply smarter for this job.
Key skills for this role
- Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.
- GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.
- Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.
- Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.
- Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.
- End-to-end chains with renderer and Android-kernel researchers when needed.
- Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.
- Reliable sandbox-escape exploit components that work under production mitigations.
- Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.
- Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.
- Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.
- Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.
- Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.
- Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
North Sydney, AUS
, USA
- Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.
- Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.
- The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.
- Independent research ownership and a consistent history of finishing high-difficulty work.
- Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.
- Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.
- Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.
- Research across multiple Android OEMs, chipsets and Chrome branches.
- vulnerabilities found made it to stable/beta releases.
- Strong patch-analysis and variant-hunting results.
- Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.
- We measure progress through technically meaningful, reproducible delivery.
- Public CVEs are not a requirement.
Verified company details for this employer are not available yet.
Full-time
Senior
Remote
Apply faster on company sites with our extension.