Browser - Vulnerability Researcher @Trenchant
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Browser - Vulnerability Researcher @Trenchant

2mths ago - Trenchant is hiring a remote Browser - Vulnerability Researcher. πŸ’Έ Salary: unspecified πŸ“Location: Worldwide

Role Description

You will join an established offensive-security organisation with a large team of senior and principal-level vulnerability researchers and exploit developers. Our browser research is focused on producing working exploit capability β€” not just crashes, reports or theoretical attack paths. This role is for a researcher who has already found and exploited vulnerabilities in production browsers. You should be comfortable owning the full path from attack-surface selection and root-cause analysis to reliable primitives, exploitability decisions and clean technical handover.

What you’ll work on

  • Renderer-reachable attack surfaces in Chromium, with room to work on WebKit or Firefox where relevant.
  • Memory-corruption and logic vulnerabilities in V8, Blink, WebAssembly, DOM bindings, parsers, media, graphics and adjacent C/C++ components.
  • Exploitation under modern constraints including pointer compression, heap isolation, control-flow protections and the V8 Sandbox (formerly commonly referred to as the Ubercage).
  • Variant analysis, patch diffing and adjacent-code research rather than stopping after a single bug.
  • Collaboration with sandbox, platform and kernel researchers when a renderer issue is part of a larger chain.

What you’ll deliver

  • Original browser vulnerabilities with a clear root cause and reliable reproduction.
  • Working exploit primitives or chain components that survive realistic release-build mitigations.
  • Minimised test cases, exploitability analysis, affected-version notes and reproducible research environments.
  • Readable exploit code and technical documentation that another senior researcher can pick up and extend.
  • Tooling that improves fuzzing, instrumentation, crash triage, variant hunting or exploit-development speed.

Qualifications

  • A proven record of delivering browser vulnerabilities or exploit components against modern browser releases.
  • Deep practical knowledge of Chromium internals, ideally including both the renderer and V8.
  • Strong C/C++ debugging, reverse engineering and source-audit skills.
  • Hands-on experience turning use-after-free, type confusion, out-of-bounds access or related bug classes into useful primitives.
  • A real understanding of the V8 Sandbox security model and how it changes exploitation strategy.
  • The judgement to distinguish an interesting crash from a chainable, operationally meaningful vulnerability.
  • The ability to work independently and finish difficult research without constant direction.

Requirements

  • Browser CVEs, Pwn2Own-level work or comparable real-world exploit delivery.
  • Experience with custom browser builds, sanitizers, source instrumentation and targeted fuzzing harnesses.
  • Exploit-chain work across Android, iOS, macOS, Windows or Linux.
  • Research on JITs, garbage-collected heaps, cross-language ownership.
  • A history of raising the technical level of other experienced researchers.

How we work

  • Fully remote, with high autonomy and direct access to other senior researchers and exploit developers.
  • We care about completed, reproducible technical delivery.
  • Public credits are useful but not required.
Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Browser - Vulnerability Researcher @Trenchant
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,118+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later