
Senior Offensive Security Researcher, GPU System Software
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in California, +3 more states.
• Take ownership of the complete security narrative for designated subcomponents, encompassing threat modeling, hardening, and verification.
• Conceptualize, prototype, and promote the adoption of mitigation and hardening technologies, including hardware Control Flow Integrity (CFI), Pointer Masking, and Memory Tagging.
• Develop and advocate for tools, methodologies, and processes that enhance product resilience throughout the organization.
• Conduct offensive security research on GPU and platform firmware, microcode, kernel drivers, and embedded software.
• Detect vulnerabilities, create proof-of-concept exploits, and collaborate with development teams to address them.
• Execute threat assessments and security evaluations of both software and hardware designs.
• Bachelor’s degree in Electrical or Computer Engineering, Computer Science, or equivalent experience.
• Over 12 years of pertinent software engineering or security research experience.
• Proven experience in an offensive security capacity.
• Strong skills in C and assembly, with practical low-level driver or firmware experience.
• Experience in vulnerability research, including fuzzing, static and dynamic analysis, exploit development, and coverage-guided techniques.
• Familiarity with secure development lifecycle practices such as threat modeling, code auditing, and incident response.
• Experience in utilizing AI and LLM-based tools for vulnerability discovery, triage, or analysis.
• Capacity to work collaboratively and remotely on intricate, cross-team objectives.
• Expertise in firmware or embedded reverse engineering, particularly on RISC-V or other non-x86 architectures.
• Experience in designing hardware or compiler-assisted mitigations from scratch, including modifications to compilers (LLVM, GCC).
• Understanding of computer architecture fundamentals: caches, buses, memory controllers, DMA, MMUs, and IOMMUs.
• Familiarity with formally verifiable languages or methods (SPARK, Ada, Rust, model checking).
• Published research, such as presentations at Black Hat or DEF CON, or articles in publications like Phrack.
• Equity
• Benefits
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.