Now hiring

Browser - Vulnerability Researcher @ Trenchant

GlobalOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

You will join an established offensive-security organisation with a large team of senior and principal-level vulnerability researchers and exploit developers. Our browser research is focused on producing working exploit capability — not just crashes, reports or theoretical attack paths. This role is for a researcher who has already found and exploited vulnerabilities in production browsers. You should be comfortable owning the full path from attack-surface selection and root-cause analysis to reliable primitives, exploitability decisions and clean technical handover.

What you’ll work on

- Renderer-reachable attack surfaces in Chromium, with room to work on WebKit or Firefox where relevant.

- Memory-corruption and logic vulnerabilities in V8, Blink, WebAssembly, DOM bindings, parsers, media, graphics and adjacent C/C++ components.

- Exploitation under modern constraints including pointer compression, heap isolation, control-flow protections and the V8 Sandbox (formerly commonly referred to as the Ubercage).

- Variant analysis, patch diffing and adjacent-code research rather than stopping after a single bug.

- Collaboration with sandbox, platform and kernel researchers when a renderer issue is part of a larger chain.

What you’ll deliver

- Original browser vulnerabilities with a clear root cause and reliable reproduction.

- Working exploit primitives or chain components that survive realistic release-build mitigations.

- Minimised test cases, exploitability analysis, affected-version notes and reproducible research environments.

- Readable exploit code and technical documentation that another senior researcher can pick up and extend.

- Tooling that improves fuzzing, instrumentation, crash triage, variant hunting or exploit-development speed.

What we’re looking for

- A proven record of delivering browser vulnerabilities or exploit components against modern browser releases.

- Deep practical knowledge of Chromium internals, ideally including both the renderer and V8.

- Strong C/C++ debugging, reverse engineering and source-audit skills.

- Hands-on experience turning use-after-free, type confusion, out-of-bounds access or related bug classes into useful primitives.

- A real understanding of the V8 Sandbox security model and how it changes exploitation strategy.

- The judgement to distinguish an interesting crash from a chainable, operationally meaningful vulnerability.

- The ability to work independently and finish difficult research without constant direction.

Strong signals

- Browser CVEs, Pwn2Own-level work or comparable real-world exploit delivery.

- Experience with custom browser builds, sanitizers, source instrumentation and targeted fuzzing harnesses.

- Exploit-chain work across Android, iOS, macOS, Windows or Linux.

- Research on JITs, garbage-collected heaps, cross-language ownership.

- A history of raising the technical level of other experienced researchers.

How we work

- Fully remote, with high autonomy and direct access to other senior researchers and exploit developers.

- We care about completed, reproducible technical delivery.

- Public credits are useful but not required.

Skills

VR

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores