Назад
Company hidden
обновлено 11 дней назад

Senior Product Security Researcher (Enterprise Browser)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Researcher (Enterprise Browser): Discovering and analyzing vulnerabilities in browser components, operating-system integrations, and enterprise applications with an accent on vulnerability research, security testing, and exploitability assessment. Focus on developing fuzzing and security-testing tooling, modeling threats, prototyping exploits, and supporting secure browser development.

Location: Tel Aviv

Company

hirify.global develops an enterprise browser that embeds security, control, visibility, and governance into a Chromium-based workplace experience.

What you will do

  • Research vulnerabilities in browser components, system integrations, and third-party libraries.
  • Develop custom tooling and automation for security testing, fuzzing, and vulnerability detection.
  • Collaborate with developers, architects, and product security leadership on threat modeling and attack-surface analysis.
  • Build proof-of-concept exploits to validate the impact and exploitability of security issues.
  • Support secure coding practices and contribute to internal security knowledge bases and playbooks.
  • Track emerging exploits and security techniques, and participate in security conferences and the wider security community.

Requirements

  • Strong understanding of browser internals, operating-system security mechanisms, or application-layer security.
  • Proficiency in one or more programming or scripting languages, including Python, JavaScript, C/C++, or Go.
  • Experience in vulnerability research, bug hunting, reverse engineering, or exploit development.
  • Familiarity with vulnerability classes such as remote code execution, memory corruption, and sandbox escapes.
  • Curiosity-driven approach with a passion for breaking systems and understanding how they work.

Nice to have

  • Experience with fuzzing tools, debuggers, or reverse-engineering frameworks.

Culture & Benefits

  • Work with professionals from diverse backgrounds focused on reinventing the modern enterprise workplace.
  • Engage with the broader security community through conferences and knowledge sharing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →