Назад
Company hidden
2 месяца назад

Android Security Researcher (Digital Forensics)

Тип работы
fulltime
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Android Security Researcher (Digital Forensics): Developing capabilities to extract evidence from modern mobile devices and embedded systems with an accent on vulnerability research and exploit development. Focus on bypassing hardware-backed encryption, secure boot chains, and ARM TrustZone secure worlds.

Location: Israel - Tel Aviv

Company

hirify.global is a global leader in digital intelligence, providing AI-powered platforms for lawful digital evidence collection and analysis to protect and save lives.

What you will do

  • Lead and participate in vulnerability research projects in unexplored territories.
  • Produce unique capabilities to extract evidence from modern mobile phones and other embedded devices.
  • Analyze and bypass hardware-backed encryption (FDE/FBE) and secure boot chains (Verified Boot/dm-verity).
  • Navigate and exploit hardened SELinux policies and ARM TrustZone secure worlds.
  • Engineer platform-wide native payloads within fragmented device ecosystems.

Requirements

  • Practical experience performing vulnerability research and exploitation in mobile or modern environments (Windows, Linux, iOS, or MacOS).
  • Practical reverse engineering experience, specifically with ARM, TrustZone, or Hypervisors.
  • Commitment to the ethical use of security research for the purpose of lawful evidence extraction.

Nice to have

  • Knowledge of cryptographic primitives and weaknesses.
  • Experience with advanced fuzzing techniques.
  • Offensive hardware research or board design experience.
  • Experience dealing with modern memory corruption mitigations, such as PAC and MTE.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →