Investigador de Vulnerabilidades

Posted yesterday

krollNew York (NY)

SENIORITY

Lead

Apply

About the role

You choose research targets, build the tooling to test them at scale (typically fuzzing harnesses), run those campaigns over days or weeks, and analyse the crashes that come out to determine which are exploitable. Most results are not security-relevant; the role exists for the small proportion that are. Confirmed findings are taken through coordinated disclosure with the vendor until a fix is released.
What you will do: Choose targets and justify the choice Build fuzzing harnesses and the triage around them Take findings through coordinated disclosure to a fix What they ask for: Reverse engineering in a real disassembler C and one systems language A credited CVE, or work you can walk through in equivalent depth
Nice to have: Exploit development Kernel or browser internals Conference talks

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this