About project
We are a Barcelona-based R&D center seeking Vulnerability Researchers/Security Researchers to join our team. The role focuses on hands-on vulnerability research, including finding and exploiting vulnerabilities in complex systems such as browsers, kernels, mobile and desktop operating systems. We offer full-time remote work as well as relocation opportunities to Barcelona. Flexible working hours are supported depending on productivity and time zones.
Your area of responsibility
Detect, analyze, and exploit vulnerabilities;
Conduct vulnerability research across browsers, kernels, mobile and desktop operating systems, and other complex software;
Understand the technical details of vulnerabilities and assess their real impact;
Develop exploits, proof-of-concept code, scripts, and software modules to validate vulnerabilities;
Perform reverse engineering and binary analysis as part of vulnerability research;
Reverse-engineer security patches to better understand vulnerabilities;
Use fuzzing and other research techniques to discover vulnerabilities;
Effectively communicate vulnerability findings and their technical impact;
Assist in the development of tools for vulnerability and security research.
Skills and requirements
Proven hands-on experience in vulnerability research and vulnerability exploitation;
Experience in exploit development;
Experience in finding vulnerabilities in complex systems;
Experience with reverse engineering;
Knowledge of OS internals;
Knowledge of modern exploitation techniques;
Experience researching at least one of the following areas: browsers, kernels, mobile OSes, desktop OSes, or embedded systems;
Experience with platforms such as Windows, Linux, macOS, iOS, or Android;
Ability to work independently in a remote environment;
Availability for full-time work.
Will be a plus
Published CVEs or other proven records of discovered vulnerabilities;
Experience finding and exploiting vulnerabilities in browsers or OS kernels;
Experience with fuzzing;
Participation in CTFs, security competitions, or security conferences;
Bug bounty or independent vulnerability research experience;
Published security research, technical write-ups, PoCs, or research tools;
Offensive security background;
Academic degree in Computer Science, Mathematics, or Physics.
We offer
A real opportunity to influence the product, architecture, and technical decisions;
Direct communication with C-level management, without unnecessary bureaucracy;
Remote-first environment;
Long-term and enjoyable cooperation;
20 paid working days of vacation per year;
5 paid undocumented sick days;
Official public holidays as days off;
Personal legal support;
English classes;
Team-building events and a friendly, supportive atmosphere.


