Android Vulnerability Researcher
Cellebrite Tel-Aviv, Tel-Aviv District, Israel
Public Safety · 1,001-5,000 employees
About the role
Research vulnerabilities across mobile technologies and layers, from applications and kernels to TrustZone, bootloaders, and firmware. Reverse engineer undocumented code and develop practical exploits across chipsets, vendors, and operating system versions as part of long-term team research projects.
What they look for
Requirements
Candidates need practical experience in vulnerability research, exploitation, and reverse engineering, along with practical knowledge of current and emerging security mitigations. Android internals, LLM-based research pipelines, cryptography, ARM reversing, advanced fuzzing, and offensive hardware research are advantageous.
Full description
Company Overview:
Cellebrite’s (Nasdaq: CLBT) mission is to enable its global customers to protect and save lives by enhancing digital investigations and intelligence gathering to accelerate justice in communities around the world. Cellebrite’s AI-powered Digital Investigation Platform enables customers to lawfully access, collect, analyze and share digital evidence in legally sanctioned investigations while preserving data privacy. Thousands of public safety organizations, intelligence agencies and businesses rely on Cellebrite’s digital forensic and investigative solutions—available via cloud, on-premises and hybrid deployments—to close cases faster and safeguard communities. To learn more, visit us at www.cellebrite.com, https://investors.cellebrite.com/investors and find us on social media @Cellebrite.
Position Overview:
The Android research group in Cellebrite Security Research Labs (SRL) is where the most challenging problems get solved. We're the ones who find the weaknesses that let us unlock modern phones and turn them into extraction capabilities investigators can actually use in the field. Our work ships straight into Cellebrite's core products, which makes this one of the most important roles in the company.
Our customers are law enforcement agencies working real cases under legal authority: child exploitation, human trafficking, homicide, terrorism. A device we unlock is often THE piece of evidence that moves an investigation forward.
What you'll do
Perform vulnerability research on a huge variety of mobile technologies and architectures, from the application layer down through the kernel, TrustZone, the bootloader, and the firmware running underneath it.
Go first into areas nobody has published and become a world-class expert in them.
Reverse engineer code that was never meant to be read: no source, no symbols, no documentation.
Turn bugs into exploits that hold up in the real world, across a wide range of chipsets, vendors, and OS versions.
Conduct long term widely scoped security research projects as part of a broader team effort
Requirements
Qualifications
Practical experience performing vulnerability research and exploitation
Practical reverse engineering experience
Practical knowledge of current and upcoming security mitigations
Advantage: knowledge of Android architecture and internals
Advantage: LLM-based pipelines for vulnerability research / exploit development / fuzzing
Advantage: Cryptographic primitives and weaknesses
Advantage: ARM Reversing
Advantage: Advanced fuzzing
Advantage: Offensive hardware research/board design
Personal Characteristics
null
Similar roles
-
Software Development Test Engineer (SDET), Android
Keeper Security United States
-
TPM, Projection Certification and Android Framework
ALTEN Technology USA Palo Alto, California, United States · $140K–$155K/yr
-
Senior Software Engineer, Mobile (Android)
Grab Singapore, Singapore
-
Android - SE
CheQ Digital Private Limited Bengaluru, Karnataka, India
-
Android Developer - Digital Wallet & Payments (ID: 3840)
STAFIDE Amsterdam, North Holland, Netherlands
-
Director, Android Go-To-Market
Google Tokyo, Japan