Specialist, Offensive Android Kernel Security (Contract)
665 Clyde Avenue, Mountain View, CA, USA
Samsung Research America
For more than 70 years, Samsung has been at the forefront of innovation. Our discoveries, inventions and breakthrough products have helped shape the history of the digital revolution. We continue to expand our global reach and open new...Lab Summary:
The Development Quality Innovation (DQI) lab in Mountain View has a dual role that is first to research new automation tools as well as take current tools and refine them to our needs. Second, act as a centralized QI group to provide quality assessment and penetration testing operations.
This duality provides a unique opportunity to explore new concepts in different technologies and perform original research in quality and security domain.
More details about project : Samsung Knox
Position Summary:
We are seeking a Android Kernel Security Specialist to join our cutting-edge Pen Test Team. In this role, you will focus on identifying and mitigating security threats to our kernel and Android operating system.
Position Responsibilities:
- Conduct in-depth research on kernel vendor modules to identify potential vulnerabilities in android system
- Review, analyze secure OS architectures and perform reverse engineering, fuzzing to identify vulnerabilities
- Perform penetration testing on Android OS components, including TEE, bootloader, and kernel
- Research and test the latest exploit trends, developing POC attacks and advanced exploits (0-day, 1-day)
- Document and present findings, including reproducible steps, in a clear and concise manner
Required Skills:
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent combination of education training and experience
- 3+ years of experience in Android system-level penetration testing and vulnerability
- Experience in publishing CVE in Android
- Hands on experience of kernel-level programming and architecture
- Proficiency in tools for kernel debugging, fuzzing, and penetration testing
- Experience with reverse engineering tools (g. IDA Pro & Ghidra), debugging tools
- Understanding of the Android software stack, with deeper technical knowledge in Android framework security, access controls, and internals
Special Attributes:
- Certifications: OSCE, OSCP, OSEE, or equivalent
- Exploit development & Vulnerability discovery
- Experience presenting findings at security conferences
- As red team most likely not have access to source code, “Reverse Engineering” will be one of the key method to identify potential weakness or flaws
Additional Information
Disclosure of Trade Secrets
Samsung has a strict policy on trade secrets. In applying to Samsung and progressing through the recruitment process, you must not disclose any trade secrets of a current or previous employer.
Essential Job Functions
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, and frequently operate standard office equipment, such as telephones and computers.
Samsung Research America is committed to complying with all Federal, State and local laws related to the employment of qualified individuals with disabilities. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact the recruiter or email sratalent@samsung.com.
Equal Employment Opportunity
At Samsung, we believe that innovation and growth are driven by an inclusive culture and a diverse workforce. We aim to create a global team where everyone belongs and has equal opportunities, inspiring our talent to be their true selves. Together, we are building a better tomorrow for our customers, partners, and communities.
Samsung Research America is committed to employing a diverse workforce, and provide Equal Employment Opportunity for all individuals regardless of race, color, religion, gender, age, national origin, marital status, sexual orientation, gender identity, status as a protected veteran, genetic information, status as a qualified individual with a disability, or any other characteristic protected by law.
For more information regarding protection from discrimination under Federal law for applicants and employees, please refer to this link: Pay Transparency
Tags: Android Automation Computer Science Exploit Exploits Ghidra IDA Pro OSCE OSCP OSEE Pentesting Red team Reverse engineering Vulnerabilities Zero-day
Perks/benefits: Conferences Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.