
Mobile Vulnerability Researcher
The Josef Group Inc. · United States
- On site
- Full-time
- United States
About the role
Mobile Vulnerability Researcher
Location: Fully Remote (U.S.)
Employment Type: Full-Time
About the Role
We are seeking a highly skilled Mobile Vulnerability Researcher to join an elite security research team focused on discovering previously unknown vulnerabilities and developing advanced exploitation techniques across modern operating systems and applications. The ideal candidate has experience researching or analyzing Common Vulnerabilities and Exposures (CVEs). Primary Workstreams (browser, app 0-click, Windows, iOS, or Android).
This role is ideal for researchers passionate about discovering zero-day vulnerabilities, reverse-engineering software, analyzing patches, and developing proof-of-concept exploits. You will identify, analyze, and weaponize complex vulnerabilities affecting mobile devices, browsers, operating systems, and applications.
What You'll Do
- Discover previously unknown vulnerabilities (zero-days) in modern software platforms.
- Perform advanced vulnerability research across one or more primary workstreams:
- Mobile applications
- Browser security
- Windows
- Android
- iOS
- Zero-click attack surfaces
- Analyze publicly disclosed CVEs to understand vulnerability mechanics.
- Reverse engineer vendor patches to identify security fixes and newly introduced protections.
- Reproduce vulnerabilities in controlled laboratory environments.
- Develop Proof-of-Concept (PoC) exploits demonstrating successful exploitation.
- Identify root cause and document technical findings.
- Evaluate customer systems for vulnerability exposure.
- Develop detection methodologies, signatures, and mitigation recommendations.
Required Qualifications
- Experience discovering or researching zero-day vulnerabilities.
- Experience performing original vulnerability research and CVE analysis.
- Demonstrated ability to identify, analyze, and validate software vulnerabilities.
- Experience developing Proof-of-Concept (PoC) or exploit code.
- Strong reverse engineering skills, including binary and patch analysis.
- Experience with three or more of the following:
- Vulnerability Research
- Exploit Development
- Reverse Engineering
- Mobile Security Research
- Malware Analysis
- Kernel Exploitation
- Fuzzing
- Strong understanding of operating system internals and modern exploit mitigations.
- Experience researching one or more of the following platforms:
- Android
- iOS
- Windows
- macOS
- Proficiency with reverse engineering tools such as IDA Pro, Ghidra, or Binary Ninja.
- Experience using debuggers, disassemblers, binary instrumentation, and dynamic analysis tools.
- Strong programming skills in C/C++ and Python.
- Ability to read and analyze x86/x64 and ARM assembly.
- Experience with static analysis, dynamic analysis, binary patch diffing, root cause analysis, CVSS scoring,
- Ability to obtain a U.S. Department of Defense Security Clearance.
Preferred Skills
- Zero-day vulnerability discovery
- CVE research and analysis
- Mobile exploitation
- Kernel vulnerability research
- Exploit mitigation bypass techniques
- Public vulnerability research and responsible disclosure
Why Join Us
- Fully remote within the United States
- Work on cutting-edge vulnerability research and exploit development
- Collaborate with world-class security researchers
- Research-focused environment with minimal bureaucracy
- Opportunities to discover and analyze zero-day vulnerabilities
- Competitive compensation, 25% annual bonus, and comprehensive benefits
- Unlimited PTO
- Equity options with near-founder-level ownership potential.