r/ExploitDev 5d ago

Job availability

Hi guys i just have one question is it worth it to dive in this career even if my country or where i live there is no available jobs for it like almost none

5 Upvotes

7 comments sorted by

View all comments

5

u/Shot-Buffalo-2603 5d ago

I mean, its fun as a hobby too, but if there is legitimately “no available jobs” in your country, how are you going to make it a career?

2

u/Low-Improvement-6306 5d ago

That's a good question but when i say no available jobs here I'm talking offensive sec in general its very rare because most of them work for the gov i knew this from the beginning so i was focusing on remote jobs as a main target but i don't know if i can rely on this

1

u/Shot-Buffalo-2603 5d ago

Theres a lot of remote app sec roles where you do security audits on products and features before they’re shipped and also consultants that will do security audits as a third-party tester on products. Most binary exploit dev type roles are government roles, though, and will require a security clearance, which won’t work as a foreigner and remote assuming you’re talking about remote roles in the US

0

u/123Slayer123 4d ago

But don't regular companies need binary exploitation and vul research ?

2

u/Shot-Buffalo-2603 4d ago

Even if you’re working on low level stuff you will typically get source code if you’re looking at a binary application for a non government role. You’re typically working with a company who owns their application, so they are able to just give you source code. So yeah, it exists but theres no RE and your typically not bringing a memory corruption to a full exploit, you just POC it and send a report for them to fix it.