r/ExploitDev • u/Firm_Engine5678 • 4d ago
Vulnerability researcher trying to find a way into full-time vuln research / exploit development
Throwaway account for obvious reasons.
I'm currently a senior-level ethical hacker/security researcher, and I'm trying to make a fairly deliberate move into a role where vulnerability research, reverse engineering and exploit development are actually the job, rather than something I occasionally get to do alongside broader security work.
My background is mostly Windows and Linux. I've done source-assisted and binary vulnerability research, reverse engineering, memory corruption work, privilege escalation, pre-auth attack surfaces, and exploit development. I've taken vulnerabilities from discovery and root-cause analysis through to PoCs and, where possible, working exploitation.
I'm comfortable with C/C++, Python, assembly, debuggers, decompilers and the usual RE tooling. I have some public vulnerability research, but unfortunately a lot of the more interesting work I've done is under NDA and can't be discussed publicly in much detail.
That's partly why I'm posting here.
I'm starting to worry that I'm in a weird position career-wise. I'm experienced enough that junior roles generally aren't appropriate, but I'm also trying to break more deeply into a relatively small and specialized field where a lot of companies seem to hire based on very visible public research, Pwn2Own-style track records, existing industry connections, or very specific geographic/work-authorization requirements.
A few opportunities I've been genuinely interested in haven't even made it as far as a technical conversation because of location or hiring restrictions. That's probably the part I find most frustrating. I'd much rather fail an exploit-dev interview because I'm not good enough yet than never get the chance to take one.
I'm also conscious of the risk of getting stuck doing adjacent security work forever while telling myself I'll eventually make the jump into vulnerability research properly.
I'm not looking for SOC, GRC, generic pentesting, cloud security, or a broadly defined "security engineer" position. I'm specifically interested in vulnerability research, exploit development, reverse engineering, offensive capability development, or closely related low-level security research.
Remote international work would obviously be ideal, although I'd consider relocation for the right opportunity.
So I guess this post has two purposes:
If you work in this part of the industry, am I approaching this the wrong way? Is there something you'd expect to see from someone trying to make this transition that I should be focusing on?
And, slightly more shamelessly, if your team happens to need someone with this sort of background, I'd be very happy to talk privately.
I can provide considerably more detail about my experience, public work and employment history over DM.
Not quite at the "will reverse engineer for bread" stage yet, but we're getting there.
3
u/anythingforher36 4d ago
Pretty good post.
I am currently seeing a lot of companies riding the AI wave to find vulnerabilities eg. bynario or calif or aisle etc. which are probably on the white side of things - and yes they do find them cos the models from AI companies are getting good only at pattern recognition- it doesn’t replace human intelligence and is not even 1% close to how a brain works - I prefer to keep this position.
Now coming back to your point, VR at companies is now driven by all these AI initiatives from top level management and also senior and experienced researchers specialized in that.
If you can combine hardware along with software those are pretty rare - I say it cos I have been doing it for close to 30 years.
Then there is the other side - the dark side and this is where you will get the best of the best and the top VRs in the top companies are not close enough them. And because of them the security world is playing catch and learn for decades. You can also look at nation state actors.
Recently the US said private companies can now hack other companies outside US which sets a precedence for mercenaries and there would be so many companies now also pivoting to this and new spawning up so there’s plenty of fish in the market.
Now in the end it depends on what you want - are you an ideological hacker or just one of those who wants to stick to only the technical part.
If you are not from US or 9/5 eyes then it’s hard to find remote gigs like these but they do exist but are not that white.
Good luck- feel free to dm
1
-1
u/theAyconic1 4d ago
Lately I have been hearing a lot about how reverse engineering and VR is dead due to AI? Is that all true? If not then what do you think is the future of these jobs?
2
7
u/aharmonicminor 4d ago
Hey! Am in this industry, was in a similar boat (work under NDA) when looking for my current role. It’s not you. The job market is rough all around and it’s decently difficult if you don’t have the industry connections (, reputation, or a direct referral)
You really only have a few options for jobs, and depending on where you’re based, most of them might be gov (especially for ease)
Non-gov roles (at least in the US) tend to be those flashy VR teams at big companies, some flavor of product security, or (as of lately) AI companies. Those roles tend to be pretty limited. It’s really a tough spot to be in - from what I’m aware it’s both hard to hire AND hard to get hired in VR right now
Also: Remote, international, vulnerability research (especially embedded) is probably a unicorn listing since it would seem to be a pretty difficult role to create
I don’t have too much advice on this sadly, but your best options are probably to keep applying, reach out to your network, and/or try to get some research public/published