Open Opportunities
Senior Vulnerability Researcher
About The Position
Company Overview:
Cellebrite’s (Nasdaq: CLBT) mission is to enable its global customers to protect and save lives by enhancing digital investigations and intelligence gathering to accelerate justice in communities around the world. Cellebrite’s AI-powered Digital Investigation Platform enables customers to lawfully access, collect, analyze and share digital evidence in legally sanctioned investigations while preserving data privacy. Thousands of public safety organizations, intelligence agencies and businesses rely on Cellebrite’s digital forensic and investigative solutions—available via cloud, on-premises and hybrid deployments—to close cases faster and safeguard communities. To learn more, visit us at www.cellebrite.com, https://investors.cellebrite.com/investors and find us on social media @Cellebrite.
The role:
Remote · France / Europe · Full-time
You'll join Cellebrite's Labs group and work at the frontier of mobile forensics research, breaking into modern Android devices and other embedded targets, from smartphones to drones, turning that research into world-unique evidence-extraction capabilities. Recent devices, from throwaway handsets to the latest flagships, are genuinely hard targets. Hardware-backed encryption, secure boot chains, increasingly hardened security policies and mitigations, and trusted execution environments (TEE/eSE) all stand between an investigator and the evidence.
Your job is to get past all of it. You'll go after the full Android attack surface, from userland and the kernel down to firmware and silicon, across every interface a modern device exposes to the outside world. Expect to go deep on the problems you're given and to have real ownership of how you crack them.
This is work with a clear purpose. Our results help law enforcement lawfully extract evidence and put criminals behind bars, every day. We want researchers who believe in that mission, not just the technical challenge. If you want your research to serve a purpose beyond the exploit itself, this is that place.
Requirements
What we're looking for:
- Proven experience in vulnerability research and exploitation, ideally on mobile or other modern targets (Android, iOS, Linux, Windows, macOS)
- Strong reverse engineering skills, mainly on ARM/ARM64 and sometimes more exotic architecturesComfortable working across memory-corruption mitigations (PAC, MTE, CFI, KASLR, and friends)
- Someone who loves hard problems and treats a locked-down system as a puzzle to be solved
- Professional fluency in French (our team's working language) and English (used across the wider company)
- We don't require any particular degree or certification. If you can do the work, we want to talk.
Nice to have:
- Published research, CVEs, or conference talks
- Advanced fuzzing experience
- Knowledge in cryptographic primitives and their weaknesses
- Offensive hardware research / board design
- CTF experience
- AI-assisted vulnerability research / agentic workflows
- Ability, or willingness to grow into, leading people
How we work:
Remote · France / Europe · Full-time
We're a small team of researchers, fully remote but genuinely close. People share what they're working on, help each other through the hard parts, and you'll always feel plugged into what the team is doing rather than off on an island. We hire for talent and curiosity and back you with the trust and autonomy to go deep on hard subjects.
#LI-CA1