Senior Product Security Low-level Researcher

Island Island · Enterprise · Tel Aviv, Israel · Engineering

This role focuses on deep technical research into operating systems, kernels, drivers, and low-level system components to uncover vulnerabilities and improve the security of Island's enterprise browser platform. Responsibilities include vulnerability research, kernel analysis, exploit development, security testing tool creation, and threat modeling at the system level.

What you'd actually do

  1. Research and discover vulnerabilities in operating system kernels, drivers, system services, virtualization layers, and low-level system components relevant to Island’s execution and trust boundaries.
  2. Analyze kernel subsystems (memory management, scheduling, IPC, filesystems, networking) and OS security primitives to identify design flaws, logic bugs, and exploitation opportunities.
  3. Develop proof-of-concept exploits for kernel- and driver-level issues to validate impact, assess exploitability, and inform mitigation strategies.
  4. Design and build custom tooling for kernel fuzzing, syscall/interface testing, driver analysis, and low-level instrumentation across supported platforms.
  5. Assess the implementation and usage of cryptographic primitives, key management, secure boot, attestation, and hardware-backed security features, identifying weaknesses or misuse patterns.

Skills

Required

  • Operating system internals
  • kernel architectures
  • driver development
  • low-level programming (C/C++, Rust, or assembly)
  • scripting (Python)
  • kernel vulnerability research
  • driver auditing
  • exploit development
  • advanced reverse engineering
  • low-level vulnerability classes (UAF, race conditions, logic bugs, privilege escalation, sandbox and isolation bypasses)
  • kernel debuggers
  • fuzzers
  • emulation
  • virtualization-based analysis frameworks
  • research mindset

What the JD emphasized

  • low-level system components
  • low-level system components
  • low-level programming
  • low-level vulnerability classes
  • low-level instrumentation
  • low-level system components