Principal Security Engineer - Fuzzing Specialist
Core
Own and evolve a coverage-guided fuzzing program to uncover hard-to-reach security flaws, drive fixes to closure, and help product teams embrace dynamic testing.
Role type
Principal Security Engineer (Fuzzing Specialist)
Builds
High-performance fuzzing harnesses, custom sanitizers, and automated crash triage pipelines.
Domain
Application security, software reliability engineering, and compiler instrumentation.
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
coverage-guided fuzzing, modern fuzzing frameworks (libFuzzer, AFL++, Honggfuzz), C/C++, Python scripting, memory-safety vulnerabilities, undefined behaviour, compiler instrumentation, crash triage, reverse engineering, debugger usage (gdb/lldb), profiler usage, static analysis tools (IDA/Ghidra)
Preferred skills
open-source fuzzing tool contributions, distributed fuzzing at scale, kernel/embedded/firmware fuzzing, symbolic execution, CI/CD integration
Technologies
libFuzzer, AFL++, Honggfuzz, gdb, lldb, IDA, Ghidra, GCP, AWS, Kubernetes, Syzkaller, QEMU
Responsibilities
Map and prioritise fuzzing surfaces across services, libraries, APIs, and protocols; Design, build, and extend fuzzing harnesses to improve code-path exploration; Continuously improve coverage by growing seed corpus and deploying targeted mutation strategies; Automate crash triage and root-cause analysis; Develop custom sanitizers to expose classes of bugs traditional fuzzing misses; Validate fixes and guard against regressions through differential fuzzing; Assess external disclosures to determine fuzzing detectability and refine harnesses
Seniority
Principal, hands-on IC