How do you actually make the jump into exploit dev full-time?
​
Hey,
Looking for some advice from people who work in exploit dev / low-level vuln research.
I already work in security and have been doing vulnerability research alongside more general security work for a while. I’ve had opportunities to do reversing, native-code research, memory corruption, and some exploit development, including taking bugs beyond just finding a crash and actually working out useful primitives / PoCs.
The problem is that this kind of work still isn't my main job, and I really want it to be.
I've been looking at dedicated exploit dev / vulnerability research positions and I feel like I'm stuck in a weird middle ground. I'm not trying to enter security from scratch, and I do have relevant experience, but I also don't have years and years of dedicated browser/kernel/mobile exploit development behind me.
A lot of the jobs I find seem to be looking for people who are already extremely specialised, rather than people who have a decent foundation and want to grow deeper into exploit development.
There's also the location issue. I'm outside most of the major exploit-dev hiring hubs, and quite a few roles I come across are limited by citizenship, clearance, residency, or simply don't hire internationally.
Another problem is that most of the interesting professional research I've done isn't something I can publish, so it's difficult to show potential employers exactly what I've worked on.
For those of you doing this professionally:
*What actually got you your first dedicated exploit dev / low-level VR job?
* What would you want to see from someone who already has some relevant experience but hasn't spent their entire career doing exploit development?
* What kind of public research/projects are actually worth doing to prove ability?
*Is native userland exploitation still a reasonable area to focus on, or would I be better off going hard into something like browsers, kernels, or mobile?
* Do companies that are willing to develop people into this kind of role actually exist, or is the expectation generally that you're already very good before they'll hire you?
* For people outside the main US/EU hiring markets, how did you find opportunities?
* I'm mainly trying to figure out whether I'm approaching this transition the wrong way.
I enjoy this stuff way more than the broader security work I do, and I'm willing to put the work in. I just don't want to spend a year grinding in a direction that isn't actually going to help me make the jump.
Would appreciate any advice.