Sobre este puesto de Senior NVIDIA Offensive Security Researcher, GPU System Software en NVIDIA
NVIDIA is looking for a highly motivated and creative Offensive Security Researcher with deep experience in low-level system software (firmware, microcode, kernel drivers) to join the NVIDIA Offensive Security Research (OSR) team. You will attack our production GPU firmware and microcode, kernel drivers, and embedded software before adversaries do, and help design the mitigations that make the next attack harder.
NVIDIA silicon runs everything from AI data centers and confidential computing to automotive, networking, and gaming. Every chip we ship carries dozens of embedded control processors, most of them running our own RISC-V cores, and we have shipped more than a billion of them. Their firmware is the root of trust for the platform. OSR is responsible for the offensive view of that ecosystem: we find the bugs, build the exploits, and then work with architecture, hardware, and software teams to close whole bug classes with mitigations such as hardware Control-Flow Integrity, Pointer Masking, Memory Tagging, and formally verified code.
What you’ll be doing:
- Be responsible for the end-to-end security story for specific subcomponents, from threat model to hardening to verification.
- Design, prototype, and drive production adoption of new mitigation and hardening technologies (hardware CFI, Pointer Masking, Memory Tagging, and others).
- Build and evangelize tools, practices, and processes that raise product robustness across the company.
- Perform offensive security research across GPU and platform firmware, microcode, kernel drivers, and embedded software.
- Identify vulnerabilities, build proof-of-concept exploits, and partner with development teams to remediate them.
- Perform threat analysis and security reviews of software and hardware designs.
What we need to see:
- BS in Electrical or Computer Engineering, Computer Science, or equivalent experience.
- 12+ years of relevant software engineering or security research experience.
- Demonstrated experience in an offensive security role.
- Excellent C and assembly skills and hands-on low-level driver or firmware experience.
- Vulnerability research experience: fuzzing, static and dynamic analysis, exploit development, and coverage-guided techniques.
- Experience with secure development lifecycle practices such as threat modeling, code audit, and incident response.
- Experience applying AI and LLM-based tooling to vulnerability discovery, triage, or analysis.
- Ability to work collaboratively and remotely on complex, cross-team goals.
Ways to stand out from the crowd:
- Firmware or embedded reverse engineering, especially on RISC-V or other non-x86 architectures.
- Experience designing hardware or compiler-assisted mitigations from the ground up, including compiler modifications (LLVM, GCC).
- Familiarity with computer architecture fundamentals: caches, buses, memory controllers, DMA, MMUs, and IOMMUs.
- Experience with formally verifiable languages or methods (SPARK, Ada, Rust, model checking).
- Published research, such as talks at BH or DEF CON, or articles in publications like Phrack.
NVIDIA is widely considered to be one of the technology world’s most desirable employers. We have some of the most forward-thinking and hardworking people on the planet working for us. If you're creative, hardworking and self-motivated, we want to hear from you! NVIDIA is leading the way in groundbreaking developments in Artificial Intelligence, High-Performance Computing and Visualization. The GPU, our invention, serves as the visual cortex of modern computers and is at the heart of our products and services.
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 431,250 USD for Level 6.You will also be eligible for equity and benefits.
This posting is for an existing vacancy.
NVIDIA uses AI tools in its recruiting processes.
NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.