iOS User Space Sandbox Escape - Vulnerability Researcher

Trenchant

United States

Remote

USD 180,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Fully remote

Job summary

Trenchant is seeking a deeply experienced iOS userspace researcher to deliver sandbox escapes and privileged-daemon exploit components. You will work on real trust boundaries across Mach, XPC, private frameworks, and entitlement-gated functionality, operating fully remotely with kernel and browser researchers.

The role emphasizes evergreen exploit-chain integration, cross-process trust relationships, and strong technical handover.

Qualifications

  • Proven delivery of iOS sandbox escapes, privileged-daemon vulnerabilities or comparable userspace exploit components.
  • Deep knowledge of iOS process isolation, code signing, entitlements, sandbox profiles and launch/service models.
  • Strong reverse engineering across Objective-C, Swift and C/C++, including private frameworks and stripped binaries.
  • Practical expertise with Mach messaging, XPC/NSXPC, serialization formats and asynchronous service interactions.

Responsibilities

  • Develop original iOS userspace vulnerabilities that cross sandbox, entitlement, process or service boundaries.
  • Create reliable sandbox-escape exploit components for integration into broader chains.
  • Map attack surfaces for privileged services, framework brokers and entitlement-gated functionality.
  • Produce triggers, PoCs, exploitation strategy, affected-version notes and clear handover.
  • Build reusable tooling for service discovery, message generation, daemon instrumentation and variant research.

Skills

iOS security research
Reverse engineering
Mach/XPC/NSXPC
arm64e exploitation
Sandbox/entitlements
Exploit-chain development

Job description

We are looking for a deeply experienced iOS userspace researcher who has already delivered sandbox escapes, privileged-daemon vulnerabilities or equivalent exploit components.

The work is focused on real trust boundaries exposed through Mach, XPC, private frameworks, privileged services and entitlement-gated functionality. This is not an application-security or jailbreak-usage role.

What you’ll work on
  • Privileged iOS daemons, frameworks and services reachable from sandboxed application or browser contexts.

  • Mach, XPC, NSXPC, serialisation and object-bridging boundaries.

  • Memory corruption, logic vulnerabilities, confused-deputy conditions, race conditions and entitlement bypasses.

  • Sandbox profiles, service registration, entitlement checks and cross-process trust relationships.

  • Private-framework and daemon-protocol reverse engineering across iOS releases and arm64e devices.

  • Exploit-chain integration with browser and kernel researchers when required.

What you’ll deliver
  • Original iOS userspace vulnerabilities that cross sandbox, entitlement, process or service boundaries.

  • Reliable sandbox-escape exploit components suitable for integration into broader chains.

  • Prioritised attack-surface maps for privileged services, framework brokers and entitlement-gated functionality.

  • Triggers, PoCs, exploitation strategy, affected-version notes, assumptions and clear technical handover.

  • Reusable tooling for service discovery, message generation, daemon instrumentation, entitlement analysis and variant research.

What we’re looking for
  • Proven delivery of iOS sandbox escapes, privileged-daemon vulnerabilities or comparable userspace exploit components.

  • Deep knowledge of iOS process isolation, code signing, entitlements, sandbox profiles and launch/service models.

  • Strong reverse engineering across Objective-C, Swift and C/C++, including private frameworks and stripped binaries.

  • Practical expertise with Mach messaging, XPC/NSXPC, serialisation formats and asynchronous service interactions.

  • Advanced ARM64/arm64e userspace exploitation, including modern heap behaviour, PAC-aware strategies and constrained code execution.

  • The ability to reason about chainability, target variation and reliability rather than stopping at a one-time daemon crash.

  • A consistent history of independently finishing complex research.

Strong signals
  • Public iOS security credits, jailbreak-chain research or comparable exploit-chain delivery.

  • Experience chaining browser compromise into an iOS userspace sandbox escape.

  • Custom XPC/Mach fuzzing, service-introspection or firmware-analysis tooling.

  • Research across multiple major iOS generations and arm64e hardware families.

  • Strong patch-diffing and variant-hunting results.

How we work
  • Fully remote, with high autonomy and direct collaboration with browser and kernel specialists.

  • We value technically meaningful delivery, clean handover and reproducibility over activity metrics or polished theatre.

  • Public CVEs are useful but not required.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior iOS Exploit Researcher — Sandbox & Privileged
Remote Senior iOS Exploit Researcher — Sandbox & Privileged

Trenchant • United States

Remote
USD 180,000 - 260,000
Fully remote
Chrome Sandbox Escape Android - Vulnerability Researcher
Chrome Sandbox Escape Android - Vulnerability Researcher

Trenchant • United States

Remote
USD 180,000 - 240,000
iOS Vulnerability Researcher (Remote)
iOS Vulnerability Researcher (Remote)

Cellebrite • Tysons (VA)

On-site
USD 100,000 - 130,000
IOS Vulnerability Researcher
IOS Vulnerability Researcher

TopClearedRecruiting • Town of Poland (NY)

On-site
USD 120,000 - 160,000
Android Kernel - Exploit Developer
Android Kernel - Exploit Developer

Trenchant • United States

Remote
USD 160,000 - 230,000
Senior Android Chrome Sandbox Exploitation Researcher
Senior Android Chrome Sandbox Exploitation Researcher

Trenchant • United States

Remote
USD 180,000 - 240,000
X-Day Offensive Research (XOR) Vulnerability Researcher
X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 150,000 - 230,000
Vulnerability Researcher
Vulnerability Researcher

Zealot Labs • New York (NY)

Hybrid
USD 120,000 - 180,000
Competitive cash
Meaningful early equity
Mission-driven work
+1
Remote iOS Vulnerability Researcher — Zero-Day Discovery
Remote iOS Vulnerability Researcher — Zero-Day Discovery

TopClearedRecruiting • Town of Poland (NY)

Hybrid
USD 120,000 - 160,000
Vulnerability Researcher
Vulnerability Researcher

Apple Inc. • Seattle (WA)

On-site
USD 172,000 - 233,000
Stock programs
Medical benefits
Tuition reimbursement
+1