Overview
In this role, you develop and advance Arm’s coverage-guided fuzzing program to uncover hard-to-reach security flaws and drive fixes. You’ll design high-performance fuzzing harnesses, build custom sanitisers, and lead data-driven security assessments that scale across products. You work with cross-functional teams to expose attack surfaces and deliver measurable coverage gains and actionable crash reports. Your work supports resilient software and helps products ship with provable security.
Responsibilities
- Map fuzzing surfaces across services, libraries, APIs, and protocols and maintain a risk-based roadmap
- Design, build, and extend fuzzing harnesses (libFuzzer, AFL++, Honggfuzz) to improve code-path exploration and reduce false positives
- Grow seed corpus, apply targeted mutation strategies, and add instrumentation to improve coverage
- Automate crash triage and root-cause analysis, differentiate exploitable crashes from benign faults, drive CVE-level remediation
- Develop custom sanitisers to reveal bugs missed by traditional fuzzing
- Validate fixes and guard against regressions via differential fuzzing and regression corpora
- Assess external disclosures to refine fuzzing coverage and harnesses
- Document and share insights from coverage metrics and post-mortems to enable data-driven security
Key requirements
- 1+ years in application or product security with a deep focus on coverage-guided fuzzing
- Hands-on experience with at least one modern fuzzing framework (libFuzzer, AFL++, Honggfuzz)
- Proficient in C/C++ with strong Python scripting for automation
- Solid understanding of memory-safety vulnerabilities, undefined behaviour, sanitisers, and compiler instrumentation
- Experience triaging crashes using debuggers/profilers and reverse-engineering tools (gdb/lldb, IDA/Ghidra)
- Excellent written communication for documenting findings and influencing engineering teams
- written communication
- cross-functional collaboration
- analytical thinking
- coverage-guided fuzzing
- libFuzzer
- AFL++
…
