Senior NVIDIA Offensive Security Researcher, GPU System Software
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
GPU
LLM @ 4
LLVM @ 4
Networking
Rust @ 4
Security @ 7
Spark @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA is seeking a highly motivated and creative Offensive Security Researcher with deep experience in low-level system software, including firmware, microcode, and kernel drivers, to join the NVIDIA Offensive Security Research team. The role focuses on attacking production GPU firmware, microcode, kernel drivers, and embedded software, and designing mitigations to prevent future attacks.
NVIDIA silicon supports AI data centers, confidential computing, automotive, networking, and gaming. Its chips contain embedded control processors, many based on RISC-V cores, with firmware serving as the platform's root of trust. The Offensive Security Research team identifies vulnerabilities, develops exploits, and works with architecture, hardware, and software teams to address entire classes of bugs through mitigations such as hardware Control-Flow Integrity, Pointer Masking, Memory Tagging, and formally verified code.
Responsibilities
- Own the end-to-end security story for specific subcomponents, from threat modeling through hardening and verification.
- Design, prototype, and drive production adoption of mitigation and hardening technologies, including hardware CFI, Pointer Masking, and Memory Tagging.
- Build and promote tools, practices, and processes that improve product robustness across the company.
- Conduct offensive security research across GPU and platform firmware, microcode, kernel drivers, and embedded software.
- Identify vulnerabilities, develop proof-of-concept exploits, and partner with development teams on remediation.
- Perform threat analysis and security reviews of software and hardware designs.
Requirements
- Bachelor's degree in Electrical or Computer Engineering, Computer Science, or equivalent experience.
- 12 or more years of relevant software engineering or security research experience.
- Demonstrated experience in an offensive security role.
- Excellent C and assembly skills, with hands-on low-level driver or firmware experience.
- Vulnerability research experience, including fuzzing, static and dynamic analysis, exploit development, and coverage-guided techniques.
- Experience with secure development lifecycle practices such as threat modeling, code auditing, and incident response.
- Experience applying AI and LLM-based tools to vulnerability discovery, triage, or analysis.
- Ability to work collaboratively and remotely on complex, cross-team goals.
Preferred Qualifications
- Firmware or embedded reverse-engineering experience, particularly with RISC-V or other non-x86 architectures.
- Experience designing hardware or compiler-assisted mitigations from the ground up, including LLVM or GCC compiler modifications.
- Familiarity with computer architecture fundamentals, including caches, buses, memory controllers, DMA, MMUs, and IOMMUs.
- Experience with formally verifiable languages or methods such as SPARK, Ada, Rust, or model checking.
- Published research, including talks at Black Hat or DEF CON, or articles in publications such as Phrack.
Compensation and Benefits
The base salary depends on location, experience, and compensation for employees in similar positions. The base salary range is USD 224,000–356,500 for Level 5 and USD 272,000–431,250 for Level 6. The role is also eligible for equity and benefits.
Applications will be accepted at least until September 26, 2026. This posting is for an existing vacancy. NVIDIA uses AI tools in its recruiting processes and is an equal opportunity employer.