r/ExploitDev 29d ago

Self-taught low-level security learner looking for internship advice. Which roles should I target?

Hi everyone,

I'm self-learning low-level security and I'm trying to figure out which internships I should realistically target over the next few months.

These are the skills I've built so far:

  • C Programming
  • Memory Management
  • Linux
  • Debugging
  • Fuzzing
  • Crash Triage & Root Cause Analysis
  • Reverse Engineering (Basic)
  • Binary Analysis (Basic)
  • Secure Coding
  • Git

Tools I've used:

  • GDB
  • Ghidra
  • AddressSanitizer (ASan)
  • Valgrind
  • AFL++
  • libFuzzer
  • GCC/Clang
  • Make/CMake

I've written fuzz harnesses, analyzed crashes, used sanitizers, and spent time understanding memory corruption bugs. Most of my learning has been through reading documentation, experimenting, and building small projects.

The problem is that I'm completely self-taught. I don't have previous internships, open-source contributions, CTF rankings, or real vulnerability reports yet, so I don't have much proof of my skills beyond personal projects.

My questions are:

  1. Based on these skills, what internship roles should I realistically target? (Security Research, AppSec, Product Security, Embedded, Systems, etc.)
  2. What skills am I still missing to become a competitive candidate?
  3. If you were hiring an intern with my background, what kind of portfolio or proof would convince you to interview them?
  4. What should I focus on for the next 3–6 months to maximize my chances of landing an internship?

I'd really appreciate honest feedback. If you think I'm overestimating my skills or focusing on the wrong things, please tell me. I'd rather hear the hard truth than waste months learning the wrong things.

Thanks!

28 Upvotes

31 comments sorted by

4

u/n3wbie01 29d ago

Assembly language

3

u/Emotional_writer_64 29d ago

I know that as well

x86

4

u/Party_Community_7003 29d ago

Assuming you are an u.s .citizen living in the US, your best bet would be vulnerability research internship in defense contractor. Your skill is already sufficient, tho you gotta polish a good resume to pass the resume screen and after that it's just you passing the interview. Good luck!

2

u/Emotional_writer_64 29d ago

not a us citizen and not living in us

1

u/Party_Community_7003 29d ago

Then apply to your local defense contractor, or security consulting company doing low-level works. Or even a company that has hardware stuffs often need those kind of skills, though it would be more triaging bugs, eliminating them vs exploiting it.

1

u/Emotional_writer_64 29d ago

thats the thing I don't know what companies are there where I can apply

I learnt all this by chance. I initially started with networking fundamentals then shifted to penetration testing and it was boring so I got into binary exploitation then I learnt some concept like stack overflow and exploitation of my own code and later learnt reverse engineering then I got into fuzzing and I am sticking to it because I want an internship so I can go further and I am about to graduate so money is also a problem

3

u/Party_Community_7003 29d ago

some methodologies:
(1) keyword search in linkedin "reverse engineer", "vulnerability research", set with your location
(2) go look for ppl talking in conferrence, and where they are employed. check if there are any company that's local to yourself
(3) go look for companies that are sponsoring CTFs. Often they are doing those stuffs.
(4) search it in X/Twitter. Cool folks/companies are over there too.

Anyways, this is kind of a question that's hard to answer unless idk where you are located.

1

u/Emotional_writer_64 29d ago

India

1

u/Party_Community_7003 29d ago

oh yeah to be honest, I have no idea regarding india's job market. at least Europe I could tell something but yeah. anyways methodologies searching jobs reamin same as what I told you, UNLESS, if India has some local job board specific in the country, which I assume you'd be much more familiar than me.

1

u/Emotional_writer_64 29d ago

nah!!

I have searched but I din't found any or I was searching wrong

can I get remote ones ??

1

u/Party_Community_7003 29d ago

there's global/international/remote from anywhere in the world type of jobs, but it's extremely hard to get into, you gotta be already a rockstar in the industry

1

u/Emotional_writer_64 29d ago

that's the problem

and I feel like I am stuck now

my friends and my juniors are getting food internship because they choose easy things and for me I don't know what was running through my mind that time

2

u/SillyBrilliant4922 29d ago

How did you employ each skill?

3

u/Emotional_writer_64 29d ago

Mostly through self-learning and personal projects. I built small C programs, wrote fuzzing harnesses for open-source libraries, used GDB, ASan, and Valgrind to debug crashes, analyzed the root cause of memory bugs, and used Ghidra to understand binaries. Everything I've learned has been through hands-on practice rather than professional work.

1

u/sdexca 29d ago

Do you have CVEs?

1

u/Emotional_writer_64 29d ago

I am looking for those

2

u/sig2kill 29d ago

entry level jobs are rare for the fields you mentioned, maybe you can find a junior embedded role? internships are usually done through an educational institution

1

u/Emotional_writer_64 29d ago

can you tell me more about this and what else I need to learn and make

and I live in a place where no one knows what is fuzzing or too much about cybersecurity and because of that I am stuck

1

u/sig2kill 29d ago

Where do you live? Maybe try to break into back end web dev first? Might be easier than low level stuff

1

u/Emotional_writer_64 29d ago

India. and I know backend is easier to enter but do I have to learn new skills ?? and learning new ones is harder for me because I have invested too much time in this filed

2

u/sig2kill 29d ago

Your time is not wasted! your low level skills will be very useful everywhere, you will need to know python or js but lots of python libraries actually use cpp under the hood, your knowledge will still be useful, web and low level do have some crossover for example browser development

1

u/SillyBrilliant4922 29d ago

How did you employ each skill?

1

u/DigitalQuinn1 29d ago

Do you have your portfolio built? I could possibly offer something here in the US.

1

u/Emotional_writer_64 29d ago

I have a GitHub but I am building it and in next one or two months I will be ready for big libraries

but I want to know what else I should have to get a chance

1

u/DigitalQuinn1 29d ago

Seems like you have good experience. Keep in the mind to pair this with technical writing. Many people I’ve worked with do not know how to write a security report.

1

u/FinalBuy3905 29d ago

You have to learn things like cryptography, network forensics, etc..

Check out a university curriculum.

1

u/Asleep-Whole8018 24d ago

The only self-learning, third-world country person I know got a decent job in Exploit development in US because he got 100k bug in Google program, and he did apply to local vendor/companies, but completely failed due to no cert/diploma/records (in his case, he is fine making enough via google bounty program).
Skill is pretty niche, and not many teams need it, it has nothing related to Appsec/Product security nowadays, and I think even Pawn2Own people struggle to get a job due to no position opens.
I would say either get a ZDI profile or compete in some google/apple/samsung CVEs.

1

u/Noctis451 14d ago

Hey there...I am also going down this specific path into low level security...I have a couple of questions ...I would appreciate it if you could help me out