Work at SecurePeak — start with the challenge
Careers · challenge SPFW-2026-09 Meet the operators →
Hiring · Andorra · Wyoming · remote EU/US

We read your solution before your CV.

Below is a 40-byte firmware header from a device we have never named. Recover the flag it protects and the application form opens. No résumé parsers, no leetcode, no six-round loop. One puzzle, one conversation with the operator you would work with, one decision.

Download spfw-2026-09.bin {{ hintLabel }}
Real firmware headers tell you how to read them. Magic, version, a one-byte parameter, a length, then the payload. The trailer is decoration. The flag format is SP{…}.

The flag is checked locally against a SHA-256 digest — nothing is sent until you apply. Attempts are not counted; taking your time is the point.

Unlock
digest mismatch · check the parameter byte and the payload length
PGP welcome · careers@securepeak.com · 0x5C630EA4 Apply
01The challenge above, or a public write-up, exploit or detection you have already published. 02Ninety minutes with the operator who leads the practice — on a real, anonymised engagement problem. 03An offer, or a written reason why not. Either way, within ten working days of step one.
Bug-count quotas, on-call without pay, or silence about your own research. You keep your name on your CVEs, and our 90-day disclosure policy applies to your findings too.
Open roles

Four seats. Each one leads its own work.