Pros
- The work at RBS is pretty unique. After 2 years and numerous opportunities to engage with the security community I would hazard guess that we're the only organization in the US doing binary analysis at this level outside of the intelligence community. - I like modifying system level binaries without truly disturbing the expectations users and vendors have about the system and its performance. (This is one of the most exciting parts about working here for me.) - To date, we operate ethically. We don't sell vulnerabilities. We disclose them responsibly. Full stop. - Generous compensation - The CEO believes in the value of conference attendance, and in non-pandemic years many of our employees attend events like Recon, DEFCON, etc. - Flexible budget for "10% time" projects relating to embedded security. - Given the nature of our work, some roles have a daily or frequent physical need to be in office or in lab. Despite this, we have historically maintained a flexible work from home policy. - After having seen and contributed to Red Balloon's IP, I believe in its high long term value.
Cons
There's not much that is unique to this company that isn't seen at most growth companies with small headcount: - At times, long hours - Shifting priorities - Unclear objectives (though today this is improving) Specific to RBS: - Management spread a bit thin (though this is changing in the coming months) - Engineering skews quite young; however, over 10 years, it has maintained an impressive level of talent through rigorous hiring practices.