Remote job
Security Researcher
Job details
About this role
Role overview Hunt for real-world vulnerabilities across open-source and customer codebases, validate findings produced by an LLM-powered scanner, and shape the detection engine that powers a security platform. The role blends hands-on security research with AI-augmented discovery, auditing code in multiple languages, triaging automated results to calibrate false-positive rates, and feeding expertise back into detection rules. Prior research from this team has already driven fixes in widely used projects, and the next researcher will continue expanding that body of disclosures.
Responsibilities - Conduct security research on open-source projects and customer codebases across multiple programming languages. - Validate and triage AI-generated vulnerability findings to calibrate false-positive rates. - Write detailed vulnerability reports and coordinate responsible disclosure and CVE assignment. - Define and refine detection rules, heuristics, and prompt strategies for the scanning engine. - Collaborate with engineering to improve detection of business logic flaws and authentication bypasses. - Contribute to a public research blog and project recognition page.
Requirements - 3+ years of experience in application security research, penetration testing, or red teaming. - Demonstrated ability to find and responsibly disclose vulnerabilities, evidenced by CVEs, bug bounties, or published research. - Strong understanding of common vulnerability classes including the OWASP Top 10, business logic flaws, auth bypasses, and injection chains. - Proficiency reading and analyzing code across Python, JavaScript or TypeScript, Go, Java, or C and C++. - Experience with static analysis concepts, code review, and source code auditing. - Excellent written communication for vulnerability reports and research write-ups.
Nice to have - Published CVEs or a meaningful bug bounty track record. - Experience with tree-sitter, semgrep, CodeQL, or similar code analysis tooling for benchmarking. - Familiarity with LLM-powered security tools or AI-augmented research workflows. - Contributions to open-source security projects.