Назад
Company hidden
4 дня назад

Principal Security Researcher (AI Security)

203 200 - 275 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Israel +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Researcher (AI Security): Conducting advanced security research and penetration testing across GitLab's AI-powered DevSecOps platform, Duo Agent Platform, and AI workflows with an accent on vulnerability discovery, exploit validation, and systemic remediation. Focus on researching prompt injection, agent manipulation, workflow exploitation, and building automation for agent-assisted vulnerability discovery.

Location: Remote in Canada, Israel, the United Kingdom, or the United States

Salary: $203,200–$275,000 USD per year for United States residents

Company

hirify.global provides an intelligent orchestration platform for DevSecOps used by organizations to improve developer productivity, operational efficiency, security, and compliance.

What you will do

  • Lead security research projects across hirify.global's DevSecOps platform, Duo Agent Platform, hirify.global Duo Chat, and AI workflows.
  • Identify systemic and chained vulnerabilities, validate them through hands-on testing, and develop proof-of-concept exploits.
  • Research AI and agentic security surfaces, define security requirements, and investigate attack scenarios.
  • Build tooling and automation for scalable security research, including agent-assisted vulnerability discovery.
  • Assess open-source tools and dependencies, coordinate responsible disclosure, and track mitigation.
  • Lead remediation initiatives, shape the security roadmap, and mentor security researchers and engineering teams.

Requirements

  • 10+ years of experience in security research, penetration testing, or offensive security.
  • Strong ability to discover and exploit vulnerabilities in large codebases and complex systems.
  • Proficiency in at least two of Ruby, Go, Python, TypeScript, or Rust, with the ability to analyze multiple programming languages.
  • Strong knowledge of AI frameworks and AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
  • Ability to drive complex cross-functional remediation initiatives and communicate technical risks clearly.
  • Remote work eligibility is limited to Canada, Israel, the United Kingdom, or the United States.

Nice to have

  • Published security research or conference presentations.
  • Software engineering experience with distributed systems expertise.
  • Experience with hirify.global or similar DevSecOps platforms.

Culture & Benefits

  • Remote-first work environment with flexible paid time off.
  • Health, financial, and well-being benefits.
  • Equity compensation and an employee stock purchase plan.
  • Growth and development fund.
  • Parental leave and team member resource groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →