Назад
Company hidden
6 дней назад

Application Security Researcher (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Researcher (AI): Building autonomous application security capabilities, including detection engines, decision-making logic, and agentic penetration testing systems, with an accent on vulnerability research, AI model evaluation, and production-grade security tooling. Focus on chaining complex attack paths, analyzing large-scale security data, reducing detection false positives, and taking research ideas from prototype to production.

Location: Canada

Company

hirify.global secures the AI-driven software development lifecycle from prompt to production by unifying development and cloud context to prevent vulnerabilities at their source.

What you will do

  • Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure.
  • Design and build detection engines and decision-making logic for autonomous security systems.
  • Evaluate AI models for application security use cases and measure their effectiveness and limitations.
  • Prototype, build, and ship security capabilities into production environments.
  • Analyze large-scale security data to identify exploitable attack paths and improve detection accuracy.
  • Partner with Product, Engineering, and Data teams while owning research initiatives from idea to shipped capability.

Requirements

  • M.Sc. in Computer Science, Cyber Security, or a related field.
  • 5+ years of hands-on experience in offensive security, vulnerability research, or application security.
  • Deep understanding of web application and API vulnerabilities, business-logic flaws, and multi-step attack chains.
  • Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code.
  • Experience with detection logic such as SAST, DAST, SCA, secrets, or custom rule engines, including reducing false positives.
  • Knowledge of CI/CD pipelines, containers, Kubernetes, a major cloud provider, LLMs or AI models, and large datasets using SQL, BigQuery, or similar tools.

Nice to have

  • Published research, CVEs, conference talks, or a bug bounty track record.
  • Experience building AI agents or LLM evaluation frameworks.
  • Background in exploit development, red teaming, or penetration testing.
  • Experience with taint analysis, call graphs, reachability, or open-source security tools.

Culture & Benefits

  • Hands-on work on application security for the AI era.
  • Collaboration with engineers, security researchers, and AI and data scientists.
  • Medical, dental, and vision coverage for Canada-based team members through Vensure.
  • Unlimited paid time off with an emphasis on work-life balance.
  • Birthday, work anniversary, and holiday gifts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →