1 день назад
Staff Security Researcher (AI)
225 000 - 300 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Security Researcher (AI): Conducting original offensive security research against Dia, its agent runtime, browser client, integrations, and backend services with an accent on prompt injection, tool-call abuse, sandbox escape, and cross-profile data access. Focus on building continuous AI-assisted vulnerability discovery, fuzzing, agentic hunting pipelines, and structural defenses that eliminate entire classes of bugs.
Location: Remote in the United States or Canada; 4+ hours of overlap with Eastern Time required. Optional office work is available in Williamsburg, Brooklyn, New York.
Annual base salary: $225,000–$300,000 USD, plus equity and benefits.
Company
builds Dia, a browser enhanced with agentic capabilities, alongside tools that help people organize, create, and explore on the internet.
What you will do
- Conduct original offensive security research against Dia, its agent, browser client, tools, integrations, and backend services.
- Investigate prompt injection, indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, and quota or abuse-scoring bypass.
- Threat model new product surfaces and review features before launch with client, infrastructure, and product engineering teams.
- Build model-driven scanning, fuzzing harnesses, and agentic vulnerability-hunting pipelines for code, infrastructure, and the agent runtime.
- Run AI-assisted red-team exercises and develop attack corpora and reusable testing harnesses.
- Define structural fixes, enforced invariants, fail-closed defaults, tests, and platform changes that prevent bug classes from returning.
Requirements
- 8+ years of experience in offensive security, vulnerability research, exploit development, red teaming, or product security testing.
- Deep expertise in at least one of: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure.
- Practical experience using LLMs as security instruments and understanding when their output is unreliable.
- Production-quality programming skills in Go, TypeScript, Python, or Swift.
- Ability to produce actionable security findings and collaborate with engineers on durable remediation without owning the fixes.
- Must be available in North American time zones with 4+ hours of overlap with Eastern Time.
Nice to have
- Experience building automated vulnerability discovery systems that operate continuously.
- Experience with AI-assisted red-team exercises, agentic hunting, or security testing of browser and cloud platforms.
Culture & Benefits
- Remote-first, distributed environment with approximately 100 employees.
- Optional access to the Brooklyn, New York office.
- Equity and comprehensive benefits for full-time employees.
- Big-company benefits combined with startup-style impact, ownership, and flexible ways of working.
- Inclusive environment that encourages applications from people of diverse backgrounds.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Security Engineer (AI)
5 дней назад
AI Security Engineer (Agentic Systems)
CrowdStrike
4 дня назад
Red Team Manager (Cybersecurity)
140 000 - 195 000$
Robinhood
8 дней назад
Offensive Security Intern (Summer 2027)
60 - 60$
3 дня назад
Associate Security Consultant (NetSPI University) (Cybersecurity)
2 дня назад