Назад
Company hidden
1 день назад

Staff Security Researcher (AI)

225 000 - 300 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Researcher (AI): Conducting original offensive security research against Dia, its agent runtime, browser client, integrations, and backend services with an accent on prompt injection, tool-call abuse, sandbox escape, and cross-profile data access. Focus on building continuous AI-assisted vulnerability discovery, fuzzing, agentic hunting pipelines, and structural defenses that eliminate entire classes of bugs.

Location: Remote in the United States or Canada; 4+ hours of overlap with Eastern Time required. Optional office work is available in Williamsburg, Brooklyn, New York.

Annual base salary: $225,000–$300,000 USD, plus equity and benefits.

Company

hirify.global builds Dia, a browser enhanced with agentic capabilities, alongside tools that help people organize, create, and explore on the internet.

What you will do

  • Conduct original offensive security research against Dia, its agent, browser client, tools, integrations, and backend services.
  • Investigate prompt injection, indirect exfiltration, tool-call abuse, permission and provenance bypass, sandbox escape, cross-profile data access, and quota or abuse-scoring bypass.
  • Threat model new product surfaces and review features before launch with client, infrastructure, and product engineering teams.
  • Build model-driven scanning, fuzzing harnesses, and agentic vulnerability-hunting pipelines for code, infrastructure, and the agent runtime.
  • Run AI-assisted red-team exercises and develop attack corpora and reusable testing harnesses.
  • Define structural fixes, enforced invariants, fail-closed defaults, tests, and platform changes that prevent bug classes from returning.

Requirements

  • 8+ years of experience in offensive security, vulnerability research, exploit development, red teaming, or product security testing.
  • Deep expertise in at least one of: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure.
  • Practical experience using LLMs as security instruments and understanding when their output is unreliable.
  • Production-quality programming skills in Go, TypeScript, Python, or Swift.
  • Ability to produce actionable security findings and collaborate with engineers on durable remediation without owning the fixes.
  • Must be available in North American time zones with 4+ hours of overlap with Eastern Time.

Nice to have

  • Experience building automated vulnerability discovery systems that operate continuously.
  • Experience with AI-assisted red-team exercises, agentic hunting, or security testing of browser and cloud platforms.

Culture & Benefits

  • Remote-first, distributed environment with approximately 100 employees.
  • Optional access to the Brooklyn, New York office.
  • Equity and comprehensive benefits for full-time employees.
  • Big-company benefits combined with startup-style impact, ownership, and flexible ways of working.
  • Inclusive environment that encourages applications from people of diverse backgrounds.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →