3 дня назад
Application Security Researcher (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Researcher (AI) (Python/Go, Kubernetes, LLMs): Building and shipping autonomous application security capabilities, detection engines, and decision-making logic with an accent on vulnerability chaining, business-logic flaws, AI model evaluation, and large-scale security data analysis. Focus on researching complex attack paths, reducing detection false positives, and taking security research from prototype to production.
Location: Argentina
Company
develops AI-driven application and cloud security technology that connects development and runtime context to detect and prevent vulnerabilities.
What you will do
- Research vulnerability chains, business-logic flaws, and complex attack paths across applications and infrastructure.
- Design and build detection engines and decision-making logic for autonomous security systems.
- Evaluate AI and LLM-based models for application security use cases and measure their effectiveness.
- Prototype, build, and ship security capabilities into production environments.
- Analyze large-scale security data to improve detection accuracy and identify exploitable attack paths.
- Partner with Product, Engineering, and Data teams while owning research initiatives from idea to production.
Requirements
- M.Sc. in Computer Science, Cyber Security, or a related field.
- 5+ years of hands-on experience in offensive security, vulnerability research, or application security.
- Deep knowledge of web application and API vulnerabilities, business-logic flaws, and multi-step attack chains.
- Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code.
- Experience with detection logic, CI/CD pipelines, containers, Kubernetes, a major cloud provider, and large datasets using SQL, BigQuery, or similar tools.
- Hands-on experience with LLMs or AI models for security tasks and the ability to communicate complex attack paths clearly.
Nice to have
- Published research, CVEs, conference talks, or a bug bounty track record.
- Experience building AI agents or LLM evaluation frameworks.
- Background in exploit development, red teaming, or penetration testing.
- Experience with taint analysis, call graphs, reachability, or open-source security tools.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →