Назад
Company hidden
3 дня назад

Application Security Researcher (AI)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Researcher (AI): Validating AI-discovered vulnerabilities, testing modern web applications and APIs, and helping enterprise customers reproduce and remediate security risks with an accent on authentication, authorization, business logic, and API security. Focus on investigating missed or misclassified vulnerabilities, developing attack methodologies, supporting complex deployments, and improving AI-driven detection with Product, Engineering, and AI Research teams.

Company

hirify.global develops an AI-powered continuous penetration testing platform for enterprise application security.

What you will do

  • Validate vulnerabilities identified by the AI platform and produce technical evidence of successful exploitation.
  • Test modern web applications and APIs to verify findings and uncover additional attack paths.
  • Investigate authentication, authorization, business logic, SSRF, XXE, deserialization, injection, and other application security issues.
  • Help customers reproduce findings, assess risk, implement remediation, and troubleshoot complex deployments, integrations, BYOM environments, and production issues.
  • Analyze missed, misclassified, or incorrectly assessed vulnerabilities and provide feedback to Product, Engineering, and AI Research.
  • Develop attack methodologies and validation techniques while tracking emerging offensive security trends.

Requirements

  • 3+ years of hands-on experience in application security, web application penetration testing, bug bounty, or red team operations.
  • Deep expertise in web application and API security, including OWASP Top 10, authentication, authorization, business logic vulnerabilities, and modern attack techniques.
  • Experience with Burp Suite and other offensive security tools.
  • Ability to write code or scripts for security testing and automation using Python, JavaScript, Go, or similar languages.
  • Experience working directly with enterprise customers, troubleshooting complex technical environments, and supporting production deployments.
  • Understanding of enterprise networking, VPNs, proxies, authentication mechanisms, and common application deployment architectures, plus strong technical communication and analytical skills.

Nice to have

  • Infrastructure penetration testing and Active Directory assessment experience.
  • Mobile or infrastructure security assessment experience.
  • Application source code review experience.
  • Security tooling or automation development experience.
  • Red team, bug bounty, or AI-powered security product experience.

Culture & Benefits

  • High ownership and the opportunity to influence product direction and customer success.
  • Close collaboration with security researchers, AI engineers, product leaders, and the founding team.
  • Exposure to AI and offensive security technologies.
  • Competitive compensation, equity, and benefits.
  • Opportunity to work on a platform protecting enterprise customers worldwide.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →