Senior Security Researcher (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Senior Security Researcher (Cybersecurity): Conducting advanced vulnerability research and security assessments across modern application stacks and cloud infrastructure with an accent on exploit crafting and threat analysis. Focus on identifying high-impact security flaws, developing proof-of-concept exploits, and innovating offensive security tradecraft.
Location: Remote (Must be based in the United States, preferably EST or CST time zones)
Salary: $120,000 - $150,000 per year
Company
provides seamless and collaborative Offensive Security Testing via a SaaS platform and an exclusive community of vetted testers.
What you will do
- Perform deep-dive vulnerability research and reverse engineering across Web/API platforms, OS stacks, and cloud infrastructures (AWS/GCP/Azure/K8s).
- Develop PoC exploits to demonstrate real-world risk for complex vulnerability classes such as memory corruption and RCE.
- Research emerging threat vectors and update industry-leading testing guidelines for AI/ML and cloud environments.
- Partner with Product and Engineering teams to integrate research findings into scalable automated testing workflows.
- Mentor junior researchers and provide technical QA for complex research initiatives.
- Represent the company through technical blog posts, whitepapers, and presentations at conferences like DEF CON and Black Hat.
Requirements
- 5+ years of experience in offensive security, vulnerability research, or red teaming (or 3+ with a strong track record of CVEs/research).
- Expertise in modern stacks: Node.js, Go, Python, Java, Rust, and OS internals (Linux/Windows/macOS).
- Proficiency in Python, Go, Bash, or Rust for building custom research tools and utilities.
- Hands-on experience with containerized environments like Docker and Kubernetes.
- Must reside in the United States.
Nice to have
- Knowledge of AI/ML security and LLM risk models.
- Experience with reverse engineering tools such as Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB.
- Published CVEs or bug bounty hall-of-fame recognitions.
- Certifications such as OSCP, OSEP, OSWE, OSEE, or GXPN.
Culture & Benefits
- Competitive compensation and an attractive equity plan.
- 401(k) program and comprehensive medical, dental, vision, and life insurance.
- Stipends for wellness, home-office equipment, and professional development.
- Flexible and generous paid time off and paid parental leave.
- Direct mentorship from experienced senior leaders in the pentesting industry.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β