עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Salary: $180,000 to $230,000 base
Location: Remote, Global (US, Israel Preferred)
Seniority: Security Researcher / Senior Security Researcher
About the Company
- We are working with a fast-growing, AI-native application security company building the next generation of code security tooling.
- The team has rebuilt core AppSec workflows using LLMs to reduce false positives, identify deeper vulnerability classes, and improve how security teams detect issues in code. They are around 10 people, have raised approximately $12.5m, are close to a Series A, and already work with enterprise and Fortune 500 customers.
- Their research team has already disclosed vulnerabilities across major open-source projects including curl, FFmpeg, django-allauth, OpenSSL and Avahi.
The Role
- This is a hands-on vulnerability research role, combining manual security research with AI-augmented discovery.
- You will audit open-source and customer codebases, validate findings from an LLM-powered scanner, write vulnerability reports, support responsible disclosure, and help improve the detection engine.
What You’ll Be Doing
- Conduct vulnerability research across open-source and customer codebases.
- Review source code across Python, JavaScript, TypeScript, Go, Java, C or C++.
- Validate and triage AI-generated vulnerability findings.
- Write clear vulnerability reports and support disclosure / CVE processes.
- Refine detection rules, heuristics and prompt strategies.
- Work with engineering to improve detection of business logic flaws, auth issues and application-level vulnerabilities.
- Contribute to public research, blogs and technical write-ups.
Experience Needed:
- Public vulnerability research.
- CVEs or responsible disclosures.
- Bug bounty track record.
- Security conference talks.
- Boutique vulnerability research firm experience.
- Offensive security experience from a strong engineering environment.
- Elite government, intelligence or military cyber experience focused on exploitation or vulnerability discovery.
Not the Right Fit
This is unlikely to suit someone whose background is mainly network pentesting, Active Directory tradecraft, compliance-led testing, blue team operations, corporate product security, or software engineering with light security exposure.
Interview Process
- 45-minute screen with the hiring manager.
- 60 to 90-minute technical interview covering scripting and practical vulnerability discovery.
- Domain competency interview based on your area of expertise.
- Co-founder conversation.
This is a chance to join an early AI-native AppSec company at a major growth point, work directly with experienced security founders, find real vulnerabilities, and help shape how AI improves application security research.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.