The Exposure Management Research Group at our company Software Technologies is expanding. We are looking for an experienced Offensive Security Researcher to join our newly formed AEV Team and lead the offensive side of our Agentic Exposure Validation (AEV) research.
About the group
The Exposure Management Research Group is the research arm behind our company's Exposure Management platform. The platform helps organizations see and reduce their risk from the outside in, across their external attack surface, threat intelligence, and digital risk. The group brings together vulnerability researchers, threat intelligence analysts, phishing researchers, and data scientists. Together, we track threat actors and campaigns, analyze vulnerabilities and active exploitation, and turn that research into detections, intelligence, and validation capabilities that serve thousands of customers worldwide. Our work relies heavily on data science, machine learning, and agentic AI to operate at scale.
About the position
Exposure validation goes beyond identifying that a vulnerability exists. Its purpose is to show whether an attacker could actually exploit that vulnerability, and how far they could get. In this position, you are responsible for bringing real offensive expertise into our AEV capability, which runs on an agentic AI system that validates exposures across our customers' environments.
You conduct hands-on offensive research, define the exploitation methodologies the system follows, and set the standard for what a validated, customer-ready finding looks like. You also work closely with our threat intelligence and detection teams, so that proven attack paths turn into protections for our customers.
This is a research position with direct product impact. It combines practical red team work with shaping how an AI-driven platform conducts, reasons about, and reports offensive activity.
What you'll do
Design and run offensive research against external attack surfaces: web applications, APIs, cloud-exposed services, identity, and edge infrastructure
Turn single findings into demonstrated impact through exploit chaining, lateral movement, and blast-radius analysis
Write and maintain the exploitation methodologies and attack hypotheses our agentic AEV engine runs on
Review agent runs and findings. Separate proven impact from claimed impact, and turn the gaps you find into better prompts, methods, and guardrails
Set the bar for customer-ready findings: a clear impact story, a reproducible chain, and remediation guidance a security team can act on
Work with threat intelligence researchers to turn in-the-wild attacker behavior (named actors, active campaigns, newly exploited vulnerabilities) into validation plays
Help close the purple loop by turning proven attack paths into detection and protection logic, and working with detection engineering on coverage
Contribute to the team's research output, including internal knowledge sharing and, where it fits, external publications and talks.
Requirements: 2+ years of hands-on offensive security experience: red teaming, penetration testing, or offensive research
Real exploitation depth beyond confirming vulnerabilities, including exploit chaining, privilege escalation, lateral movement, and showing business impact
Comfort with the non-deterministic side of offense: business logic flaws, misconfigurations, credential and token abuse, and using information disclosure as an entry point
Strong scripting and automation skills (Python preferred)
Clear written communication. You can explain a complex attack chain to an engineer and to a CISO
Strong advantage
A consulting background covering many customer environments, not one internal estate. You know what customers value in an engagement deliverable and how to present it
Broad exposure to defensive technologies, security controls, and vendors, and an understanding of what attacks look like from the defender's side.
This position is open to all candidates.