We're looking for an experienced Application Security Researcher to help customers maximize the value of our AI-powered offensive security platform.
In this role, you'll work hands-on with customer environments, validate security findings, investigate complex application vulnerabilities, and help organizations understand, reproduce, and remediate the risks identified by our platform.
You'll collaborate closely with customers, Product, Engineering, AI Research, and Customer Success teams, providing valuable feedback that continuously improves the platform while serving as a trusted technical advisor throughout the customer journey, from complex deployments to production investigations.
This is an ideal role for someone with a strong offensive security background who enjoys combining technical research with customer interaction and wants to help shape the future of AI-driven application security.
Responsibilities
Validate vulnerabilities discovered by our AI platform and provide clear technical evidence of successful exploitation.
Perform hands-on testing of modern web applications and APIs to verify findings and identify additional attack paths.
Analyze complex application security issues, including authentication, authorization, business logic flaws, and API vulnerabilities.
Help customers understand security findings, reproduce vulnerabilities, assess risk, and implement remediation recommendations.
Investigate cases where the platform missed, misclassified, or incorrectly assessed vulnerabilities and provide actionable feedback to Product and Engineering teams.
Collaborate closely with AI Research and Engineering teams to improve detection accuracy, attack coverage, and platform capabilities.
Develop new attack methodologies and validation techniques for modern web applications.
Stay current on emerging application security trends, offensive techniques, and modern attack methodologies.
Support customers during complex deployments, integrations, and production troubleshooting, including BYOM deployments and connectivity to internal applications.
Requirements: Requirements
3+ years of hands-on experience in Application Security, Web Application Penetration Testing, Bug Bounty, or Red Team operations.
Deep expertise in Web Application and API security.
Strong understanding of OWASP Top 10, authentication, authorization, business logic vulnerabilities, SSRF, XXE, deserialization, injection flaws, and modern attack techniques.
Experience using Burp Suite and other offensive security tools.
Ability to clearly communicate complex security findings to both technical and non-technical audiences.
Experience writing code or scripts to support security testing and automation (Python, JavaScript, Go, or similar).
Strong analytical and problem-solving skills.
Comfortable working independently in a fast-paced startup environment with a high degree of ownership.
Experience working directly with large enterprise customers, troubleshooting complex technical environments, and supporting production deployments.
Solid understanding of enterprise networking, authentication mechanisms, VPNs, proxies, and common application deployment architectures.
Nice to Have
Experience performing infrastructure penetration testing, including Active Directory assessments.
Familiarity with Mobile or Infrastructure security assessments.
Experience reviewing application source code.
Experience developing security tooling or automation.
Red Team experience.
Experience participating in Bug Bounty programs.
Familiarity with AI-powered security products or LLM technologies.
This position is open to all candidates.