About the Role
You will lead security research at the company, inventing novel approaches that become product capabilities using LLMs and program analysis. You will own the path from idea to shipped capability, including hypothesis formation, proof of concept building, measurement, and partnering with engineering. You will also set the quality bar for benchmarks and evaluations, and shape how research operates as the team grows.
Responsibilities
- Identify where novel approaches can meaningfully beat the state of the art in vulnerability detection, triage, and remediation, and decide what to pursue.
- Build proofs of concept for new detection and remediation techniques, validate them, and carry them through to production.
- Design datasets, benchmarks, and evaluation pipelines to measure precision, coverage, and false-positive rates.
- Conduct deep research into modern attack vectors across cloud, containers, microservices, APIs, AI-generated code, and LLM applications.
- Develop the internal corpus of vulnerabilities, exploit patterns, and remediation strategies.
- Define the company's research publications, speaking engagements, and community credibility.
Requirements
- 8+ years in security research, vulnerability analysis, or applied security engineering.
- Experience in an early-stage or 0→1 environment, comfortable with ambiguity and changing direction.
- Proven track record of turning research into shipped products, features, or detections.
- Deep expertise in modern application stacks (microservices, containers, cloud platforms).
- Strong programming ability in at least one modern language (Python, Go, TypeScript, etc.).
- Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively.
- Hands-on experience applying LLMs to real problems or a demonstrated ability to do so quickly.
- History of discovering serious vulnerabilities and responsible disclosure.
- Ability to clearly explain complex attacks and their impact to various audiences.
- Permanent authorization to work in the US (for San Francisco role) or Israel (for Israel role).
Skills
- Security research
- Vulnerability analysis
- Applied security engineering
- LLMs
- Program analysis
- Modern application stacks
- Microservices
- Containers
- Cloud platforms
- Python
- Go
- TypeScript
- Experiment design
- Dataset building
- Benchmarking
- Quantitative measurement
- Prompting
- Fine-tuning
- Agentic systems
- Responsible disclosure
- Communication
Location
- San Francisco, CA
- Israel
Work Type
- Full-time
- Onsite
Experience Level
- 8+ years
About the Company
- A well-funded security startup founded by leaders from Microsoft's vulnerability mitigation efforts and Tesla's offensive research.
- Building a platform to fundamentally change how companies handle security vulnerabilities by understanding and fixing them at the root.
- Focusing on research problems to develop novel detection, triage, and remediation capabilities.
