Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Application Security Researcher role.
Rezi rewrites your resume against OX Security's job description. Free.

Tailor your resume to this Application Security Researcher role.
Rezi rewrites your resume against OX Security's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Application Security Researcher posting at OX Security — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Application Security Researcher posting at OX Security — free, in seconds.
About the Role
OX Security secures the AI-driven SDLC from prompt to production, eliminating critical, real-time risks from AI code generation. We are seeking a skilled Application Security Researcher to join our Security Research group, focusing on building next-generation application security, including autonomous, agentic pen testing capabilities. This role involves building, breaking, and redefining offensive security at scale.
Responsibilities
- Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure.
- Design and build detection engines and decision-making logic for autonomous security systems.
- Evaluate AI models for application security use cases, measuring their performance and limitations.
- Prototype, build, and ship security capabilities into production environments.
- Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy.
- Partner with Product, Engineering, and Data teams to shape the next generation of security features.
- Set the team's research direction and own initiatives end to end, from idea to shipped capability.
Requirements
- M.Sc. in Computer Science, Cyber Security, or a related field.
- 5+ years of hands-on experience in offensive security, vulnerability research, or application security.
- Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains.
- Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code.
- Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives.
- Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider.
- Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail.
- Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy.
- Ability to take a research idea from prototype to production with minimal guidance.
- Clear written communication skills to explain complex attack paths to engineers and product managers.
- Published research, CVEs, conference talks, or bug bounty track record.
- Experience building AI agents or evaluation frameworks for LLMs.
- Background in exploit development, red teaming, or penetration testing.
- Experience with code analysis techniques (taint analysis, call graphs, reachability).
- Contributions to open-source security tools.
Skills
- Python
- Go
- Web application vulnerabilities
- API vulnerabilities
- Business-logic flaws
- Multi-step attack chains
- Detection engines
- SAST
- DAST
- SCA
- Secrets detection
- Rule engines
- CI/CD pipelines
- Containers
- Kubernetes
- Cloud platforms
- LLMs
- AI models
- SQL
- BigQuery
- Vulnerability research
- Offensive security
- Application security
- Exploit development
- Red teaming
- Penetration testing
- Code analysis
- Taint analysis
- Call graphs
- Reachability
- Open-source security tools
Experience Level
- 5+ years of hands-on experience
Education Level
- M.Sc. in Computer Science, Cyber Security, or a related field
Benefits
- Comprehensive Health Coverage: Medical, Dental, and Vision plans.
- Unlimited Paid Time Off (PTO).
- Gifts on your birthday & anniversary, & Holidays.
About the Company
- OX Security secures the AI-driven SDLC from prompt to production.
- We eliminate critical, real-time risks from AI code generation through cloud runtime by doing what conventional tools can’t: unifying development and cloud context to stop vulnerabilities right at the source.
- At OX, we’re building the future of cyber security for the AI era.
- If you’re looking to work on disruptive technology with an amazing team, you belong here.