
Security Researcher
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Estonia.
• Conduct research on browser, WebView, Android, and iOS environments from the viewpoint of an attacker.
• Discover new security signals, behavioral indicators, and technical patterns aimed at enhancing fraud, abuse, automation, and AI agent detection.
• Examine attacker methodologies involving bots, browser automation, AI agents, emulators, device spoofing, hooking, instrumentation, remote access tools, and anti-detection strategies.
• Design and execute experiments to compare legitimate, automated, AI-assisted, and manipulated environments.
• Assess signals for dependability, stability, susceptibility to spoofing, privacy implications, performance impact, and feasibility in production.
• Convert research insights into precise SDK feature requirements for web and mobile data gathering.
• Develop internal tools, scripts, and lab environments to facilitate signal research and validation.
• Collaborate with SDK, engineering, product, and detection teams to transition research from hypothesis to production.
• A minimum of 3 years of practical experience in security research, mobile security, browser research, fraud research, detection research, reverse engineering, or a comparable technical role.
• Proficient understanding of web browsers, mobile browsers, WebViews, browser APIs, JavaScript runtime behavior, browser automation, fingerprinting, client-side web security, and low-level browser technologies.
• Familiarity with the architecture or codebase of contemporary open-source browsers and rendering engines, including Chromium, WebKit, Blink, or Gecko.
• Experience with native Android and/or iOS applications, mobile OS behavior, app instrumentation, emulators, device spoofing, mobile automation, mobile security, and low-level platform APIs.
• Sound understanding of how malicious actors attempt to evade detection using automation, AI agents, spoofing, and anti-detection methods.
• Capability to recognize subtle technical signals and translate them into actionable detection or data collection opportunities.
• Proven experience in designing technical experiments and validating research hypotheses.
• Proficiency in one or more SDK development languages and environments, such as TypeScript/JavaScript, Kotlin/Java, or Swift/Objective-C.
• Scripting skills, preferably in Python.
• Ability to work autonomously on ambiguous problems and effectively communicate findings to engineering, product, and research stakeholders.
• Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related field, or equivalent practical experience.
• Security: carefully vetted clients to reduce risks and ensure reliable and timely payments.
• Career support and assistance in discovering new opportunities if a project does not align well.
• Legal aid regarding independent contractor or sole proprietorship status, taxes, and related processes.
• English language courses.
• Opportunities for professional growth.
• Team-building activities.
• People-centered management with minimal bureaucracy.
• A friendly company culture.
• Flexible working hours.
• Comprehensive financial and legal support for independent contractors.
• Free English classes with native speakers or Ukrainian instructors.
• Dedicated HR support.
NTT
BDR Solutions LLC
ON Partners
Danaher Corporation
Get handpicked remote jobs straight to your inbox weekly.