
Security Researcher
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Latvia.
• Conduct research on browser, WebView, Android, and iOS environments from the perspective of an attacker.
• Detect security signals, behavioral indicators, and technical patterns to enhance detection of fraud, abuse, automation, and AI agents.
• Examine attacker methodologies that involve bots, browser automation, AI agents, emulators, device spoofing, hooking, instrumentation, remote access tools, and anti-detection techniques.
• Develop and conduct experiments to compare legitimate, automated, AI-assisted, and manipulated environments.
• Assess signals for their reliability, stability, susceptibility to spoofing, privacy implications, performance impact, and production viability.
• Convert research insights into SDK feature specifications for web and mobile data gathering.
• Create internal tools, scripts, and lab environments for signal research and validation purposes.
• Work collaboratively with SDK, engineering, product, and detection teams to transition research from theory to production.
• Minimum of 3 years of practical experience in security research, mobile security, browser research, fraud research, detection research, reverse engineering, or a related technical field.
• Proficient in web browsers, mobile browsers, WebViews, browser APIs, JavaScript runtime behavior, browser automation, fingerprinting, client-side web security, and low-level browser technologies.
• Knowledge of modern open-source browser and rendering-engine architectures or codebases, such as Chromium, WebKit, Blink, or Gecko.
• Experience with native Android and/or iOS applications, mobile OS behavior, app instrumentation, emulators, device spoofing, mobile automation, mobile security, and low-level platform APIs.
• Solid understanding of attacker techniques that involve automation, AI agents, spoofing, and anti-detection methods.
• Ability to identify nuanced technical signals and leverage them for detection or data collection purposes.
• Experience in designing technical experiments and validating research hypotheses.
• Familiarity with SDK development languages and environments such as TypeScript/JavaScript, Kotlin/Java, or Swift/Objective-C.
• Proficiency in scripting, preferably in Python.
• Capability to work independently on ambiguous challenges and articulate findings clearly to engineering, product, and research stakeholders.
• Experience with Web SDKs, Mobile SDKs, client-side telemetry, device intelligence, behavioral signals, AI agent detection, or fraud detection products is a plus.
• Background in researching bots, credential stuffing, scraping, headless browsers, AI-assisted automation, app cloning, SDK abuse, phishing kits, malware, or anti-detection frameworks is advantageous.
• Experience in reverse engineering Android or iOS applications is a plus.
• Familiarity with detection quality measurement, feature evaluation, false-positive analysis, production monitoring, or machine learning concepts is beneficial.
• A Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related field, or equivalent practical experience is beneficial.
• Security through thorough client vetting, reducing risks and ensuring prompt, reliable payments.
• Career support and assistance in locating new opportunities if a project does not meet expectations.
• Legal assistance regarding independent contractor or sole proprietorship status, taxes, and related processes.
• English language courses.
• Opportunities for professional growth.
• Team-building activities.
• People-centric management approach with minimal bureaucracy.
• Supportive company culture.
• Flexible working hours.
• Comprehensive financial and legal support for independent contractors.
• Free English classes with native speakers or Ukrainian teachers.
• Dedicated HR support.
NTT
BDR Solutions LLC
ON Partners
Danaher Corporation
Get handpicked remote jobs straight to your inbox weekly.