
Senior Application Security Researcher
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Canada.
• Perform practical application security research to enhance contemporary AppSec practices.
• Collaborate with engineers, researchers, and AI/data scientists on cutting-edge detection technologies.
• Create autonomous, intelligent penetration-testing capabilities.
• Focus on constructing and dismantling security systems instead of engaging in standard AppSec tasks.
• Transform research concepts from initial prototype to final production.
• Over 5 years of hands-on experience in offensive security, vulnerability research, or application security.
• In-depth knowledge of web application and API vulnerabilities, including business-logic flaws and multi-step attack sequences.
• Proficient coding skills in Python, Go, or similar languages, with experience delivering production-quality code.
• Background in developing or refining detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and minimizing false positives.
• Strong understanding of modern technology stacks: CI/CD pipelines, containers, Kubernetes, and familiarity with at least one major cloud service provider.
• Practical experience using LLMs/AI models for security applications, with the ability to assess their effectiveness and limitations.
• Comfortable working with large datasets (SQL, BigQuery, or similar) to support research and evaluate detection accuracy.
• Capable of taking research ideas from prototype to production with limited assistance.
• Excellent written communication skills — able to articulate complex attack paths to engineers and product managers.
• Master’s degree in Computer Science, Cyber Security, or a related discipline.
• Record of published research, CVEs, conference presentations, or a successful bug bounty history.
• Experience in creating AI agents or assessment frameworks for LLMs.
• Expertise in exploit development, red teaming, or penetration testing.
• Familiarity with code analysis techniques (taint analysis, call graphs, reachability).
• Contributions to open-source security projects.
• Opportunity to work on innovative security solutions.
• Collaborative environment with talented professionals across various fields.
• Professional growth and development opportunities.
• Competitive salary and benefits package.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.