
Senior Security Engineer – Research & Engineering
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United Kingdom.
• Assess specifications alongside designs and proofs to ascertain what has been established as opposed to what has been assumed.
• Utilize cutting-edge tools and advanced AI models to uncover issues that fall outside the scope of proofs.
• Execute red-team evaluations during one-week sprints following a preparatory period of seven weeks.
• Develop AI-driven discovery and triage tools, including agentic harnesses, triage pipelines, and automated exploit generation.
• Collaborate in small teams and engage with third-party partners.
• Report to a domain lead specializing in applied cryptography and proof systems, operating system internals, applications, hardware, or AI infrastructure.
• Ensure the separation of information across multiple concurrent engagements.
• Occasionally participate in sprints and hackathon events held in London.
• Compromise formally verified designs and production software, demonstrating vulnerabilities through working exploits.
• Map formal properties, threat models, and foundational assumptions to the actual attack surface.
• Produce clear security assessments documenting successful findings, unsuccessful attempts, and the limitations of proofs.
• Publish tools and methodologies, contribute to the blog, present internally, and share lessons learned between engagements.
• Proven experience with red teaming production software, being personally accountable for identifying and validating exploitable vulnerabilities.
• Hands-on involvement in offensive work, rather than exercise coordination or scanner triage.
• Experience in creating AI-driven tools for vulnerability discovery, including agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation.
• Familiarity with applying formal methods to system designs and code implementations.
• Ability to read specifications and proof artifacts, as well as reason about machine-checked proofs.
• Proficiency in at least one of the following: Lean, Rocq, F*, Dafny, or Verus/Rust.
• Experience in identifying vulnerabilities in network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure.
• Proficient in Python, C++, and/or Rust.
• Experience in producing security assessment reports for expert audiences.
• Proven experience in delivering projects to a fixed external schedule with defined acceptance criteria.
• Ethical handling of vulnerability reporting in technology.
• Preferred: published research on vulnerabilities, such as CVEs, advisories, or presentations at OffensiveCon, RECon, CCC, or USENIX Security.
• Preferred: experience auditing or contributing to formally verified codebases such as HACL*, EverCrypt, seL4, CompCert, or CakeML.
• Preferred: experience in building automated bug-finding infrastructures at scale.
• Preferred: knowledge of zero-knowledge proof systems, proof-checking kernels, or SMT-backed tools.
• Preferred: experience in attacking AI inference infrastructure.
• Preferred: participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar events.
• Preferred: familiarity with compiler technology, program analysis, or binary analysis.
• Preferred: experience in reading, writing, and publishing academic papers.
• Performance-based bonuses.
• $1,000 stipend for working from home.
• Annual stipend of $750 for Learning & Development.
• Company-sponsored team celebrations, including travel and accommodation.
• Philanthropic contribution matching up to $2,000 annually.
• Remote-first culture founded on autonomy and trust.
Newxel
Wealthsimple
Xcelerate Solutions
Catholic Relief Services
Get handpicked remote jobs straight to your inbox weekly.