Member of Technical Staff, Vulnerability Researcher

CONFISA INTERNATIONAL GROUP

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Conduct advanced offensive security research across cloud infrastructure (AWS, GCP), production services, and AI platforms
  • Design and execute adversary simulations targeting identity systems, cloud control planes, and supply chains
  • Discover and exploit vulnerabilities in proprietary applications, APIs, CI/CD pipelines, and AI-powered workflows
  • Research emerging attack vectors against LLMs, AI agents, and retrieval systems
  • Reverse engineer critical services to uncover architectural weaknesses and novel exploitation techniques
  • Build custom offensive tooling, automation frameworks, fuzzers, and proof-of-concept exploits
  • Partner with engineering teams to validate fixes and improve secure-by-design practices

Requirements

  • Proven experience in offensive security, vulnerability research, red teaming, or exploit development
  • Deep understanding of cloud security (AWS, GCP), IAM, Kubernetes, and containers
  • Strong background in application security, code auditing, and reverse engineering
  • Proficiency in Python, Go, Rust, C/C++, or similar security research languages
  • Strong understanding of operating system internals, networking, and authentication protocols
  • Excellent written communication skills

Preferred Qualifications

  • Experience researching AI/LLM security (prompt injection, jailbreaks, RAG security)
  • Experience discovering zero-day vulnerabilities or contributing to bug bounty programs
  • Published CVEs, conference talks, or open-source security tooling
  • Familiarity with fuzzing, symbolic execution, or binary analysis

Benefits

  • Base salary of $200,000 – $250,000
  • Equity compensation eligibility
  • Performance-based bonuses
  • Up to 100% reimbursement for health-insurance premiums
  • Paid time off
  • 401(K) plan with company match

Skills & tools

CybersecurityCloud Security

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Offensive security experience
  2. 02Cloud security expertise (AWS/GCP)
  3. 03Application security background
  4. 04Proficiency in Python, Go, Rust, or C/C++
  5. 05OS internals knowledge
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches