DescriptionAbout the PositionWe9re looking for a highly skilled
Application Security Researcher to join our Security Research group and help us push the boundaries of modern AppSec. This is a critical, hands-on role where you9ll work closely with engineers, researchers, and AI & data scientists to build the next generation of application security - including autonomous, agentic pen testing capabilities.
This is not a typical AppSec role. You9ll be building, breaking, and redefining how offensive security works at scale.
ResponsibilitiesWhat You9ll Be Doing- Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure
- Design and build detection engines and decision-making logic for autonomous security systems
- Evaluate AI models for application security use cases, measuring where they perform and where they fall short
- Prototype, build, and ship security capabilities into production environments
- Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy
- Partner with Product, Engineering, and Data teams to shape the next generation of security features
- Help set the team9s research direction and own initiatives end to end, from idea to shipped capability
RequirementsWhat You9ll Bring- M.Sc. in Computer Science, Cyber Security, or a related field
- 5+ years of hands-on experience in offensive security, vulnerability research, or application security
- Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
- Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code
- Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
- Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
- Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail
- Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
- Ability to take a research idea from prototype to production with minimal guidance
- Clear written communication: you can explain a complex attack path to engineers and product managers
Nice to Have- Published research, CVEs, conference talks, or bug bounty track record
- Experience building AI agents or evaluation frameworks for LLMs
- Background in exploit development, red teaming, or penetration testing
- Experience with code analysis techniques (taint analysis, call graphs, reachability)
- Contributions to open-source security tools
Benefits Package (via Vensure)
We partner with Vensure to provide top-tier benefits for our Canada-based team members:
- Comprehensive Health Coverage: Medical, Dental, and Vision plans to keep you and your family healthy.
- Unlimited Paid Time Off (PTO): We offer unlimited vacation because we trust you to take time when you need it and to manage your time effectively. We value work-life balance and want you to recharge.
- Gifts on your birthday & anniversary, & Holidays.