Application Security Researcher

OX Security

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • M.Sc. in Computer Science, Cyber Security, or related field
  • 5+ years of hands-on experience in offensive security or application security
  • Deep understanding of web app and API vulnerabilities
  • Strong coding skills in Python, Go, or similar languages
  • Experience in building or tuning detection logic
  • Solid understanding of CI/CD, containers, Kubernetes, and cloud providers
  • Hands-on experience with AI models for security tasks
  • Ability to work with large datasets to drive research

Responsibilities

  • Research vulnerability chaining and complex attack paths
  • Design and build detection engines for autonomous security systems
  • Evaluate AI models for application security; measure performance
  • Prototype and ship security capabilities into production
  • Analyze large-scale security data to improve detection accuracy
  • Collaborate with cross-functional teams to shape security features
  • Set research direction and own initiatives from concept to execution

Benefits

  • Comprehensive Health Coverage including Medical, Dental, and Vision plans
  • Unlimited Paid Time Off (PTO) to promote work-life balance
  • Gifts on your birthday, anniversary, and holidays
Full Job Description
Description

About the Position

We9re looking for a highly skilled Application Security Researcher to join our Security Research group and help us push the boundaries of modern AppSec. This is a critical, hands-on role where you9ll work closely with engineers, researchers, and AI & data scientists to build the next generation of application security - including autonomous, agentic pen testing capabilities.

This is not a typical AppSec role. You9ll be building, breaking, and redefining how offensive security works at scale.

Responsibilities

What You9ll Be Doing

  • Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure
  • Design and build detection engines and decision-making logic for autonomous security systems
  • Evaluate AI models for application security use cases, measuring where they perform and where they fall short
  • Prototype, build, and ship security capabilities into production environments
  • Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy
  • Partner with Product, Engineering, and Data teams to shape the next generation of security features
  • Help set the team9s research direction and own initiatives end to end, from idea to shipped capability

Requirements

What You9ll Bring

  • M.Sc. in Computer Science, Cyber Security, or a related field
  • 5+ years of hands-on experience in offensive security, vulnerability research, or application security
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
  • Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
  • Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
  • Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail
  • Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
  • Ability to take a research idea from prototype to production with minimal guidance
  • Clear written communication: you can explain a complex attack path to engineers and product managers


Nice to Have

  • Published research, CVEs, conference talks, or bug bounty track record
  • Experience building AI agents or evaluation frameworks for LLMs
  • Background in exploit development, red teaming, or penetration testing
  • Experience with code analysis techniques (taint analysis, call graphs, reachability)
  • Contributions to open-source security tools

Benefits Package (via Vensure)

We partner with Vensure to provide top-tier benefits for our Canada-based team members:

  • Comprehensive Health Coverage: Medical, Dental, and Vision plans to keep you and your family healthy.
  • Unlimited Paid Time Off (PTO): We offer unlimited vacation because we trust you to take time when you need it and to manage your time effectively. We value work-life balance and want you to recharge.
  • Gifts on your birthday & anniversary, & Holidays.

Similar Jobs

More Jobs at OX Security

More Information Technology Jobs

Find similar Application Security Researcher jobs: