Source Job

$168,000–$238,000/yr
Canada Israel UK United States Unlimited PTO

  • Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
  • Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
  • Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.

Security Research Penetration Testing Ruby Python

20 jobs similar to Staff Security Researcher

Jobs ranked by similarity.

US

  • Design adversarial prompts to test AI models for offensive security capabilities.
  • Evaluate model-generated code for functional correctness and real-world exploitability.
  • Test model behavior across cybersecurity categories like malware, exploitation, and social engineering.

Handshake is a career platform that helps everyone find a path to a great career. They support 25 million job seekers, over 1 million employers, and 1,600 educational institutions.

United States Canada Dominican Republic Unlimited PTO

  • Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
  • Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
  • Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.

Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.

US

  • Lead the design and development of an AI-driven exploit discovery and productization system.
  • Coordinate efforts of engineers and security researchers to ensure quality quarterly deliveries.
  • Collaborate across teams to integrate existing targeting data and tools for mission needs.

Clarity Innovations is a trusted national security partner that empowers the Intelligence Community and Department of Defense with innovative software and data engineering solutions. They are a people-focused company committed to being a destination employer for top talent, offering an environment where innovation thrives.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

Canada Unlimited PTO

  • Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
  • Partner with engineering to embed security controls into production.
  • Lead vulnerability management and incident response activities.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.

Global

  • Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
  • Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
  • Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.

Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.

$139,000–$258,000/yr
US Canada Unlimited PTO

  • Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
  • Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
  • Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.

US Unlimited PTO 12w maternity 12w paternity

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.

Europe 5w PTO 16w maternity 8w paternity

  • Shape AI security at the edge by turning new threats into protections customers can use.
  • Think like an attacker to find new ways AI systems can be exploited and stop them.
  • Build for real time, catching threats without slowing down the applications we protect.

bunny.net is a content delivery network and edge computing company that accelerates the internet. Founded in 2015, the company has 95+ employees and fosters a culture of ownership, improvement, and challenging what's possible.

$180,000–$210,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Threat model new product features and integrations, hardening systems with effective controls.
  • Operate and evolve the application security toolchain, keeping it high-signal for developers.
  • Own day-to-day security operations across the detection stack, triaging and resolving incidents.

Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.

US

  • Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
  • Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
  • Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.

Global Unlimited PTO

  • Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.

Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.

Canada Israel UK United States

  • Lead the Security Posture Management team to secure GitLab's own software factory and drive comprehensive rollouts of security capabilities.
  • Serve as Customer Zero for GitLab security features, capturing adoption friction and feeding insights to Product and Engineering.
  • Establish proactive software supply chain security, including third-party governance, trusted dependency controls, and SBOM requirements.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. With over 50 million registered users and more than 50% of the Fortune 100 trusting them, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.

$120,000–$145,000/yr
US

  • Design, build, and scale application security capabilities to support secure software development across the enterprise.
  • Develop security patterns and guardrails for AI-assisted development and agentic workflows.
  • Integrate security tools with developer platforms to improve vulnerability management and automate remediation.

NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.

$120,000–$150,000/yr
US Unlimited PTO

  • Plan and conduct offensive security engagements, effectively communicating findings to stakeholders.
  • Build scripts, tools, or methodologies to enhance services and stay current with adversary tradecraft.
  • Serve as a subject matter expert and mentor less experienced staff while contributing to training courses.

SpecterOps provides offensive security assessment services, including red team assessments and penetration tests, for large commercial enterprises. The company fosters a culture of passionate curiosity and continuous improvement, with a remote team that values empathy and transparency.

US 4w PTO 12w maternity 4w paternity

  • Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
  • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.

Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.

$165,000–$200,000/yr
US Unlimited PTO

  • Lead the long-term technical strategy for offensive security, including red teaming and adversary simulations.
  • Conduct deep-dive vulnerability research and partner with DevOps to build automated security guardrails.
  • Mentor senior and mid-level engineers to foster a security-minded development culture.

Greenlight is a family technology company that helps families raise financially smart kids through its suite of products including the Greenlight app, debit card, and safety features. With over 6.5 million family members, Greenlight fosters a culture of innovation and collaboration to make family life easier.

US

  • Conduct vulnerability research to identify net-new vulnerabilities across operating systems, platforms, and devices.
  • Reverse engineer firmware and software to author original exploits and detection artifacts.
  • Apply agentic approaches to scale vulnerability discovery and exploit development.

VulnCheck delivers structured exploit intelligence on what is actively weaponized in the wild. Founded in 2021, it has a transparent, collaborative culture with a team of smart, humble, and supportive experts.

Canada

  • Add security tooling and checks to CI/CD pipelines with Python automation.
  • Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
  • Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.

Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.

Switzerland

  • Investigate emerging vulnerabilities across the Ubuntu ecosystem, helping identify, assess, remediate, and document security issues.
  • Collaborate with internal engineering teams, upstream developers, and the broader open source community to deliver robust security fixes.
  • Contribute to security initiatives across the broader open source ecosystem and engage with industry communities.

They are a globally distributed security engineering team dedicated to protecting users and strengthening the security of open source software. The environment is highly technical, collaborative, and international, with opportunities to share knowledge through open source contributions and industry events.