Vulnerability researcher, web and APIs_
Remote or New York · full-time
What you'll do
Find vulnerabilities in widely used open-source web applications and APIs, disclose them responsibly, and turn each pattern into a workflow the registry can run on anyone's code: authorisation gaps, injection, deserialisation, session handling, business-logic flaws. Curate CyberGym and the web benchmarks as the bench is stood up.
What we look for
CVEs or disclosures under your name. Depth in authentication and authorisation, and range across several languages and frameworks. You can read an unfamiliar codebase and find the entry points before lunch.
What we offer
Research as the job, not the side of it. Publication by default, the models and budget to run at max, and a registry built to carry your work to everyone who runs it.