Application Security Researcher

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Application Security Researcher researching vulnerabilities and autonomous penetration testing for OX Security’s AI-driven security platform. Building detection engines and shipping offensive-security capabilities to production.

Responsibilities:

  • Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure
  • Design and build detection engines and decision-making logic for autonomous security systems
  • Evaluate AI models for application security use cases, measuring where they perform and where they fall short
  • Prototype, build, and ship security capabilities into production environments
  • Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy
  • Partner with Product, Engineering, and Data teams to shape the next generation of security features
  • Help set the team's research direction and own initiatives end to end, from idea to shipped capability

Requirements:

  • M.Sc. in Computer Science, Cyber Security, or a related field
  • 5+ years of hands-on experience in offensive security, vulnerability research, or application security
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
  • Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
  • Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
  • Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail
  • Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
  • Ability to take a research idea from prototype to production with minimal guidance
  • Clear written communication: you can explain a complex attack path to engineers and product managers