Senior Application Security Researcher
TypeFull-time job
LocationCanada
Posted3 hours ago
Description
The company secures the AI-driven SDLC from prompt to production, unifying development and cloud context to stop vulnerabilities at the source. The Security Research group is hiring a senior, hands-on Application Security Researcher to push modern AppSec forward — working with engineers, researchers and AI/data scientists on next-generation detection, including autonomous, agentic pen-testing capabilities. This is a build-and-break role, not a typical AppSec position.
Requirements
Must-have skills:
5+ years hands-on in offensive security, vulnerability research, or application security
Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
Strong coding in Python, Go, or similar, with production-quality code shipped
Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
Hands-on use of LLMs / AI models for security tasks, with the judgment to measure where they help and where they fail
Comfort with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
Takes research ideas from prototype to production with minimal guidance
Clear written communication — can explain a complex attack path to engineers and product managers
. in Computer Science, Cyber Security, or a related field
Nice to have:
Published research, CVEs, conference talks, or a bug bounty track record
Experience building AI agents or evaluation frameworks for LLMs
Background in exploit development, red teaming, or penetration testing
Code analysis techniques (taint analysis, call graphs, reachability)
Contributions to open-source security tools
Originally posted on Himalayas
The company secures the AI-driven SDLC from prompt to production, unifying development and cloud context to stop vulnerabilities at the source. The Security Research group is hiring a senior, hands-on Application Security Researcher to push modern AppSec forward — working with engineers, researchers and AI/data scientists on next-generation detection, including autonomous, agentic pen-testing capabilities. This is a build-and-break role, not a typical AppSec position.
Requirements
Must-have skills:
5+ years hands-on in offensive security, vulnerability research, or application security
Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
Strong coding in Python, Go, or similar, with production-quality code shipped
Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
Hands-on use of LLMs / AI models for security tasks, with the judgment to measure where they help and where they fail
Comfort with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
Takes research ideas from prototype to production with minimal guidance
Clear written communication — can explain a complex attack path to engineers and product managers
. in Computer Science, Cyber Security, or a related field
Nice to have:
Published research, CVEs, conference talks, or a bug bounty track record
Experience building AI agents or evaluation frameworks for LLMs
Background in exploit development, red teaming, or penetration testing
Code analysis techniques (taint analysis, call graphs, reachability)
Contributions to open-source security tools
Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.