Vulnerability researcher, web and APIs_
Remote or New York · full-time
Find bugs in open-source web applications and APIs, disclose them, and turn the patterns into workflows.
What you'll do
Find vulnerabilities in widely used open-source web applications and APIs, disclose them responsibly, and turn each pattern into a workflow the registry can run on anyone's code: authorisation gaps, injection, deserialisation, session handling, business-logic flaws. Own CyberGym and the web benchmarks on the bench.
What we look for
CVEs or disclosures under your name. Depth in authentication and authorisation, and range across several languages and frameworks. You can read an unfamiliar codebase and find the entry points before lunch.
What we offer
Research as the job, not the side of it. Publication by default, the models and budget to run at max, and a registry that carries your work to every user.