About the role
from job page← All open positionsSecurity ResearcherHunt for real-world vulnerabilities in open-source and customer codebases, validate AI-generated findings, and shape the detection engine that powers ZeroPath.DepartmentSecurityLocationRemote (US)TypeFull-timeCompensation$140k - $180k + EquityAbout the RoleZeroPath has already disclosed vulnerabilities in curl (150+ bugs fixed), FFmpeg, django-allauth, OpenSSL, and Avahi. You will expand that list. This role sits at the intersection of manual security research and AI-augmented discovery. You will audit codebases, validate and triage findings from our LLM-powered scanner, and feed your expertise back into the detection engine. Your work directly improves what the AI catches next time.What You'll DoConduct security research on open-source projects and customer codebases across multiple languagesValidate and triage AI-generated vulnerability findings to calibrate false positive ratesWrite detailed vulnerability reports and coordinate responsible disclosure and CVE assignmentDefine and refine detection rules, heuristics, and prompt strategies for the scanning engineCollaborate with the engineering team to improve detection of business logic and auth flawsContribute to ZeroPath's public research blog and Wall of FameWhat We're Looking For3+ years of experience in application security research, penetration testing, or red teamingDemonstrated ability to find and responsibly disclose vulnerabilities (CVEs, bug bounties, or published research)Strong understanding of common vulnerability classes: OWASP Top 10, business logic flaws, auth bypasses, injection chainsProficiency in reading and analyzing code across Python, JavaScript/TypeScript, Go, Java, or C/C++Experience with static analysis concepts, code review, and source code auditingExcellent written communication for vulnerability reports and research write-upsNice to HavePublished CVEs or a meaningful bug bounty track recordExperience with tree-sitter, semgrep, CodeQL, or similar code analysis tooling for benchmarkingFamiliarity with LLM-powered security tools or AI-augmented research workflowsContributions to open-source security projectsInterested?Send us your resume and tell us why you're excited about this role. We read every application.Apply for This Role
