Overview
Build agent-scale systems for triaging, validating, and acting on externally reported security vulnerabilities, with an emphasis on root-cause analysis and automated remediation.
What you'll do
- Design and operate systems that ingest externally reported vulnerabilities and assess validity, severity, and reproducibility at scale.
- Build LLM/agent-based reasoning to validate security findings beyond signature matching.
- Connect validated findings to root cause so fixes address the underlying class, not just the report.
- Develop automation that can propose and increasingly open remediation for well-understood vulnerability classes with human review gates.
- Re-think traditional product security processes (e.g., manual threat modeling, ad hoc code review, point-in-time pentests) and replace or augment them with agent-driven tooling.
- Manage the bug bounty program’s researcher-facing side (scope, policy, engagement) plus internal tooling to improve resolution and triage learning.
- Extend tooling into customer-facing security testing capabilities for what customers build and deploy on the platform.
What you'll need
- Strong software engineering background.
- Ability to assess externally reported findings, reproduce them, and judge severity.
- Experience or strong interest in agentic and LLM-based security tooling.
- Root-cause and systems thinking focused on scaling to large report volumes.
- Comfort defining a new practice for agent-scale product security.
- Strong familiarity with JavaScript/TypeScript and Node.js runtime security.
- Familiarity with modern web frameworks, ideally including Next.js or React with Node-based frameworks.
Details
- In-office anchor days on Monday, Tuesday, and Friday for candidates within commuting distance of SF, NY, London, or Berlin.
- Fully remote if located beyond the commuting distance.
Read the full description and apply on the company’s own careers page.