About this role
Role Overview
This role evaluates advanced AI systems for security reasoning and vulnerability analysis, focusing on exploit development, root-cause analysis, and secure software engineering. It is designed for experienced offensive security researchers with a track record of public technical contributions and demonstrated expertise in pragmatic vulnerability discovery and exploit assessment.
Key Responsibilities- Assess AI-generated analyses of complex cybersecurity scenarios, exploit writeups, and vulnerability reports for technical accuracy.
- Review technical writeups for correctness, exploitability, and the quality of mitigations and recommendations.
- Validate root-cause analyses of vulnerabilities across software, operating systems, networking, cloud, and web applications.
- Provide structured, actionable feedback on security reasoning, exploit chains, and defensive guidance.
- Contribute to the design and refinement of benchmarks that measure advanced AI security capabilities.
Candidates should hold multiple of the following credentials:
- Member of a top-ranked Capture The Flag team with demonstrable competitive achievements.
- Discoverer or co-author of Common Vulnerabilities and Exposures, affecting widely used open-source or commercial software.
- Publicly recognized bug bounty researcher with accepted findings from major programs, for example Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, or Linux Foundation programs.
- Research experience at a respected security laboratory or academic research group, such as university security research groups or well-known industry labs.
- Author of high-quality security research publications, conference papers, or widely cited technical writeups.
- Deep technical knowledge in one or more of the following: exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
- Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
- Familiarity with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
- Experience with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
- Knowledge of Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
- Strong programming skills in C, C++, Rust, Python, Go, or Java.
- Excellent technical writing skills and the ability to explain complex security concepts clearly.
- Hall of Fame recognition from major bug bounty programs.
- Presentations or publications at conferences such as Black Hat, DEF CON, USENIX Security, IEEE S and P, ACM CCS, or NDSS.
- Maintainer or significant contributor to well-known open-source security tools.
- Offensive Security certifications such as OSCP, OSEP, OSCE3, GIAC certifications, or equivalent credentials.
- Location: Remote.
- Engagement type: hourly.
- Pay rate: 200 to 250 hourly.