Job Openings Remote | Member of Technical Staff, Vulnerability Researcher — $240,000–$400,000/year

About the job Remote | Member of Technical Staff, Vulnerability Researcher — $240,000–$400,000/year

We are sharing a full-time opportunity for an experienced Vulnerability Researcher with deep expertise in offensive security, red teaming, multi-cloud exploitation, application security, reverse engineering, exploit development, and emerging AI/LLM security.

The role focuses on advanced security research across cloud infrastructure, production services, developer platforms, AI systems, identity architectures, and software supply chains. The successful candidate will identify novel attack paths, build proof-of-concept tooling, validate remediation efforts, and work closely with engineering teams to strengthen secure-by-design practices.

Key Responsibilities

Offensive Security & Vulnerability Research

  • Conduct advanced research across cloud infrastructure, production services, internal tooling, applications, APIs, and AI platforms
  • Identify architectural weaknesses, vulnerability classes, privilege-escalation paths, and lateral-movement risks
  • Perform code auditing, reverse engineering, exploit research, and proof-of-concept development
  • Design realistic adversary simulations and advanced red-team scenarios
  • Document findings clearly for engineering and security stakeholders

Cloud, Application & Supply Chain Security

  • Assess AWS and GCP environments, including IAM, networking, Kubernetes, containers, and cloud control planes
  • Evaluate authentication, authorisation, APIs, proprietary applications, and service interactions
  • Review CI/CD systems, infrastructure-as-code, developer workflows, and software supply-chain risks
  • Analyse insider-threat and distributed-system attack scenarios
  • Validate security controls across complex production environments

AI/LLM Security & Offensive Tooling

  • Research security risks affecting LLMs, AI agents, RAG systems, and tool-enabled workflows
  • Evaluate prompt injection, indirect attacks, tool abuse, and autonomous or orchestrated AI systems
  • Build custom security tooling, automation, fuzzing utilities, or analysis frameworks
  • Develop reproducible proof-of-concept implementations for validated vulnerabilities
  • Investigate emerging attack surfaces and novel vulnerability classes

Remediation & Security Engineering

  • Collaborate with infrastructure, product, AI, and security engineering teams on remediation
  • Verify that fixes address underlying attack paths and identify residual risk
  • Support secure-by-design architecture and development practices
  • Produce technical vulnerability reports and document attack methodologies
  • Contribute research insights to long-term security strategy

Ideal Profile

  • Proven experience in offensive security, vulnerability research, red teaming, or exploit development
  • Deep understanding of AWS and GCP security
  • Strong knowledge of IAM, cloud networking, Kubernetes, containers, APIs, and identity systems
  • Strong application-security, code-auditing, and reverse-engineering experience
  • Familiarity with CI/CD and software supply-chain security
  • Proficiency in Python, Go, Rust, C/C++, or comparable security-research languages
  • Strong knowledge of operating-system internals, networking, and authentication protocols
  • Ability to investigate ambiguous technical problems independently and develop novel research approaches
  • Excellent written technical communication skills
  • Experience with AI/LLM security, agentic systems, prompt injection, tool abuse, or RAG security is highly valuable
  • Zero-day discovery, exploit development, published CVEs, security research, bug-bounty work, or open-source tooling is advantageous
  • Experience with fuzzing, symbolic execution, binary analysis, macOS internals, endpoint security, virtualisation, or hardware-backed security is beneficial

Engagement Details

  • Full-time engagement
  • Fully remote
  • Compensation: $240,000–$400,000/year
  • Work will involve vulnerability research, red teaming, cloud security, application security, reverse engineering, exploit research, AI/LLM security, and remediation validation
  • Responsibilities may span AWS, GCP, Kubernetes, containers, CI/CD systems, APIs, identity architectures, AI agents, retrieval systems, and developer platforms
  • Regular collaboration with infrastructure, product, AI, and security engineering teams is expected
  • Research priorities and attack surfaces may evolve as systems and emerging threats develop
  • All security research must be conducted only within authorised environments and scopes, and without using confidential or proprietary information belonging to any unauthorised third party

About the Platform

This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy