Staff Security Researcher

RekrytointipalveluJobgetherBrussels (Firmensitz, recherchiert)Job.bojulkaistu 09.09.2026
Pakollinen:TypeScriptPythonRustRubyAISecurityRemote

Accountabilities: Security Research: Conduct advanced security research across at least two technical specialty areas, identifying novel, systemic, and chained vulnerabilities where multiple weaknesses can combine to create significant security impact.

Vulnerability Validation & Exploitation: Perform hands-on testing and develop proof-of-concept exploits that demonstrate realistic attack scenarios, validating the severity and practical impact of identified vulnerabilities.

AI & Agent Security: Research the security of AI-powered and agentic capabilities, investigate emerging attack vectors such as prompt injection and agent manipulation, and contribute to defining security requirements for AI-enabled systems.

Vulnerability Class Research: Assess emerging industry vulnerability classes against complex codebases and drive remediation at the systemic level rather than addressing individual vulnerabilities in isolation.

Security Tooling & Automation: Build tools, automation, and agent-assisted workflows that scale security research and improve the efficiency of vulnerability discovery and analysis.

Open Source Security: Research the security posture of open-source tools and dependencies integrated into the platform, communicate findings responsibly to maintainers, and track remediation in accordance with responsible disclosure practices.

Cross-Functional Security Leadership: Partner with engineering and security teams to communicate findings, provide constructive technical feedback, define security improvements, and influence remediation priorities.

Technical Strategy & Mentorship: Contribute to the security team roadmap, solve high-scope and ambiguous technical problems, mentor other individual contributors, and advise teams beyond the immediate security function when appropriate.

Knowledge Sharing: Share novel vulnerability classes, research findings, attack techniques, and security insights with internal teams and the broader security community through documentation, presentations, or other knowledge-sharing activities.

Requirements

Professional Experience: 7+ years of experience in security research, penetration testing, offensive security, application security, or a closely related discipline.

Offensive Security Expertise: Demonstrated hands-on experience discovering, validating, and exploiting vulnerabilities, with the ability to develop realistic proof-of-concept attacks.

Technical Specialization: Subject matter expertise in at least two technical areas that directly impact product security, with the ability to investigate complex vulnerabilities across multiple domains.

Programming Skills: Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust. Experience with AI frameworks is an advantage.

Code Analysis: Strong ability to read, understand, and analyze code across multiple programming languages and complex codebases.

AI Security Knowledge: Practical understanding of AI attack vectors, including prompt injection, agent manipulation, workflow exploitation, and other emerging threats affecting AI-powered applications and agentic systems.

Technical Leadership: Experience leading technical objectives and security initiatives across cross-functional teams, influencing engineering decisions without relying solely on direct authority.

Communication: Excellent written and verbal communication skills, with the ability to explain complex security research clearly to both technical and non-technical stakeholders.

Risk & Remediation: Ability to translate technical findings into clear risk assessments, business-relevant impact statements, and practical remediation recommendations.

Analytical Thinking: Strong problem-solving skills and creative thinking, particularly when developing novel attack scenarios and investigating systemic security weaknesses.

Preferred Experience: Published security research or conference presentations, software engineering experience with distributed systems, security certifications such as OSCP, OSCE, GPEN, or similar, and experience securing DevSecOps platforms are all valuable additions.

Benefits

Compensation: U.S. base salary range of $168,000–$238,000 USD , with the final level and compensation determined based on experience, skills, education, geographic location, and internal and market considerations.

Equity: Equity compensation and an employee stock purchase plan.

Health & Well-Being: Benefits designed to support physical health, financial security, and overall well-being.

Flexible Time Off: Flexible paid time off to support work-life balance.

Parental Leave: Paid parental leave for eligible employees.

Professional Development: Dedicated growth and development resources to support continuous learning and career progression.

Inclusive Community: Team member resource groups and an emphasis on creating an inclusive and equitable workplace.

Remote Work: Remote-first employment model, with location eligibility determined by applicable hiring guidelines.

Technical Impact: Opportunity to work on complex application security, AI security, DevSecOps, offensive research, and emerging vulnerability challenges at significant scale.

Career Growth: Exposure to advanced security research, cross-functional technical leadership, mentorship, and opportunities to influence security strategy and engineering practices.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1