Principal Vulnerability Engineer (0-Day Research & Offensive Security Tooling) (Remote)
About the Rol
eWe are looking for an exceptional Principal Vulnerability Engineer to join our Offensive Security Research team. This is a unique opportunity for a highly technical security professional who combines elite vulnerability research capabilities with production-grade software engineering expertise
.You will conduct original 0-day and n-day vulnerability research while building scalable, AI-powered tooling that automates vulnerability discovery, exploit validation, patch analysis, and detection engineering. Working at the intersection of offensive security, reverse engineering, software engineering, and applied AI, you will help organizations identify and eliminate critical vulnerabilities before they can be weaponized by adversaries
.This role is ideal for a Senior Vulnerability Researcher, Principal Security Engineer, Exploit Developer, Offensive Security Researcher, Red Team Researcher, Security Software Engineer, or Reverse Engineer looking to work on high-impact security challenges at scale
.What You’ll D
oVulnerability Researc
- hConduct original 0-day and n-day vulnerability research across enterprise technologies, cloud services, applications, appliances, firmware, and operating systems
- .Perform patch diffing, root-cause analysis, reverse engineering, and exploit development against both source-available and binary-only targets
- .Discover and validate critical vulnerabilities including remote code execution (RCE), authentication bypass, privilege escalation, sandbox escapes, and full system compromise scenarios
- .Develop proof-of-concept exploits and technical advisories to support vulnerability validation and risk assessment
.Offensive Security Engineerin
- gDesign, build, and maintain production-grade tooling for automated vulnerability discovery, exploit validation, attack surface analysis, and detection signature generation
- .Develop scalable offensive security systems capable of operating across large attack surfaces and processing vast amounts of security data
- .Build automation that transforms manual research workflows into repeatable, scalable security capabilities
- .Drive engineering excellence through clean, maintainable, and production-quality code
.AI & LLM Innovatio
- nDesign and implement AI-assisted and LLM-powered workflows to accelerate vulnerability research and exploit development
- .Integrate large language models into offensive security pipelines to improve triage, analysis, automation, and research productivity
- .Explore emerging applications of AI in vulnerability discovery, reverse engineering, code analysis, and security automation
- .Measure and optimize the real-world impact of AI-driven security tooling
.Research Leadershi
- pLead advanced research initiatives focused on emerging threats, attack techniques, and novel vulnerability classes
- .Collaborate with engineers, researchers, and product teams to operationalize research outcomes
- .Establish technical standards and best practices across offensive security engineering and vulnerability research
- .Mentor team members on exploit development, reverse engineering, vulnerability analysis, and tooling development
.Community Engagemen
- tPublish original research, technical blogs, whitepapers, and vulnerability disclosures
- .Present research findings at industry-leading security conferences and events
- .Represent the organization within the global offensive security and vulnerability research community
- .Contribute to the advancement of security research through responsible disclosure and knowledge sharing
.What We’re Looking Fo
rVulnerability Research Expertis
- e5+ years of hands-on experience in vulnerability research, exploit development, offensive security, or security research
- .Demonstrated history of discovering, validating, or analyzing high-impact vulnerabilities
- .Experience with CVEs, coordinated vulnerability disclosure, security advisories, or published research
- .Deep understanding of modern attack techniques, exploit chains, and adversary methodologies
.0-Day & N-Day Researc
- hStrong experience performing patch diffing and root-cause analysis
- .Ability to reverse engineer software updates and identify security fixes before public disclosure details emerge
- .Experience building proof-of-concept exploits for vulnerability validation
- .Knowledge of vulnerability lifecycle management and exploitation techniques
.Web & Binary Securit
- yExpertise across both web application and binary exploitation domains
- .Strong understanding of authentication, authorization, deserialization, injection, memory corruption, logic flaws, and privilege escalation vulnerabilities
- .Hands-on experience with
- :Burp Suit
- eGhidr
- aIDA Pr
- oBinary Ninj
- aWinDb
- gGD
- BFrid
- aAFL+
- +libFuzze
- rFuzzing frameworks and debugging tool
sSoftware Engineerin
- gExpert-level Python development experience
- .Strong software engineering background with experience building production systems used by customers or internal stakeholders
- .Experience designing scalable architectures, APIs, automation platforms, and security tooling
- .Knowledge of modern software development practices, testing, CI/CD, and cloud-native environments
.AI & Automatio
- nPractical experience leveraging LLMs, AI agents, or machine learning systems within security workflows
- .Ability to evaluate, implement, and operationalize AI technologies that deliver measurable research acceleration
- .Experience building AI-assisted tooling for code analysis, vulnerability research, reverse engineering, or security operations is highly desirable
.Startup & Scale-Up Mindse
- tComfortable operating in a fast-paced, high-growth environment
- .Demonstrated ownership mentality and bias toward execution
- .Ability to navigate ambiguity, solve difficult technical problems, and deliver outcomes with minimal supervision
- .Passion for innovation, experimentation, and continuous learning
.Technologi
esVulnerability Research, 0-Day Research, N-Day Analysis, Patch Diffing, Exploit Development, Reverse Engineering, Offensive Security, Red Teaming, Security Research, Binary Exploitation, Web Application Security, Remote Code Execution (RCE), Memory Corruption, Authentication Bypass, Privilege Escalation, CVE Research, Vulnerability Discovery, Python, Ghidra, IDA Pro, Burp Suite, WinDbg, GDB, Frida, AFL++, Fuzzing, Detection Engineering, Security Automation, AI Security, LLMs, Security Tooling, Threat Research, Binary Analysis, Firmware Security, Cloud Security, Attack Surface Managemen
t.Why Join
- Us?Conduct cutting-edge 0-day and n-day vulnerability resear
- ch.Build AI-powered offensive security tooling used at sca
- le.Focus on impactful vulnerabilities and real-world exploitation scenari
- os.Present original research at leading global cybersecurity conferenc
- es.Work alongside world-class security researchers, engineers, and offensive security specialis
- ts.Influence the future of offensive security through innovation, automation, and advanced resear
ch….
