Principal Security Researcher
jobgether · US
About The Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Researcher based in the United States.
This is a senior, high-impact security research role focused on protecting a leading AI-powered DevSecOps platform and its <users.You> will conduct cutting-edge offensive security research across complex applications, codebases, AI systems, and agentic workflows.The role combines hands-on vulnerability discovery, penetration testing, exploit validation, automation, and strategic security <leadership.You> will help identify systemic and chained vulnerabilities and turn emerging threats into scalable remediation strategies.A major focus will be securing AI and agentic capabilities, including prompt injection, agent manipulation, and workflow <exploitation.You> will collaborate with engineering, product, and security teams while mentoring other researchers and influencing technical roadmaps.This fully remote opportunity is ideal for an experienced security expert who thrives on complex problems, ambiguity, and innovative attack research.
Accountabilities
- Lead sophisticated security research projects across multiple functional and technical areas, identifying novel, systemic, and chained vulnerabilities.
- Conduct hands-on penetration testing and develop proof-of-concept exploits to validate vulnerabilities and demonstrate realistic attack scenarios.
- Research emerging vulnerability classes and assess their applicability across complex codebases, driving remediation of systemic issues rather than isolated instances.
- Lead security research focused on AI and agentic systems, including identifying attack vectors and defining security requirements for engineering teams.
- Develop and guide security tooling, automation, and agent-assisted approaches that scale vulnerability discovery across large codebases.
- Assess the security posture of open-source tools and dependencies, communicate findings responsibly to maintainers, and track mitigation efforts.
- Translate complex technical findings into actionable risk assessments, remediation recommendations, and improvements for engineering and business stakeholders.
- Integrate research outcomes into engineering, product, and business functions to ensure identified risks are addressed effectively.
- Help shape security team and sub-department roadmaps by bringing forward emerging threats, research findings, and innovative security approaches.
- Solve highly complex technical problems involving significant scope, ambiguity, and cross-functional dependencies.
- Mentor, teach, and advise security professionals, engineers, and other technical experts across multiple teams.
- Share novel vulnerability research, methodologies, and security insights with the broader security community.
- Contribute to maintaining development velocity while strengthening systemic product security across the platform.
Requirements
- 10+ years of experience in security research, penetration testing, offensive security, or a closely related discipline.
- Demonstrated expertise discovering and exploiting vulnerabilities in large-scale codebases and complex software systems.
- Strong programming proficiency in at least two of the following: Ruby, Go, Python, TypeScript, or Rust.
- Ability to read, understand, and analyze code across multiple programming languages and diverse codebases.
- Strong understanding of AI frameworks and modern AI security concepts.
- Deep knowledge of AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation.
- Experience leading complex remediation initiatives involving multiple technical and business stakeholders.
- Strong analytical and problem-solving capabilities, with the creativity to develop unconventional attack scenarios and identify non-obvious security weaknesses.
- Excellent written and verbal communication skills, including the ability to explain highly technical concepts clearly and concisely.
- Ability to translate technical research into meaningful business risk assessments and practical remediation strategies.
- Strong cross-functional collaboration skills and the ability to influence engineering and technical decision-making.
- Experience with published security research or conference presentations is a plus.
- Software engineering experience, particularly with distributed systems, is advantageous.
- Experience with a major DevSecOps platform or comparable enterprise software environment is preferred.
Benefits
- Base salary: $203,200–$275,000 USD for U.S.-based residents, depending on factors such as experience, skills, education, geographic location, and market considerations.
- Equity compensation and employee stock purchase plan.
- Flexible paid time off.
- Parental leave.
- Growth and development fund to support ongoing professional development.
- Team Member Resource Groups and an inclusive, collaborative culture.
- Fully remote work environment, subject to location-based eligibility requirements.
- Opportunity to work on cutting-edge AI, application security, and DevSecOps challenges.
- Significant opportunities to influence security strategy, engineering practices, and technology direction.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
