Remote | Member of Technical Staff, Vulnerability Researcher — $240,000–$400,000/year

24-Mag
  • New York
  • Remote
    13 days ago

    Job Description

    We are sharing a full-time opportunity for an experienced Vulnerability Researcher with deep expertise in offensive security, red teaming, multi-cloud exploitation, application security, reverse engineering, exploit development, and emerging AI/LLM security.

    The role focuses on advanced security research across cloud infrastructure, production services, developer platforms, AI systems, identity architectures, and software supply chains. The successful candidate will identify novel attack paths, build proof-of-concept tooling, validate remediation efforts, and work closely with engineering teams to strengthen secure-by-design practices.

    Key Responsibilities

    Offensive Security & Vulnerability Research

    • Conduct advanced research across cloud infrastructure, production services, internal tooling, applications, APIs, and AI platforms
    • Identify architectural weaknesses, vulnerability classes, privilege-escalation paths, and lateral-movement risks
    • Perform code auditing, reverse engineering, exploit research, and proof-of-concept development
    • Design realistic adversary simulations and advanced red-team scenarios
    • Document findings clearly for engineering and security stakeholders

    Cloud, Application & Supply Chain Security

    • Assess AWS and GCP environments, including IAM, networking, Kubernetes, containers, and cloud control planes
    • Evaluate authentication, authorisation, APIs, proprietary applications, and service interactions
    • Review CI/CD systems, infrastructure-as-code, developer workflows, and software supply-chain risks
    • Analyse insider-threat and distributed-system attack scenarios
    • Validate security controls across complex production environments

    AI/LLM Security & Offensive Tooling

    • Research security risks affecting LLMs, AI agents, RAG systems, and tool-enabled workflows
    • Evaluate prompt injection, indirect attacks, tool abuse, and autonomous or orchestrated AI systems
    • Build custom security tooling, automation, fuzzing utilities, or analysis frameworks
    • Develop reproducible proof-of-concept implementations for validated vulnerabilities
    • Investigate emerging attack surfaces and novel vulnerability classes

    Remediation & Security Engineering

    • Collaborate with infrastructure, product, AI, and security engineering teams on remediation
    • Verify that fixes address underlying attack paths and identify residual risk
    • Support secure-by-design architecture and development practices
    • Produce technical vulnerability reports and document attack methodologies
    • Contribute research insights to long-term security strategy

    Ideal Profile

    • Proven experience in offensive security, vulnerability research, red teaming, or exploit development
    • Deep understanding of AWS and GCP security
    • Strong knowledge of IAM, cloud networking, Kubernetes, containers, APIs, and identity systems
    • Strong application-security, code-auditing, and reverse-engineering experience
    • Familiarity with CI/CD and software supply-chain security
    • Proficiency in Python, Go, Rust, C/C++, or comparable security-research languages
    • Strong knowledge of operating-system internals, networking, and authentication protocols
    • Ability to investigate ambiguous technical problems independently and develop novel research approaches
    • Excellent written technical communication skills
    • Experience with AI/LLM security, agentic systems, prompt injection, tool abuse, or RAG security is highly valuable
    • Zero-day discovery, exploit development, published CVEs, security research, bug-bounty work, or open-source tooling is advantageous
    • Experience with fuzzing, symbolic execution, binary analysis, macOS internals, endpoint security, virtualisation, or hardware-backed security is beneficial

    Engagement Details

    • Full-time engagement
    • Fully remote
    • Compensation: $240,000–$400,000/year
    • Work will involve vulnerability research, red teaming, cloud security, application security, reverse engineering, exploit research, AI/LLM security, and remediation validation
    • Responsibilities may span AWS, GCP, Kubernetes, containers, CI/CD systems, APIs, identity architectures, AI agents, retrieval systems, and developer platforms
    • Regular collaboration with infrastructure, product, AI, and security engineering teams is expected
    • Research priorities and attack surfaces may evolve as systems and emerging threats develop
    • All security research must be conducted only within authorised environments and scopes, and without using confidential or proprietary information belonging to any unauthorised third party

    About the Platform

    This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.

    By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy

    Numbers & Facts

    LocationNew York (
    Remote
    )
    Website4-mag.com/privacy-policy

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Architectural Designunmatched
    • Architectural Servicesunmatched
    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Agentsunmatched
    • Auditingunmatched
    • Authenticationunmatched
    • Automationunmatched
    • C Programming Languageunmatched
    • C++ Programming Languageunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Debugging Skillsunmatched
    • Distributed Computingunmatched
    • Endpoint Securityunmatched
    • Fuzz Testingunmatched
    • GCP (Good Clinical Practices)unmatched
    • Go Programming Language (Golang)unmatched
    • Hardware Virtualizationunmatched
    • Infrastructure as a Service (IaaS)unmatched
    • Injectionsunmatched
    • Mac Operating Systemunmatched
    • Machine Toolunmatched
    • Network Protocolsunmatched
    • Open Sourceunmatched
    • Production Controlunmatched
    • Production Systemsunmatched
    • Project Evaluationunmatched
    • Proof of Conceptunmatched
    • Python Programming/Scripting Languageunmatched
    • Research Skillsunmatched
    • Reverse Engineeringunmatched
    • Risk Analysisunmatched
    • Rust Programming Languageunmatched
    • Software Engineeringunmatched
    • System Architectureunmatched
    • Systems/Internals Programmingunmatched
    • Team Playerunmatched
    • Technical Consultingunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder