$220,000–$350,000 Per Year
Artificial Intelligence (AI), Artificial Intelligence (AI) Agents, Benchmarking, C Programming Language, C++ Programming Language, Computer Firmware, Computer Security, Debugging Tools, Electrical Wiring, Fuzz Testing, GDB (Gnu Debugger), Government, Instrumentation, Internet Security, Internet of Things, Linux Operating System, Machine Tool, Mobile Operating System, Research Skills, Rust Programming Language, Sales, Startup, Systems/Internals Programming, Unicorn Library Management System, United States Citizen
New York City, NY · On-site · Full-time
Compensation: $220,000–$350,000 + competitive equity
About the Company
An early-stage, government-focused offensive-security company building AI systems that autonomously perform vulnerability research against real targets — compressing a process that once took months into days. The company sells exclusively to allied governments and is backed by tier-1 venture firms. The team is scaling rapidly and includes alumni from leading AI labs and national-security organizations.
Founded 2025 · Seed stage, 11–50 people · Industry: Security / Offensive Cyber
The Role
Help design and build agentic systems that autonomously hack into real targets across firmware, network stacks, mobile operating systems, and IoT. This is deeply technical, low-level work at the intersection of offensive security and AI agent infrastructure — wiring emulation, instrumentation, fuzzing, and exploit primitives into tool interfaces that agents can operate. Vulnerability research must be the central, primary function of your day-to-day.
What you'll be doing
- Own vulnerability discovery end-to-end against real firmware, network stacks, mobile OSes, and IoT targets using emulation stacks, instrumentation, and fuzzing pipelines.
- Wire emulation environments (QEMU, Unicorn, Qiling) and instrumentation tooling (Frida, DynamoRIO) into agent-accessible tool interfaces.
- Design and build evaluation and benchmarking infrastructure that measures whether the agentic vulnerability research pipeline is working.
- Develop and weaponize exploits from discovered vulnerabilities, turning raw findings into working exploit primitives.
- Contribute to agent harness orchestration, tool-use design, and eval loops that power autonomous vulnerability research at scale.
Tech stack: C / C++ / Rust; GDB, IDA, Ghidra; QEMU, Unicorn, Qiling, PANDA, FirmAE; Frida, DynamoRIO; Linux (kernel internals, system-level debugging); fuzzing pipelines; modern mitigations (ASLR, CFI, PAC, MTE); agent harnesses / orchestration / eval loops.
Requirements
- Vulnerability research as primary current role function
- Strong RE and debugger chops (GDB, IDA, or Ghidra)
- 2 to 3 or more years C, C++, or Rust systems programming
- Deep Linux systems fluency
- NYC in-person 5 days, relocation required
- US citizen or clearance-eligible preferred
Green Flags
- Exploit weaponization experience
- Offensive security firm background (NSO, Paragon, or equivalent)
- Competitive CTF background or public CVEs
- AI enthusiast with genuine technical interest in agents
- Startup-suitable culture fit
Red Flags
- Vulnerability research is a minority function in current role
- Corporate or enterprise-only background without startup fit
- Not willing or able to work in-person in New York five days per week
- Foreign national from a country the company does not sell to
Why Join
- Frontier mission: build AI agents that autonomously run offensive vulnerability research against real targets.
- Deeply technical, low-level work at the intersection of offensive security and AI agent infrastructure.
- Seed stage with tier-1 venture backing, real government customers, and meaningful equity upside.
Details
- Location — New York City, NY
- Work policy — In-person 5 days per week; no remote option; relocation required
- Compensation — $220,000–$350,000 + competitive equity
- Visa sponsorship — None available; US citizen or clearance-eligible preferred
- Employment type — Full-time