Zealot — Vulnerability Researcher

DavidJoseph&Co
  • New York, New York
    22 days ago

    Job Description

    Zealot — Vulnerability Researcher

    Type: Full-time | On-site | New York City, NY Compensation: $220,000–$350,000 + Competitive Equity Hiring count: 2 Visa sponsorship: None Available. US citizen or clearance-eligible preferred; foreign nationals from countries Zealot Labs does not sell to cannot be considered. Reports to: R&D team, led by Ilya (~8 engineers). Intro call with Oliver.

    About Zealot Labs

    Zealot Labs builds AI systems that autonomously perform vulnerability research against real targets, collapsing a manual process that once took roughly six months into a matter of days using coordinated agents. It sells exclusively to governments — paying clients include the CIA and the German federal law enforcement agency — and is backed by tier-1 US venture firms. The team is approaching 20 people and scaling toward 30, with alumni from Anthropic, xAI, NSA, USCYBERCOM, and Anduril.

    Founded: 2025 | Team size: ~11–50 (approaching 20) | Total funding: Not disclosed (tier-1 US VC-backed) Industry: Security / Offensive Cyber Website: zealotlabs.com Office: New York City, NY

    Why Candidates Should Join

    • Frontier mission: Build AI agents that autonomously run offensive vulnerability research against real firmware, network stacks, mobile OSes, and IoT — compressing six months of manual work into days.
    • Elite team: Alumni from Anthropic, xAI, NSA, USCYBERCOM, and Anduril; R&D led by Ilya.
    • Real customers, real stakes: Government clients, tier-1 US VC backing, seed stage with meaningful equity upside.
    • Deeply technical, low-level work at the intersection of offensive security and AI agent infrastructure — not a side capacity.

    Intake Call Summary

    • An intake video is present on the Contrario role page but was not transcribed — no text intake summary is available. If you share a transcript or notes, I'll fold the key points in here.

    The Role

    Zealot Labs is hiring multiple Vulnerability Researchers to help design and build agentic systems that autonomously hack into real targets across firmware, network stacks, mobile operating systems, and IoT. Deeply technical, low-level work wiring emulation, instrumentation, fuzzing, and exploit primitives into tool interfaces that agents can operate. Vulnerability research must be the central, primary function of the day-to-day — not a secondary responsibility.

    What You'll Be Doing

    • Own vulnerability discovery end-to-end against real firmware, network stacks, mobile OSes, and IoT targets using emulation stacks, instrumentation, and fuzzing pipelines.
    • Wire emulation environments (QEMU, Unicorn, Qiling) and instrumentation tooling (Frida, DynamoRIO) into agent-accessible tool interfaces.
    • Design and build evaluation and benchmarking infrastructure that measures whether the agentic vulnerability research pipeline is working.
    • Develop and weaponize exploits from discovered vulnerabilities, turning raw findings into working exploit primitives.
    • Contribute to agent harness orchestration, tool-use design, and eval loops that power autonomous vulnerability research at scale.
    • Collaborate directly with the R&D team to push the boundary of what agents can autonomously discover and exploit across target device classes.

    Tech stack: C / C++ / Rust; GDB, IDA, Ghidra; QEMU, Unicorn, Qiling, PANDA, FirmAE; Frida, DynamoRIO; Linux (kernel internals, system-level debugging); fuzzing pipelines; modern mitigations (ASLR, CFI, PAC, MTE); agent harnesses / orchestration / eval loops.

    Requirements

    • Vulnerability research as primary current role function
    • Strong RE and debugger chops (GDB, IDA, or Ghidra)
    • 2 to 3 or more years C, C++, or Rust systems programming
    • Deep Linux systems fluency
    • NYC in-person 5 days, relocation required
    • US citizen or clearance-eligible preferred

    Green Flags

    • Exploit weaponization experience
    • Offensive security firm background (NSO, Paragon, or equivalent)
    • Competitive CTF background or public CVEs
    • AI enthusiast with genuine technical interest in agents
    • Startup-suitable culture fit

    Red Flags

    • Vulnerability research is a minority function in current role
    • Corporate or enterprise-only background without startup fit
    • Not willing or able to work in-person in New York five days per week
    • Foreign national from a country Zealot Labs does not sell to

    Role Details

    • Salary — $220,000–$350,000
    • Equity — Competitive Equity
    • On-site policy — In-person New York City, 5 days per week; no remote option; relocation required
    • Visa sponsorship — None Available; US citizen or clearance-eligible preferred
    • Employment type — Full-time
    • Location — New York City, NY

    Screening Questions

    1. Have you done any exploit weaponization? (Contrario "Required Candidate Q&A" — a required field on the submission form, not just a call question.)

    Interview Process

    Stage 1 — Pending Approval — Candidates awaiting initial approval. Stage 2 — Introductory call with Oliver.Stage 3 — Technical interview with a member of the R&D team (15 to 30 minutes).Stage 4 — In-person interview in New York — On-site meeting with the team; happens as soon as scheduling allows, with a team member in New York approximately every two weeks. Stage 5 — Offer Extended.Stage 6 — Candidate Hired — Candidate accepts and starts.

    Ideal Companies & Backgrounds

    Updated Jul 20, 2026 No dedicated "Ideal Companies" section was present on the role page. The only company signals are in the Green Flags: offensive security firms — NSO, Paragon, or equivalent US/allied-ecosystem organizations.

    Ideal Candidate Profiles

    For reference only — do not source these specific profiles (Contrario "DO NOT CONTACT").Stratos Tiganourias — LinkedIn URL not captured in the pasted HTML (only a LinkedIn button was present). Aviv Yahav — LinkedIn URL not captured in the pasted HTML (only a LinkedIn button was present).

    Numbers & Facts

    LocationNew York, New York

    Skills

    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Agentsunmatched
    • Benchmarkingunmatched
    • C Programming Languageunmatched
    • C++ Programming Languageunmatched
    • Computer Firmwareunmatched
    • Computer Securityunmatched
    • Debugging Toolsunmatched
    • Ecosystemsunmatched
    • Electrical Wiringunmatched
    • Federal Governmentunmatched
    • Federal Laws and Regulationsunmatched
    • Fundingunmatched
    • Fuzz Testingunmatched
    • GDB (Gnu Debugger)unmatched
    • Governmentunmatched
    • Instrumentationunmatched
    • Internet Securityunmatched
    • Internet of Thingsunmatched
    • Law Enforcementunmatched
    • Linux Operating Systemunmatched
    • Machine Toolunmatched
    • Mobile Operating Systemunmatched
    • National Security Agency (NSA)unmatched
    • Research & Development (R&D)unmatched
    • Research Skillsunmatched
    • Rust Programming Languageunmatched
    • Salesunmatched
    • Startupunmatched
    • Systems/Internals Programmingunmatched
    • Unicorn Library Management Systemunmatched
    • United States Citizenunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder