Vulnerability Researcher

David Joseph & Company

New York, New York

JOB DETAILS
SALARY
$220,000–$350,000 Per Year
SKILLS
Artificial Intelligence (AI), Artificial Intelligence (AI) Agents, C Programming Language, C++ Programming Language, Computer Firmware, Computer Security, Debugging Tools, Electrical Wiring, Fuzz Testing, GDB (Gnu Debugger), Government, Instrumentation, Internet Security, Internet of Things, Linux Operating System, Mobile Operating System, Research Skills, Reverse Engineering, Rust Programming Language, Sales, Startup, Systems/Internals Programming, United States Citizen
LOCATION
New York, New York
POSTED
3 days ago

New York City, NY · On-site · Full-timeCompensation: $220,000–$350,000 + competitive equity

About the Company

Our client builds AI systems that autonomously perform vulnerability research against real targets, collapsing a manual process that once took roughly six months into a matter of days using coordinated agents. It sells exclusively to governments and is backed by tier-1 US venture firms. The team is approaching 20 people and scaling toward 30, with alumni from leading AI labs and national-security organizations.

Founded 2025 · ~11–50 people (Seed) · Industry: Security / Offensive Cyber

The Role

The client is hiring multiple Vulnerability Researchers to help design and build agentic systems that autonomously find vulnerabilities across firmware, network stacks, mobile operating systems, and IoT. It's deeply technical, low-level work — wiring emulation, instrumentation, fuzzing, and exploit primitives into tool interfaces that agents can operate. Vulnerability research must be the central, primary function of the day-to-day, not a secondary responsibility.

Tech stack: C / C++ / Rust; GDB, IDA, Ghidra; QEMU, Unicorn, Qiling, PANDA, FirmAE; Frida, DynamoRIO; Linux (kernel internals, system-level debugging); fuzzing pipelines; modern mitigations (ASLR, CFI, PAC, MTE); agent harnesses / orchestration / eval loops.

Requirements

  • Vulnerability research as the primary function of your current role
  • Strong reverse-engineering and debugger skills (GDB, IDA, or Ghidra)
  • 2–3+ years of C, C++, or Rust systems programming
  • Deep Linux systems fluency
  • On-site in NYC five days a week; relocation required
  • US citizen or clearance-eligible (preferred)

Nice to Haves

  • Exploit-weaponization experience
  • An offensive-security-firm background
  • A competitive CTF background or public CVEs
  • A genuine technical interest in AI agents
  • A startup-suitable culture fit

Why Join

  • A frontier mission: build AI agents that autonomously run offensive vulnerability research against real firmware, network stacks, mobile OSes, and IoT — compressing six months of manual work into days
  • An elite team drawn from leading AI labs and national-security organizations
  • Real customers, real stakes: government clients, tier-1 US VC backing, seed stage with meaningful equity upside
  • Deeply technical, low-level work at the intersection of offensive security and AI-agent infrastructure

Details

  • Location — New York City, NY
  • Work policy — On-site, 5 days/week; relocation required
  • Compensation — $220,000–$350,000 + competitive equity
  • Visa sponsorship — Not available; US citizen or clearance-eligible preferred. Applicants from restricted countries cannot be considered.
  • Employment type — Full-time

About the Company

D

David Joseph & Company