Jobs · Information Technology · California

Security Researcher

Pi Security · San Francisco, CA · Today
On-siteInformation TechnologyFull-time

About the role

We are a well-funded security startup in San Francisco, founded by the teams who led Microsoft's vulnerability mitigation efforts and Tesla's offensive research. (If still in stealth, keep this line as-is; if launched, name Pi and use the standard boilerplate.) We're building a platform that changes how companies handle security vulnerabilities — not by finding more of them, but by understanding them deeply enough to fix them at the root and keep whole classes from coming back. The hard problems behind that — what to detect, how to prove a finding is real, how to remediate the way a senior engineer would — are research problems. That's where you come in.

Responsibilities

  • Lead security research at the company. This is not a bug-hunting role. Your job is to invent the novel approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before customers ever see them.
  • You own the path from idea to shipped capability — forming the hypothesis, building the proof of concept, measuring whether it actually works, and partnering with engineering until it's in the product.
  • You are accountable for ideas becoming product, not staying research. The quality bar. Design the datasets, benchmarks, and evaluation pipelines that measure precision, coverage, and false-positive rates. Nothing reaches customers past a bar you haven't signed off on — and if quality slips, you catch it first.
  • Vulnerability depth. Deep research into modern attack vectors across cloud (AWS/GCP), containers, microservices, APIs, AI-generated code, and LLM applications — not just how vulnerabilities are found, but how they're born, how they're fixed, and how a whole class gets eliminated.
  • The data foundation. The internal corpus of vulnerabilities, exploit patterns, and remediation strategies the platform learns from. Its depth and correctness are yours.
  • Our research voice. What we publish, where we speak, and the credibility the company earns in the security community. Your work should be visible.

Requirements

  • Experience: 8+ years in security research, vulnerability analysis, or applied security engineering.
  • Startup DNA: You've worked in an early-stage or 0→1 environment — comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.
  • Research-to-product track record: You've turned research into things that shipped — features, tools, detections in production — not just papers or reports.
  • Technical depth: Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.
  • Builder skills: Strong programming ability in at least one modern language (Python, Go, TypeScript, etc.). Comfortable writing production-quality code.
  • Data rigor: Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You don't ship on vibes.
  • LLM fluency: Hands-on experience applying LLMs to real problems — evaluation, prompting, fine-tuning, or agentic systems — or a demonstrated ability to get there fast.
  • Proven findings: A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.
  • Communication: You can explain a complex attack and its real impact clearly to engineers, executives, and customers.

Qualifications

  • Work authorization: Permanent authorization to work in the US (for the San Francisco role) or in Israel (for the Israel role).

Skills

  • LLM fluency: Hands-on experience applying LLMs to real problems — evaluation, prompting, fine-tuning, or agentic systems — or a demonstrated ability to get there fast.

Benefits

  • Permanent authorization to work in the US (for the San Francisco role) or in Israel (for the Israel role).

Pay

Competitive salary and equity package.

Schedule

Full-time, onsite.

Similar jobs

Security Researcher

Netwrix CorporationUnited States· Yesterday
RemoteInformation Technologyapply on ats.rippling.com

Security Researcher

RecoWilmington, DE· 3 wk ago
RemoteInformation Technologyapply on comeet.com

Security Researcher

depthfirstSan Francisco, CA· 1 mo ago
Information Technologyapply on jobs.ashbyhq.com

Security Researcher

CorgeaSan Mateo, CA· 9 mo ago
Information Technologyapply on ycombinator.com

Security Researcher

CylakeSunnyvale, CA· 3 wk ago
Information Technology$150k–$250k/yrapply on jobs.ashbyhq.com