Principal Security Researcher

United StatesPosted Aug 4, 2026

Conduct hands-on vulnerability research across vulnerability classes, languages, frameworks, and codebase architectures to discover and validate vulnerabilities, assess reachability and exploitability, evaluate fixes for security correctness, and identify opportunities to expand MDASH coverage. Translate research and evaluation insights into implemented improvements to MDASH agents, tools, model configurations, and analysis methods, and measure their impact. Identify representative evaluation targets and author trusted ground truth spanning vulnerability evidence, attack paths, severity, validation, and remediation. Drive MDASH's eval-driven development and hill-climbing loop by running evaluations, uncovering patterns in missed and incorrect results, and creating adversarial and regression cases that turn blind spots into measurable capability gains. Build research prototypes, fuzzing harnesses, datasets, graders, and automation that accelerate capability improvement. Provide technical leadership across the MDASH security research team by shaping research direction, leading complex investigations, mentoring other researchers, and raising the quality of vulnerability research and implementation. Collaborate across research, engineering, applied science, and product teams to deliver improvements, communicate results, and influence technical direction. Master's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 4+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Risk Management, Cyber Security, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience. Bachelor's, Master's, or Doctorate Degree in Computer Science, Computer Security, Computer Engineering, or a related field OR equivalent experience. 8+ years of experience in vulnerability research, application security, offensive security, secure software development, program analysis, or related security work. Demonstrated hands-on experience discovering, reproducing, and validating software vulnerabilities; assessing reachability and exploitability; and evaluating remediation correctness. Experience with fuzzing and at least one additional vulnerability research technique, such as manual code review, static analysis, dynamic analysis, debugging, reverse engineering, symbolic execution, taint analysis, or exploit development. Proficiency developing security research tooling or automation in one or more programming languages. Experience communicating complex technical findings through clear written reports, vulnerability analyses, or presentations. Deep knowledge of multiple vulnerability classes and their exploitation patterns, including memory corruption, injection, authentication and authorization, cryptography, deserialization, path traversal, server-side request forgery, and business-logic flaws. Experience building fuzzing harnesses, custom mutators, sanitizers, coverage-guided fuzzing workflows, or large-scale fuzzing infrastructure. Experience analyzing vulnerabilities across multiple programming languages and ecosystems, such as C/C++, C#, Java, JavaScript or TypeScript, Python, and cloud-native applications. Experience constructing security benchmarks, curating ground truth, measuring recall, precision, consistency, or remediation efficacy, and translating root-cause analysis into generalized improvements. Experience building and improving AI agents or agentic systems using large language models, including prompt and tool orchestration, model evaluation, automated grading, or reinforcement learning for security tasks. Experience with static application security testing, software composition analysis, SARIF, secure development lifecycle practices, or developer remediation workflows. Record of vulnerability disclosures, security advisories, CVEs, research publications, conference presentations, open-source security tools, or substantive contributions to the security community.

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free