Application Security Researcher
Toronto, Ontario, Canada · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 days ago
- Work mode
- In office
- Education
- M.Sc. in Computer Science or Cyber Security
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
At OX Security, we focus on securing the AI-driven software development lifecycle from initial prompt through to production. Our approach addresses critical and real-time risks emerging from AI code generation in cloud runtime environments by uniquely combining development and cloud contexts to eliminate vulnerabilities at their origin. Join us as we innovate the future of cybersecurity for the AI age, working alongside a talented and passionate team on breakthrough technology.
Key Responsibilities
- Investigate vulnerability chains, business logic errors, and intricate attack sequences affecting both applications and infrastructure.
- Create and implement detection engines and decision-making algorithms for autonomous security systems.
- Assess AI models specifically for application security scenarios, identifying their strengths and limitations.
- Develop prototypes and deploy security solutions within live production environments.
- Analyze extensive security datasets to detect exploitable attack vectors and enhance detection precision.
- Collaborate closely with Product, Engineering, and Data teams to shape future security capabilities.
- Lead research initiatives from conception through deployment, taking full ownership of the projects.
Candidate Requirements
- Master's degree in Computer Science, Cybersecurity, or closely related disciplines.
- Minimum five years of practical experience in offensive security, vulnerability research, or application security.
- In-depth knowledge of web application and API security vulnerabilities including complex business logic flaws and multi-step attack methodologies.
- Proficient programming skills in Python, Go, or comparable languages, with a proven track record of delivering production-grade software.
- Experience in developing or fine-tuning detection mechanisms (SAST, DAST, SCA, secrets detection, or custom rules) and minimizing false positives.
- Strong understanding of contemporary application and infrastructure technologies such as CI/CD pipelines, containers, Kubernetes, and at least one major cloud platform.
- Hands-on experience utilizing large language models (LLMs) or other AI models for security-related tasks, coupled with the discernment to evaluate their effectiveness and shortcomings.
- Comfortable working with large datasets via tools like SQL or BigQuery to aid research and optimize detection accuracy.
- Capable of independently advancing research concepts from initial prototype stages to full production deployment.
- Excellent written communication skills to clearly articulate complex attack paths to engineering and product stakeholders.
Preferred Qualifications
- Authored published research, disclosed CVEs, presented at conferences, or maintained an active bug bounty record.
- Experience designing AI agents or evaluation frameworks for language models.
- Background in exploit creation, red teaming exercises, or penetration testing.
- Familiarity with code analysis techniques such as taint tracking, call graph generation, and reachability analysis.
- Contributions to open-source security projects.
Benefits
- Comprehensive healthcare benefits including medical, dental, and vision coverage for employees and their families, facilitated through Vensure.
- Unlimited paid time off enabling flexible vacation to support work-life balance and personal recharge.
- Special gifts provided on birthdays, work anniversaries, and holidays.
Minimum education
Master's Degree
Industry
Cybersecurity