O

Application Security Researcher

OX Security

Toronto, Ontario, Canada · Full Time

Be the first to apply

Experience
5+ yrs
Salary
—
Openings
1
Posted
2 days ago
Work mode
In office
Education
M.Sc. in Computer Science or Cyber Security
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

At OX Security, we focus on securing the AI-driven software development lifecycle from initial prompt through to production. Our approach addresses critical and real-time risks emerging from AI code generation in cloud runtime environments by uniquely combining development and cloud contexts to eliminate vulnerabilities at their origin. Join us as we innovate the future of cybersecurity for the AI age, working alongside a talented and passionate team on breakthrough technology.

Key Responsibilities

  • Investigate vulnerability chains, business logic errors, and intricate attack sequences affecting both applications and infrastructure.
  • Create and implement detection engines and decision-making algorithms for autonomous security systems.
  • Assess AI models specifically for application security scenarios, identifying their strengths and limitations.
  • Develop prototypes and deploy security solutions within live production environments.
  • Analyze extensive security datasets to detect exploitable attack vectors and enhance detection precision.
  • Collaborate closely with Product, Engineering, and Data teams to shape future security capabilities.
  • Lead research initiatives from conception through deployment, taking full ownership of the projects.

Candidate Requirements

  • Master's degree in Computer Science, Cybersecurity, or closely related disciplines.
  • Minimum five years of practical experience in offensive security, vulnerability research, or application security.
  • In-depth knowledge of web application and API security vulnerabilities including complex business logic flaws and multi-step attack methodologies.
  • Proficient programming skills in Python, Go, or comparable languages, with a proven track record of delivering production-grade software.
  • Experience in developing or fine-tuning detection mechanisms (SAST, DAST, SCA, secrets detection, or custom rules) and minimizing false positives.
  • Strong understanding of contemporary application and infrastructure technologies such as CI/CD pipelines, containers, Kubernetes, and at least one major cloud platform.
  • Hands-on experience utilizing large language models (LLMs) or other AI models for security-related tasks, coupled with the discernment to evaluate their effectiveness and shortcomings.
  • Comfortable working with large datasets via tools like SQL or BigQuery to aid research and optimize detection accuracy.
  • Capable of independently advancing research concepts from initial prototype stages to full production deployment.
  • Excellent written communication skills to clearly articulate complex attack paths to engineering and product stakeholders.

Preferred Qualifications

  • Authored published research, disclosed CVEs, presented at conferences, or maintained an active bug bounty record.
  • Experience designing AI agents or evaluation frameworks for language models.
  • Background in exploit creation, red teaming exercises, or penetration testing.
  • Familiarity with code analysis techniques such as taint tracking, call graph generation, and reachability analysis.
  • Contributions to open-source security projects.

Benefits

  • Comprehensive healthcare benefits including medical, dental, and vision coverage for employees and their families, facilitated through Vensure.
  • Unlimited paid time off enabling flexible vacation to support work-life balance and personal recharge.
  • Special gifts provided on birthdays, work anniversaries, and holidays.

Minimum education

Master's Degree

Industry

Cybersecurity

Tools & software

Kubernetes required

How they work

Communication Teamwork & Collaboration Initiative Learning Agility

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer