
Security Researcher
DepthFirst12 months ago
Responsibilities
- Build technology that discovers novel vulnerabilities at scale in open-source and proprietary codebases.
- Develop techniques to reduce false positives through automated exploitation, proof-of-concept generation, and context inference.
- Collaborate with engineers to understand system limitations and design improved methodologies.
- Publish internal technical reports and contribute to security advisories as needed.
Requirements
- At least 3 years of full-time experience in security research, offensive security, or a related field.
- Experience finding vulnerabilities in source code.
- Experience creating proof-of-concept exploits for vulnerabilities.
- Programming experience in Python.
- Bachelor’s degree in Computer Science or Software Engineering, or equivalent industry experience.
- Strong curiosity, problem-solving ability, and interest in using new tools to address real-world security problems.
Benefits
- Health, vision, and dental insurance
- Office lunch when working from the San Francisco office
- Meaningful equity
- Competitive salary with no specific base amount stated
About DepthFirst
DepthFirst builds an AI-driven security platform that analyzes source code, infrastructure, and business logic to detect and help remediate software vulnerabilities, including potential zero-days. It sells enterprise security software and services to engineering and security teams at organizations with large codebases and open-source dependencies. Privately held and headquartered in San Francisco, the company focuses on general security intelligence delivered by AI agents that continuously scan customer and popular open-source projects.