13 hours ago
Base Salary
$124k - $271k/yr
Responsibilities
- Conduct AI-assisted vulnerability research across products, applications, services, and infrastructure.
- Use threat analysis, architecture knowledge, source code, and system behavior to select targets and guide investigations.
- Apply frontier and open-weight models, agents, and AI capabilities to reconnaissance, code analysis, hypothesis generation, exploit development, and verification.
- Design and tune research harnesses with appropriate context, tools, execution environments, and feedback.
- Build custom analysis utilities, fuzzers, agents, test harnesses, proofs of concept, and exploits.
- Reproduce findings, establish preconditions, distinguish demonstrated vulnerabilities from possible weaknesses, and address false positives, false negatives, nondeterminism, and reproducibility gaps.
- Communicate findings, support remediation, verify fixes, and share AI-driven security research techniques across the organization.
Requirements
- 5+ years of hands-on vulnerability research, offensive security, application security, or penetration testing experience.
- Demonstrated ability to select targets, develop and revise hypotheses, and establish exploitability and impact in complex software or production systems.
- Hands-on experience conducting offensive workflows with frontier and open-weight models, including model selection for legitimate exploit development.
- Experience evaluating AI-driven research quality, including false positives, missed vulnerabilities, unstable results, reproducibility gaps, and agent architecture trade-offs.
- Deep technical expertise in at least one security domain, such as web applications and APIs, Java applications, cloud or service infrastructure, client software, operating systems, or reverse engineering.
- Strong programming and debugging skills, including reading unfamiliar code, building research tooling, writing proofs of concept, and tracing behavior across system boundaries.
- Strong understanding of attack surfaces, trust boundaries, exploitability, and security impact, with the persistence to conduct independent open-ended research.
- Ability to communicate technical findings and uncertainty clearly to technical and nontechnical audiences.
Benefits
- Structured hybrid work approach incorporating office and remote work environments.
- Benefits and perks supporting physical, mental, emotional, and financial health, work-life balance, and community involvement.
- Application window of at least five days; anticipated position close date is October 14, 2026.
About Zoom
Zoom builds a cloud platform for video meetings, team chat, webinars, phone, rooms, and contact center used by businesses, schools, and public-sector organizations. It sells these collaboration and communications services as SaaS subscriptions with add-ons for events, telephony, and enterprise features, and offers developer APIs/SDKs. Founded in 2013 and headquartered in San Jose, California, Zoom Video Communications is a public company traded on Nasdaq.
