The company secures the AI-driven SDLC from prompt to production, unifyingdevelopment and cloud context to stop vulnerabilities at the source. TheSecurity Research group is hiring a senior, hands-on Application SecurityResearcher to push modern AppSec forward — working with engineers, researchersand AI/data scientists on next-generation detection, including autonomous,agentic pen-testing capabilities. This is a build-and-break role, not a typicalAppSec position.
Requirements
- 5+ years hands-on in offensive security, vulnerability research, orapplication security
- Deep understanding of web application and API vulnerabilities, includingbusiness-logic flaws and multi-step attack chains
- Strong coding in Python, Go, or similar, with production-quality code shipped
- Experience building or tuning detection logic (SAST, DAST, SCA, secrets, orcustom rule engines) and reducing false positives
- Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and atleast one major cloud provider
- Hands-on use of LLMs / AI models for security tasks, with the judgment tomeasure where they help and where they fail
- Comfort with large datasets (SQL, BigQuery, or similar) to drive research andmeasure detection accuracy
- Takes research ideas from prototype to production with minimal guidance
- Transparent written communication — can explain a complex attack path to engineersand product managers
- M.Sc. in Computer Science, Cyber Security, or a related field
Nice to have
- Published research, CVEs, conference talks, or a bug bounty track record
- Experience building AI agents or evaluation frameworks for LLMs
- Background in exploit development, red teaming, or penetration testing
- Code analysis techniques (taint analysis, call graphs, reachability)
- Contributions to open-source security tools
#J-18808-Ljbffr
📌 Senior Application Security Researcher (Toronto)
🏢 Kibbi
📍 Toronto