Application Security Researcher

OX Security · Canada

RemoteWorkplace
TodayPosted · Sep 28
HimalayasSource
$134kpenetration tester median
Experience5+ years

Skills in this posting

Benefits

The posting

Description

About the Position

OX Security secures the AI-driven SDLC from prompt to production. We eliminate critical, real-time risks from AI code generation through cloud runtime by doing what conventional tools can’t: unifying development and cloud context to stop vulnerabilities right at the source. At OX, we’re building the future of cyber security for the AI era. If you’re looking to work on disruptive technology with an amazing team, you belong here.

We’re looking for a highly skilled Application Security Researcher to join our Security Research group and help us push the boundaries of modern AppSec. This is a critical, hands-on role where you’ll work closely with engineers, researchers, and AI & data scientists to build the next generation of application security - including autonomous, agentic pen testing capabilities.

This is not a typical AppSec role. You’ll be building, breaking, and redefining how offensive security works at scale.

Responsibilities

What You’ll Be Doing

Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure

Design and build detection engines and decision-making logic for autonomous security systems

Evaluate AI models for application security use cases, measuring where they perform and where they fall short

Prototype, build, and ship security capabilities into production environments

Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy

Partner with Product, Engineering, and Data teams to shape the next generation of security features

Help set the team's research direction and own initiatives end to end, from idea to shipped capability

What You'll Bring

M.Sc. in Computer Science, Cyber Security, or a related field

5+ years of hands-on experience in offensive security, vulnerability research, or application security

Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains

Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code

Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives

Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider

Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail

Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy

Ability to take a research idea from prototype to production with minimal guidance

Clear written communication: you can explain a complex attack path to engineers and product managers

Nice to Have

Published research, CVEs, conference talks, or bug bounty track record

Experience building AI agents or evaluation frameworks for LLMs

Background in exploit development, red teaming, or penetration testing

Experience with code analysis techniques (taint analysis, call graphs, reachability)

Contributions to open-source security tools

Benefits Package (via Vensure)

We partner with Vensure to provide top-tier benefits for our Canada-based team members:

Comprehensive Health Coverage: Medical, Dental, and Vision plans to keep you and your family healthy.

Unlimited Paid Time Off (PTO): We offer unlimited vacation because we trust you to take time when you need it and to manage your time effectively. We value work-life balance and want you to recharge.

Gifts on your birthday & anniversary, & Holidays.

Originally posted on Himalayas

The PivotHop read

Where these skills also reach

More penetration tester roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves