Posted on: 09/10/2026
Required Experience :
- 1 - 3 years hands-on in one or more of : Application or product security, VAPT, secure code review, or vulnerability research; Software engineering with real code-review responsibility; LLM evaluation, annotation, or red teaming for coding or tool-calling agents.
- Strong security fundamentals and demonstrable hands-on work matter more here than years or pedigree.
- You can read code and judge a patch. Comfortable in at least one of Python, JavaScript/TypeScript, Go, Java, C/C++, Ruby or PHP, and able to reason about a diff in a language you don't write daily.
- Working knowledge of vulnerability classes - injection, path traversal, deserialization, memory safety, authentication and access-control flaws, and how each is properly fixed.
- Able to read long agent trajectories - 10+ turn reasoning and tool-call chains - without losing the thread.
- Able to fix, not just flag. You can write or repair a test that fails on the vulnerable build and passes on the fixed one, and correct a broken verifier or accept-set without weakening what it checks.
- Clear written reasoning. Your annotations are the deliverable; they must stand up to a researcher disagreeing with them.
- Comfortable with Git, containers/Docker, reading test output and stack traces, and structured labeling formats (JSON/JSONL).
The job is for:
Did you find something suspicious?