Remote | Member of Technical Staff, Vulnerability Researcher — $240,000–$400,000/year
24-MAGWe are sharing a full-time opportunity for an experienced Vulnerability Researcher with deep expertise in offensive security, red teaming, multi-cloud exploitation, application security, reverse engineering, exploit development, and emerging AI/LLM security to identify novel attack paths and strengthen the resilience of modern production systems.
The role focuses on advanced security research across cloud infrastructure, production services, developer platforms, AI systems, identity architectures, and software supply chains. The successful candidate will operate as an internal adversarial researcher, discover previously unknown weaknesses, build proof-of-concept tooling, validate remediation efforts, and collaborate closely with engineering teams to improve secure-by-design practices.
Key Responsibilities
Offensive Security Research
- Conduct advanced security research across cloud infrastructure, production services, internal tooling, and AI platforms
- Investigate realistic attack paths across complex enterprise systems
- Identify architectural weaknesses and vulnerability classes
- Develop technically rigorous proof-of-concept research
- Document findings clearly for engineering and security stakeholders
Cloud Security & Multi-Cloud Research
- Evaluate security across AWS and GCP environments
- Assess identity, access-control, networking, Kubernetes, and container configurations
- Investigate cloud control-plane and infrastructure weaknesses
- Analyse privilege boundaries and service interactions
- Support validation of security controls across multi-cloud systems
Adversary Simulation & Red Teaming
- Design realistic adversary simulations
- Evaluate identity systems, cloud control planes, software supply chains, and distributed architectures
- Assess privilege-escalation and lateral-movement risks
- Simulate insider-threat and advanced adversarial scenarios
- Identify opportunities to improve defensive controls
Application & API Security
- Review proprietary applications and APIs for security weaknesses
- Conduct code auditing and vulnerability analysis
- Evaluate authentication and authorisation behaviour
- Identify implementation and architectural security issues
- Collaborate with engineering teams on remediation validation
CI/CD & Software Supply Chain Security
- Assess build and deployment pipelines
- Identify weaknesses in CI/CD systems and infrastructure automation
- Evaluate software-supply-chain risk
- Review infrastructure-as-code and developer workflows
- Support improvements to secure development and deployment practices
AI & LLM Security Research
- Research emerging security risks affecting LLMs and AI agents
- Evaluate agentic workflows and tool-enabled AI systems
- Analyse prompt injection, tool abuse, indirect attacks, and related AI security risks
- Assess retrieval and RAG-based systems
- Investigate security implications of autonomous and orchestrated AI workflows
Reverse Engineering & Vulnerability Discovery
- Reverse engineer critical services where appropriate
- Identify architectural and implementation weaknesses
- Investigate potential novel vulnerability classes
- Analyse operating-system and service behaviour
- Apply advanced security-research techniques to ambiguous technical problems
Offensive Tooling & Automation
- Build custom tooling supporting security research
- Develop automation frameworks and research utilities
- Create fuzzing or analysis tooling where relevant
- Produce proof-of-concept implementations for validated vulnerabilities
- Improve the speed and repeatability of vulnerability research workflows
Security Control Validation
- Work with infrastructure, product, and AI engineering teams to validate fixes
- Evaluate whether remediation addresses underlying attack paths
- Identify residual risk after mitigation
- Support secure-by-design engineering practices
- Contribute to stronger long-term security architecture
Security Research Documentation
- Produce internal technical research and vulnerability reports
- Document attack methodologies and findings
- Communicate complex security issues clearly to engineering teams
- Support strategic remediation planning
- Contribute insights to long-term security strategy
Ideal Profile
- Proven experience in offensive security, vulnerability research, red teaming, or exploit development
- Deep understanding of AWS and GCP security
- Strong knowledge of IAM, cloud networking, Kubernetes, containers, and identity systems
- Strong application-security and code-auditing experience
- Experience with reverse engineering and vulnerability discovery
- Familiarity with software supply-chain and CI/CD security
- Strong understanding of APIs and infrastructure automation
- Proficiency in Python, Go, Rust, C/C++, or comparable security-research languages
- Strong knowledge of operating-system internals
- Strong networking and authentication-protocol knowledge
- Ability to investigate ambiguous technical problems independently
- Ability to develop novel security-research approaches
- Excellent written technical communication skills
- Experience with AI/LLM security is highly valuable
- Familiarity with agentic systems, prompt injection, tool abuse, RAG security, or autonomous workflows is advantageous
- Experience discovering zero-day vulnerabilities or developing exploits is highly valued
- Published CVEs, conference talks, technical blog posts, open-source security tooling, or bug-bounty experience are advantageous
- Experience with macOS internals, endpoint security, virtualisation, or hardware-backed security is beneficial
- Familiarity with fuzzing, symbolic execution, binary analysis, or compiler security is valuable
- Contributions to the broader security-research community are advantageous
Engagement Details
- Full-time engagement
- Fully remote
- Compensation: $240,000–$400,000/year
- Work will involve vulnerability research, red teaming, cloud security, application security, reverse engineering, exploit research, AI/LLM security, and remediation validation
- Strong hands-on offensive-security experience is central to this role
- Responsibilities may span AWS, GCP, Kubernetes, containers, CI/CD systems, APIs, identity architectures, AI agents, retrieval systems, and developer platforms
- Regular collaboration with infrastructure, product, AI, and security engineering teams is expected
- Project priorities, research areas, attack surfaces, and defensive requirements may evolve as systems and emerging threats develop
- All security research must be conducted only within authorised environments and scopes, and without using confidential or proprietary information belonging to any unauthorised third party
About the Platform
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams.
By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy