onsite
Application Security Engineer - Theori
Security Engineer
Hands‑on Application Security Engineer who will own the triage, validation, and exploitation of AI‑generated static analysis findings, creating proof‑of‑concept exploits and coordinating vendor disclosures.
About the role
Key Responsibilities
- Triaging and validating vulnerability reports produced by an AI‑powered static analysis platform, distinguishing true positives from noise.
- Developing proof‑of‑concept exploits to demonstrate impact and verify findings.
- Coordinating responsible disclosure with vendors and tracking remediation progress.
- Conducting deep‑dive security research, including reverse engineering and binary analysis, to uncover novel attack vectors.
- Improving detection rules and AI models by feeding back real‑world findings and false‑positive data.
Requirements
- 3+ years of hands‑on experience in application security, vulnerability research, or exploit development.
- Proficiency in programming/scripting languages such as Python and C++.
- Strong background in reverse engineering, binary analysis, and static code analysis tools.
- Demonstrated ability to think like an attacker and produce high‑quality proof‑of‑concept exploits.
- Experience working with AI/ML‑driven security tooling or a strong interest in integrating AI into security workflows.