430,068open jobs
14,667companies
59,611added this week
Browse all
Salary
$168k – $238k per year
Location
Remote (Canada)
Seniority
Staff · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Researcher based in Canada

This is a senior security research role focused on securing AI-powered DevSecOps and modern software development environments. You will conduct cutting-edge research across complex application and AI security surfaces, identifying novel, systemic, and chained vulnerabilities before they can affect customers. The role combines hands-on offensive security research, penetration testing, exploit development, and security tooling with strategic influence across engineering teams. You will investigate emerging AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation, while helping define security requirements for AI-enabled capabilities. Working in a highly collaborative and technically sophisticated environment, you will translate research findings into actionable remediation strategies and systemic security improvements. The position also offers opportunities to mentor researchers, shape security roadmaps, and contribute novel vulnerability research to the broader security community.

Accountabilities:

    • Security Research: Conduct advanced security research across at least two technical specialty areas, identifying novel, systemic, and chained vulnerabilities where multiple weaknesses can combine to create significant security impact.
    • Vulnerability Validation & Exploitation: Perform hands-on testing and develop proof-of-concept exploits that demonstrate realistic attack scenarios, validating the severity and practical impact of identified vulnerabilities.
    • AI & Agent Security: Research the security of AI-powered and agentic capabilities, investigate emerging attack vectors such as prompt injection and agent manipulation, and contribute to defining security requirements for AI-enabled systems.
    • Vulnerability Class Research: Assess emerging industry vulnerability classes against complex codebases and drive remediation at the systemic level rather than addressing individual vulnerabilities in isolation.
    • Security Tooling & Automation: Build tools, automation, and agent-assisted workflows that scale security research and improve the efficiency of vulnerability discovery and analysis.
    • Open Source Security: Research the security posture of open-source tools and dependencies integrated into the platform, communicate findings responsibly to maintainers, and track remediation in accordance with responsible disclosure practices.
    • Cross-Functional Security Leadership: Partner with engineering and security teams to communicate findings, provide constructive technical feedback, define security improvements, and influence remediation priorities.
    • Technical Strategy & Mentorship: Contribute to the security team roadmap, solve high-scope and ambiguous technical problems, mentor other individual contributors, and advise teams beyond the immediate security function when appropriate.
    • Knowledge Sharing: Share novel vulnerability classes, research findings, attack techniques, and security insights with internal teams and the broader security community through documentation, presentations, or other knowledge-sharing activities.
    • Requirements

      • Professional Experience: 7+ years of experience in security research, penetration testing, offensive security, application security, or a closely related discipline.
      • Offensive Security Expertise: Demonstrated hands-on experience discovering, validating, and exploiting vulnerabilities, with the ability to develop realistic proof-of-concept attacks.
      • Technical Specialization: Subject matter expertise in at least two technical areas that directly impact product security, with the ability to investigate complex vulnerabilities across multiple domains.
      • Programming Skills: Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust. Experience with AI frameworks is an advantage.
      • Code Analysis: Strong ability to read, understand, and analyze code across multiple programming languages and complex codebases.
      • AI Security Knowledge: Practical understanding of AI attack vectors, including prompt injection, agent manipulation, workflow exploitation, and other emerging threats affecting AI-powered applications and agentic systems.
      • Technical Leadership: Experience leading technical objectives and security initiatives across cross-functional teams, influencing engineering decisions without relying solely on direct authority.
      • Communication: Excellent written and verbal communication skills, with the ability to explain complex security research clearly to both technical and non-technical stakeholders.
      • Risk & Remediation: Ability to translate technical findings into clear risk assessments, business-relevant impact statements, and practical remediation recommendations.
      • Analytical Thinking: Strong problem-solving skills and creative thinking, particularly when developing novel attack scenarios and investigating systemic security weaknesses.
      • Preferred Experience: Published security research or conference presentations, software engineering experience with distributed systems, security certifications such as OSCP, OSCE, GPEN, or similar, and experience securing DevSecOps platforms are all valuable additions.
      • Benefits

        • Compensation: U.S. base salary range of $168,000-$238,000 USD, with the final level and compensation determined based on experience, skills, education, geographic location, and internal and market considerations.
        • Equity: Equity compensation and an employee stock purchase plan.
        • Health & Well-Being: Benefits designed to support physical health, financial security, and overall well-being.
        • Flexible Time Off: Flexible paid time off to support work-life balance.
        • Parental Leave: Paid parental leave for eligible employees.
        • Professional Development: Dedicated growth and development resources to support continuous learning and career progression.
        • Inclusive Community: Team member resource groups and an emphasis on creating an inclusive and equitable workplace.
        • Remote Work: Remote-first employment model, with location eligibility determined by applicable hiring guidelines.
        • Technical Impact: Opportunity to work on complex application security, AI security, DevSecOps, offensive research, and emerging vulnerability challenges at significant scale.
        • Career Growth: Exposure to advanced security research, cross-functional technical leadership, mentorship, and opportunities to influence security strategy and engineering practices.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
430,068 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Senior AI Engineer 3 hours ago
$84k – $166k per year (Estimated) • Remote • Contractor • 5+ years exp
Go
JavaScript
Java
Kotlin
TypeScript
SQL
C#
Databases
PostgreSQL
Redis
DynamoDB
Apache Kafka
AI/ML
Cursor
Claude
Claude Code
AI Agents
OpenAI Codex
Frontend
GraphQL
React.js
DevOps
gRPC
Terraform
GCP
Azure
AWS
Docker
Apply
$80k – $159k per year (Estimated) • Remote • Full-Time • 5+ years exp
Python
Java
PHP
TypeScript
Databases
PostgreSQL
DevOps
Rest API
Terraform
Helm
CI/CD
ArgoCD
AWS
Docker
Kubernetes
Apply
$46k – $72k per year • In office • Full-Time • Tokyo
Python
JavaScript
TypeScript
SQL
Node JS
Databases
Redis
AI/ML
LLM
Frontend
React.js
DevOps
Vercel
CI/CD
AWS
Kubernetes
AWS Lambda
Amazon S3
IAM
Amazon ECS
Cybersecurity
ISO 27001
Threat Modeling
Apply
$113k – $243k per year (Estimated) • Remote • Full-Time • 10+ years exp
Python
JavaScript
TypeScript
C++
Frontend
Tailwind CSS
Next.js
React.js
Radix UI
tRPC
shadcn/ui
Mantine
DevOps
CI/CD
Apply
Remote • Full-Time • 5+ years exp
JavaScript
TypeScript
Frontend
GraphQL
Chart.js
React.js
Storybook
Ant Design
Sass
Less
Mobile
React Native
DevOps
AWS
Design
Figma
QA
Playwright
Apply
$84k – $144k per year • Remote • Full-Time • 3+ years exp
Marketing
YouTube
Apply
$84k – $144k per year • Remote • Full-Time • 3+ years exp
Marketing
YouTube
Apply
Remote • Full-Time • 5+ years exp
JavaScript
TypeScript
Frontend
GraphQL
Chart.js
React.js
Storybook
Ant Design
Sass
Less
Mobile
React Native
DevOps
AWS
Design
Figma
QA
Playwright
Apply
Senior AI Engineer 3 hours ago
$84k – $166k per year (Estimated) • Remote • Contractor • 5+ years exp
Go
JavaScript
Java
Kotlin
TypeScript
SQL
C#
Databases
PostgreSQL
Redis
DynamoDB
Apache Kafka
AI/ML
Cursor
Claude
Claude Code
AI Agents
OpenAI Codex
Frontend
GraphQL
React.js
DevOps
gRPC
Terraform
GCP
Azure
AWS
Docker
Apply
$80k – $159k per year (Estimated) • Remote • Full-Time • 5+ years exp
Python
Java
PHP
TypeScript
Databases
PostgreSQL
DevOps
Rest API
Terraform
Helm
CI/CD
ArgoCD
AWS
Docker
Kubernetes
Apply
See all jobs
This is one of many
430,068 more open roles from verified company boards, updated every day.