896,285open jobs
55,555companies
150,473added this week
Browse all
Salary
≈ $98k – $223k per year (Estimated)
Location
In office (Tel Aviv)
Seniority
Staff · 8+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 28, 2026. First seen by Alion on Jul 29, 2026.

Overview
Company
Impact
Profile match

Pi

Secure software as fast as you build. Pi's agentic platform eliminates recurring vulnerabilities, automates remediation, and brings AI code security to your SDLC.

Lead Security Researcher

Location: Israel · Type: Full-time, onsite

About Us

Pi Security is a product security company in San Francisco, founded by the teams who led Microsoft's vulnerability mitigation efforts and Tesla's offensive research.

We built a platform for the agentic SDLC. It changes how companies handle security vulnerabilities, not by finding more of them, but by understanding them deeply enough to fix them at the root and keep entire classes from coming back. The hard problems behind that (what to detect, how to prove a finding is real, how to remediate the way a senior engineer would) are research problems. That is where you come in.

The Role

You will lead security research at Pi. This is not a bug hunting role. Your job is to invent the approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before a customer ever sees them.

You own the path from idea to shipped capability. You form the hypothesis, build the proof of concept, measure whether it actually works, and partner with engineering until it is in the product. You also own the quality bar: the benchmarks and evaluations that decide whether what we ship is good enough to put in front of customers.

You will set the research agenda, not just execute one. As the team grows, you will shape how research works here.

What You'll Own

The research agenda. Identify where new approaches can meaningfully beat the state of the art in vulnerability detection, triage, and remediation, then decide what we pursue and what we kill. No one hands you a backlog.

Approaches that ship. Build proofs of concept for new detection and remediation techniques, validate them against real world code and data, and carry the winners through to production with engineering. You are accountable for ideas becoming product, not staying research.

The quality bar. Design the datasets, benchmarks, and evaluation pipelines that measure precision, coverage, and false positive rates. Nothing reaches customers past a bar you have not signed off on, and if quality slips, you catch it first.

Vulnerability depth. Deep research into modern attack vectors across cloud (AWS/GCP), containers, microservices, APIs, AI generated code, and LLM applications. Not just how vulnerabilities are found, but how they are born, how they are fixed, and how a whole class gets eliminated.

The data foundation. The internal corpus of vulnerabilities, exploit patterns, and remediation strategies the platform learns from. Its depth and correctness are yours.

Our research voice. What we publish, where we speak, and the credibility the company earns in the security community. Your work should be visible.

What We're Looking For

Experience. 8+ years in security research, vulnerability analysis, or applied security engineering.

Startup DNA. You have worked in an early stage or 0 to 1 environment. Comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.

Research to product track record. You have turned research into things that shipped: features, tools, detections in production. Not just papers or reports.

Technical depth. Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.

Builder skills. Strong programming ability in at least one modern language (Python, Go, TypeScript). Comfortable writing production quality code.

Data rigor. Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You do not ship on vibes.

LLM fluency. Hands on experience applying LLMs to real problems, whether evaluation, prompting, fine tuning, or agentic systems, or a demonstrated ability to get there fast.

Proven findings. A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.

Communication. You can explain a complex attack and its real impact clearly to engineers, executives, and customers.

Work authorization. Permanent authorization to work in the US for the San Francisco role, or in Israel for the Israel role.

Bonus Points

We care about impact, not credentials. Things that get our attention:

  • Research that went public and mattered. Publications, disclosures, or talks that changed how people think about a problem, not just filled a slot at a conference.

  • A product you built at a startup. Something that shipped, that real users depended on, where you can point at your fingerprints.

  • Novel ways of putting LLMs or agents to work inside real engineering or security workflows, beyond demos and prompt wrappers.

  • A healthy disrespect for "that's how we've always done it," and a track record of building the better way.

Why Join

You will define the research direction of a company at the stage where one person's ideas still shape the product. The team comes from top tier security organizations, the funding is in place, and the problem is real: vulnerability management is broken in ways everyone in the industry can see and almost no one is positioned to fix. If you want your research to ship and to matter, we would like to talk.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
896,285 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Tel Aviv
≈ $78k – $194k per year (Estimated) • In office • Full-Time • 4+ years exp • Haifa
Python
DevOps
AWS
Cybersecurity
Threat Modeling
Apply
≈ $101k – $230k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Tel Aviv
Apply
≈ $93k – $211k per year (Estimated) • Hybrid • 5+ years exp • Tel Aviv
JavaScript
PHP
TypeScript
PHP
WordPress
AI/ML
Model Context Protocol
AI Agents
LLM
DevOps
Azure
CI/CD
AWS
Kubernetes
Cybersecurity
Threat Modeling
OWASP
Apply
≈ $124k – $258k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • Dallas
DevOps
Azure
AWS
Cybersecurity
ISO 27001
NIST CSF
NIST 800-53
Zero Trust
Defense in Depth
Least Privilege
Threat Modeling
Management
Agile
Apply
≈ $105k – $215k per year (Estimated) • Remote (Canada) • 4+ years exp
AI/ML
Claude
Claude Code
LLM
OpenAI Codex
Human-in-the-Loop
DevOps
Azure
CI/CD
AWS
Kubernetes
GitHub
Cybersecurity
Snyk
Trivy
CodeQL
Wiz
Dependabot
Kyverno
BeyondTrust
Apply
Data Scientist 2 hours ago
≈ $15k – $36k per year (Estimated) • In office • Full-Time • 4+ years exp • Hyderabad
Python
AI/ML
AI Agents
RAG
Machine Learning
DevOps
GCP
Azure
AWS
Apply
≈ $13k – $32k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
Python
Java
AI/ML
Embeddings
AI Agents
RAG
Multi-Agent Systems
Machine Learning
DevOps
GCP
Azure
AWS
Docker
Kubernetes
Management
ServiceNow
Agile
Apply
In office • Full-Time • Bengaluru
Python
Databases
Databricks
AI/ML
AI Agents
DevOps
Azure
CI/CD
Git
Linux
Cybersecurity
Microsoft Entra ID
Apply
≈ $105k – $194k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • PhD • United States
Python
JavaScript
Java
TypeScript
SQL
Java
Spring Boot
Databases
PostgreSQL
MS SQL
Apache Kafka
Amazon DocumentDB
Microsoft Fabric
AI/ML
LangChain
Semantic Kernel
LLM
OpenAI
Machine Learning
Frontend
React.js
DevOps
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Amazon EKS
Linux
Management
Agile
Apply
≈ $105k – $194k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • PhD • United States
Python
JavaScript
Java
TypeScript
Java
Spring Boot
Databases
PostgreSQL
MS SQL
Apache Kafka
Amazon DocumentDB
Microsoft Fabric
AI/ML
LLM
OpenAI
Frontend
React.js
DevOps
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Management
Agile
Apply
Security Researcher 2 months ago
≈ $142k – $279k per year (Estimated) • In office • Full-Time • 8+ years exp • San Francisco
Python
TypeScript
AI/ML
Fine-tuning
AI Agents
LLM
DevOps
GCP
AWS
Apply
Head of Engineering 13 days ago
≈ $202k – $379k per year (Estimated) • In office • Full-Time • San Francisco
AI/ML
AI Agents
LLM
LLM Guardrails
DevOps
CI/CD
GitHub
GitLab
Cybersecurity
Crowdstrike
Apply
Product Designer 18 days ago
≈ $102k – $218k per year (Estimated) • In office • Full-Time • 3+ years exp • San Francisco
JavaScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Next.js
React.js
Design
Figma
Sketch
Apply
Product Marketing 19 days ago
≈ $120k – $239k per year (Estimated) • In office • Full-Time • 5+ years exp • San Francisco
AI/ML
AI Agents
DevOps
AWS
Cybersecurity
Crowdstrike
Apply
≈ $156k – $296k per year (Estimated) • In office • Full-Time • 5+ years exp • San Francisco
JavaScript
TypeScript
AI/ML
AI Agents
LLM Guardrails
Frontend
Tailwind CSS
Next.js
React.js
Storybook
tRPC
QA
Playwright
Vitest
Apply
≈ $101k – $230k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Tel Aviv
Apply
≈ $105k – $228k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Tel Aviv
SQL
AI/ML
Model Context Protocol
Computer Vision
AI Agents
LLM
LLM Guardrails
Multi-Agent Systems
DevOps
CI/CD
Apply
≈ $136k – $322k per year (Estimated) • Hybrid • Full-Time • Tel Aviv
AI/ML
AI Agents
Management
Monday.com
Apply
≈ $92k – $251k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Tel Aviv
AI/ML
Chain-of-Thought
AI Agents
LLM
Tool Use
Machine Learning
DevOps
AWS
Apply
≈ $82k – $191k per year (Estimated) • In office • Full-Time • 3+ years exp • Tel Aviv
DevOps
Linux
Apply
See all jobs
This is one of many
896,285 more open roles from verified company boards, updated every day.