Pi Security Logo

Pi Security

Security Researcher

Posted 2 Days Ago
Be an Early Applicant
In-Office
San Francisco, CA, USA
Senior level
In-Office
San Francisco, CA, USA
Senior level
Lead security research into vulnerability detection, triage, and remediation using LLMs and program analysis. Set the research agenda, develop proofs of concept, validate approaches against real-world data, design benchmarks and evaluation pipelines, build vulnerability and remediation datasets, and carry successful capabilities into production with engineering. Research modern cloud, container, microservice, API, and LLM application attack vectors while contributing to public security research and company credibility.
The summary above was generated by AI
Lead Security Researcher

Location: San Francisco, CA or Israel · Type: Full-time, onsite

About Us

Pi Security is a product security company in San Francisco, founded by the teams who led Microsoft's vulnerability mitigation efforts and Tesla's offensive research.

We built a platform for the agentic SDLC. It changes how companies handle security vulnerabilities, not by finding more of them, but by understanding them deeply enough to fix them at the root and keep entire classes from coming back. The hard problems behind that (what to detect, how to prove a finding is real, how to remediate the way a senior engineer would) are research problems. That is where you come in.

The Role

You will lead security research at Pi. This is not a bug hunting role. Your job is to invent the approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before a customer ever sees them.

You own the path from idea to shipped capability. You form the hypothesis, build the proof of concept, measure whether it actually works, and partner with engineering until it is in the product. You also own the quality bar: the benchmarks and evaluations that decide whether what we ship is good enough to put in front of customers.

You will set the research agenda, not just execute one. As the team grows, you will shape how research works here.

What You'll Own

The research agenda. Identify where new approaches can meaningfully beat the state of the art in vulnerability detection, triage, and remediation, then decide what we pursue and what we kill. No one hands you a backlog.

Approaches that ship. Build proofs of concept for new detection and remediation techniques, validate them against real world code and data, and carry the winners through to production with engineering. You are accountable for ideas becoming product, not staying research.

The quality bar. Design the datasets, benchmarks, and evaluation pipelines that measure precision, coverage, and false positive rates. Nothing reaches customers past a bar you have not signed off on, and if quality slips, you catch it first.

Vulnerability depth. Deep research into modern attack vectors across cloud (AWS/GCP), containers, microservices, APIs, AI generated code, and LLM applications. Not just how vulnerabilities are found, but how they are born, how they are fixed, and how a whole class gets eliminated.

The data foundation. The internal corpus of vulnerabilities, exploit patterns, and remediation strategies the platform learns from. Its depth and correctness are yours.

Our research voice. What we publish, where we speak, and the credibility the company earns in the security community. Your work should be visible.

What We're Looking For

Experience. 8+ years in security research, vulnerability analysis, or applied security engineering.

Startup DNA. You have worked in an early stage or 0 to 1 environment. Comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.

Research to product track record. You have turned research into things that shipped: features, tools, detections in production. Not just papers or reports.

Technical depth. Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.

Builder skills. Strong programming ability in at least one modern language (Python, Go, TypeScript). Comfortable writing production quality code.

Data rigor. Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You do not ship on vibes.

LLM fluency. Hands on experience applying LLMs to real problems, whether evaluation, prompting, fine tuning, or agentic systems, or a demonstrated ability to get there fast.

Proven findings. A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.

Communication. You can explain a complex attack and its real impact clearly to engineers, executives, and customers.

Work authorization. Permanent authorization to work in the US for the San Francisco role, or in Israel for the Israel role.

Bonus Points

We care about impact, not credentials. Things that get our attention:

  • Research that went public and mattered. Publications, disclosures, or talks that changed how people think about a problem, not just filled a slot at a conference.

  • A product you built at a startup. Something that shipped, that real users depended on, where you can point at your fingerprints.

  • Novel ways of putting LLMs or agents to work inside real engineering or security workflows, beyond demos and prompt wrappers.

  • A healthy disrespect for "that's how we've always done it," and a track record of building the better way.

Why Join

You will define the research direction of a company at the stage where one person's ideas still shape the product. The team comes from top tier security organizations, the funding is in place, and the problem is real: vulnerability management is broken in ways everyone in the industry can see and almost no one is positioned to fix. If you want your research to ship and to matter, we would like to talk.

Similar Jobs

One Month Ago
Remote or Hybrid
2 Locations
85K-120K Annually
Senior level
85K-120K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Analyze in-the-wild exploits and perform deep reverse engineering to track adversaries. Build detection, automation, and classification frameworks; develop host/network signatures and tooling. Produce high-quality intelligence reports and briefings, collaborate across teams, and contribute to mitigation and large-scale hunting efforts.
Top Skills: Ai-Assisted ToolsDebuggersDecompilersDisassemblersDynamic Analysis FrameworksLinuxLlmsWindowsPythonSnortStatic Analysis FrameworksYara
22 Days Ago
In-Office
San Francisco, CA, USA
144K-280K Annually
Senior level
144K-280K Annually
Senior level
Artificial Intelligence • Machine Learning • Security • Software
Secure Apollo’s internal software, infrastructure, and AI-agent environments through threat modeling, red teaming, attack-trajectory development, adversary tracking, and detection engineering. Own security findings through remediation by designing durable controls, automated tests, CI/CD integrations, and monitoring. Collaborate closely with engineers and research teams to address novel AI-agent and insider-risk threats while documenting threat models and failure modes clearly.
Top Skills: Adversarial TestingAi AgentsAi/Ml SystemsCi/CdCloud SecurityDetection EngineeringLlm SecurityRed TeamingSocThreat Modeling
One Month Ago
In-Office
Santa Clara, CA, USA
184K-357K Annually
Senior level
184K-357K Annually
Senior level
Artificial Intelligence • Computer Vision • Hardware • Robotics • Metaverse
Conduct offensive security research on SoC and GPU designs, develop tooling and automation, identify and exploit side-channel/fault/physical attacks, integrate mitigations into security architecture, and publish vulnerability research.
Top Skills: Arm AssemblyAsicBinary InstrumentationCChipwhispererConfidential ComputingFuzzingGhidraIda ProJtagMachine Learning For Side-Channel AnalysisRisc-V AssemblySocSymbolic ExecutionTeeTrustzoneVerilog

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account