Strix Logo

Strix

Security Researcher

Posted 5 Days Ago
Be an Early Applicant
In-Office
San Francisco, CA, USA
Mid level
In-Office
San Francisco, CA, USA
Mid level
Conduct offensive security research across web applications, APIs, cloud infrastructure, and open-source software. Develop and exploit vulnerabilities, translate offensive techniques into AI agent behaviors and playbooks, create vulnerable environments and benchmarks, and analyze findings to reduce false positives. The role requires hands-on penetration testing, red teaming, bug bounty, or vulnerability research experience, strong web security knowledge, and Python or similar programming skills.
The summary above was generated by AI
About Strix

We believe that software is the foundation of modern civilization, yet vulnerabilities threaten its integrity, security, and resilience. Strix is on a mission to solve security.

Strix builds autonomous AI penetration testing agents that think like attackers: discovering, validating, and helping fix real vulnerabilities across live applications, codebases, and infrastructure, continuously, not once a year. We are looking for strong technical people who want to work at the intersection of AI, security, and infrastructure.

About this role

We're looking for a Security Researcher to push the frontier of what our AI agents can find. You will hunt for real vulnerabilities, turn your offensive-security expertise into agent skills, benchmarks, and detection strategies, and validate that Strix finds what matters in real-world targets.

You're excited about this role because you will…
  • Discover and exploit vulnerabilities in web applications, APIs, cloud infrastructure, and open-source software

  • Encode offensive-security techniques into agent behaviors, tools, and playbooks that scale your expertise

  • Build and curate vulnerable environments and benchmarks that measure real agent capability

  • Analyze agent findings, separate signal from noise, and drive the false-positive rate toward zero

Qualifications
  • 3+ years of hands-on offensive security experience (penetration testing, red teaming, bug bounty, or vulnerability research)

  • Deep understanding of web application security, exploitation techniques, and modern attack surfaces

  • Programming experience in Python or similar; comfort building your own tooling

  • CVEs, published research, CTF results, or a strong bug bounty track record are a plus

  • A tendency to leave things in a better way than you found them

What we offer
  • Competitive salary with meaningful equity

  • Health, vision, and dental insurance

  • Office lunch and dinner (when working from our New York office)

Strix is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

To all recruitment agencies: Strix does not accept agency resumes. Please do not forward resumes to Strix employees. Strix is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.

Similar Jobs

9 Days Ago
Hybrid
150K-185K Annually
Entry level
150K-185K Annually
Entry level
Cloud • Information Technology • Security • Software • Cybersecurity
Research bots, automation frameworks, fraud kits, and adversary techniques; reverse-engineer attacks, test and improve detection systems, develop detection heuristics and signatures, design mitigations, and automate analyst investigations. Partner with data scientists and engineers to operationalize intelligence at scale. Clearly communicate attacker behavior and defensive strategies to technical and non-technical audiences.
Top Skills: Browser InternalsCaptchasHTTPJavaScriptPythonTlsWeb Fingerprinting
2 Days Ago
Remote or Hybrid
2 Locations
85K-120K Annually
Senior level
85K-120K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Analyze in-the-wild exploits and perform deep reverse engineering to track adversaries. Build detection, automation, and classification frameworks; develop host/network signatures and tooling. Produce high-quality intelligence reports and briefings, collaborate across teams, and contribute to mitigation and large-scale hunting efforts.
Top Skills: Ai-Assisted ToolsDebuggersDecompilersDisassemblersDynamic Analysis FrameworksLinuxLlmsWindowsPythonSnortStatic Analysis FrameworksYara
3 Hours Ago
Hybrid
106K-183K Annually
Senior level
106K-183K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Provides strategic technical leadership in industrial hygiene and safety engineering for a major account. Responsibilities include hazard identification, exposure assessments, risk prioritization, control evaluation, onsite industrial hygiene sampling, robotics and automation safety reviews, facility modernization support, executive reporting, KPI tracking, training, mentoring, and project leadership. The role is remote with up to 35% overnight travel across the United States and potentially internationally.
Top Skills: Ansi StandardsArtificial IntelligenceAutomation SystemsIso StandardsLotoRobotics

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account