Corgea logo
Corgea Verified
["Legal Tech","Artificial Intelligence","Software","SaaS","Natural Language Processing"]

Security Researcher

San Francisco, California, United StatesRemoteFull Time$120,000–$220,000 /yrPosted 2 months agoHidden Gem · YC Startup

Is this role right for you?

Upload your resume and get a skill-by-skill breakdown — see exactly where you match, where you're close, and what to highlight. Not a mystery percentage.

Get a tailored resume highlighting what this role needs.

Role summary

Corgea is seeking a remote Security Researcher in the US to focus on uncovering, analyzing, and preventing vulnerabilities in modern software, particularly at the intersection of AI, security research, and developer tooling. The role involves researching and designing detection methods for new vulnerability classes, analyzing code (including AI-generated code) for exploit patterns, and collaborating with the engineering team to integrate research into their AI-driven security engine. Candidates should have 4-8 years of experience in application security, offensive research, or secure software development, with proficiency in languages like Python, Java, Go, or C/C++ and a strong understanding of various vulnerability classes. Experience with static/dynamic analysis, fuzzing, or reverse engineering is a plus.

#### **Job Description**

We’re looking for a **Security Researcher** who is passionate about uncovering, analyzing, and preventing vulnerabilities in modern software. This role sits at the intersection of AI, security research, and developer tooling. You’ll help shape how Corgea detects new classes of vulnerabilities and automate secure code analysis at scale.

This is a **remote** position based in the US (preferably in California or the San Francisco Bay Area).

#### **What You’ll Be Doing**

* Research and design detection methods for emerging vulnerability classes across multiple languages and frameworks.
* Analyze source code, binaries, and AI-generated code to identify new exploit patterns and attack surfaces.
* Collaborate with our engineering team to integrate your research into Corgea’s AI-driven security engine.
* Conduct security evaluations of open-source and enterprise applications to validate and refine Corgea’s models.
* Stay current on the latest CVEs, exploit techniques, and security trends to inform product intelligence.

#### **Who You Are**

* 4–8 years of experience in **application security**, **offensive research**, or **secure software development**.
* Strong understanding of **vulnerability classes** (e.g., injection, deserialization, path traversal, auth bypass, XXE, SSRF, RCE).
* Proficiency in one or more languages such as **Python, Java, JavaScript/TypeScript, Go, or C/C++**.
* Experience with **static or dynamic analysis tools**, fuzzing, or reverse engineering is a plus.
* Curiosity about how attackers think—and how AI can help defenders move faster.
* Comfortable working autonomously in a fast-paced, research-driven startup.

#### **Why You Should Apply**

* Competitive salary and equity package (0.50 % – 2.00 %).
* Work on cutting-edge problems at the frontier of AI and cybersecurity.
* Collaborate directly with leading engineers, researchers, and security experts.
* Flexible hybrid schedule aligned with San Francisco time.

#### **Diversity and Inclusion**

At Corgea, we’re committed to diversity and inclusion. We assess all applicants based on merit, qualifications, competence, and talent—without discrimination of any kind.
Ready to apply?
You'll be redirected to Corgea's application page.

Similar roles