
Security Researcher
Role summary
Corgea is seeking a remote Security Researcher in the US to focus on uncovering, analyzing, and preventing vulnerabilities in modern software, particularly at the intersection of AI, security research, and developer tooling. The role involves researching and designing detection methods for new vulnerability classes, analyzing code (including AI-generated code) for exploit patterns, and collaborating with the engineering team to integrate research into their AI-driven security engine. Candidates should have 4-8 years of experience in application security, offensive research, or secure software development, with proficiency in languages like Python, Java, Go, or C/C++ and a strong understanding of various vulnerability classes. Experience with static/dynamic analysis, fuzzing, or reverse engineering is a plus.
We’re looking for a **Security Researcher** who is passionate about uncovering, analyzing, and preventing vulnerabilities in modern software. This role sits at the intersection of AI, security research, and developer tooling. You’ll help shape how Corgea detects new classes of vulnerabilities and automate secure code analysis at scale.
This is a **remote** position based in the US (preferably in California or the San Francisco Bay Area).
#### **What You’ll Be Doing**
* Research and design detection methods for emerging vulnerability classes across multiple languages and frameworks.
* Analyze source code, binaries, and AI-generated code to identify new exploit patterns and attack surfaces.
* Collaborate with our engineering team to integrate your research into Corgea’s AI-driven security engine.
* Conduct security evaluations of open-source and enterprise applications to validate and refine Corgea’s models.
* Stay current on the latest CVEs, exploit techniques, and security trends to inform product intelligence.
#### **Who You Are**
* 4–8 years of experience in **application security**, **offensive research**, or **secure software development**.
* Strong understanding of **vulnerability classes** (e.g., injection, deserialization, path traversal, auth bypass, XXE, SSRF, RCE).
* Proficiency in one or more languages such as **Python, Java, JavaScript/TypeScript, Go, or C/C++**.
* Experience with **static or dynamic analysis tools**, fuzzing, or reverse engineering is a plus.
* Curiosity about how attackers think—and how AI can help defenders move faster.
* Comfortable working autonomously in a fast-paced, research-driven startup.
#### **Why You Should Apply**
* Competitive salary and equity package (0.50 % – 2.00 %).
* Work on cutting-edge problems at the frontier of AI and cybersecurity.
* Collaborate directly with leading engineers, researchers, and security experts.
* Flexible hybrid schedule aligned with San Francisco time.
#### **Diversity and Inclusion**
At Corgea, we’re committed to diversity and inclusion. We assess all applicants based on merit, qualifications, competence, and talent—without discrimination of any kind.
Similar roles
- Senior Security ResearcherMicrosoft · Redmond, Washington, United States · Hybrid
- Senior Security ResearcherClarity Innovations, LLC · United States
- Security ResearcherIru · Miami, Florida, United States · Hybrid
- Principal Security ResearcherMicrosoft · Redmond, Washington, United States · Hybrid
- Security ResearcherMicrosoft · United States · Remote