You find the failures that matter before a user does, testing the product as a connected system of hardware, software and people. Finding the flaw is half the role; explaining it clearly and working with the team to close it is the other half, and it is the half that decides whether the finding actually helps.
Open for applications. Starts at: Pilot expansion.
We are taking applications for this role now and building the pipeline for it. The stage above is when the work itself is expected to begin, which is something you deserve to know before you apply rather than after. It is context, not a gate.
Where
In the office together five days a week, in one of our garages, and remote-friendly around your family, arranged one person at a time. We hire across the United States 🇺🇸, India 🇮🇳 and the UAE 🇦🇪.
The work
Conduct authorized research into device compromise, sandbox boundaries, agent manipulation, data exposure and recovery abuse. Build reproducible demonstrations and work with owners on repairs and regression coverage. Follow agreed scope and coordinated vulnerability handling.
The milestone
In your first 90 days, complete one scoped assessment with reproducible findings, impact analysis and verified remediation.
Required
Nice to have
Evidence
Bring evidence of original security research, deep debugging or high-quality vulnerability discovery. Clear explanations and constructive collaboration are as important as finding a flaw.
Evidence, not credentials. We are describing work you can point at, in whatever form it exists.
The exercise
Present a past finding with its root cause, practical impact, remediation and the assumptions that limited the test.
The package
Indicative pay ranges by market and level are on the compensation page. Plan numbers are confirmed in your offer letter.
Apply
One short form. A person reads every application and you hear back either way. You will get your own link to check where things stand, and you can withdraw or delete your application from it at any time, without an account.