Penetration tester, offensive research_
Remote or New York · full-time
Run the platform against real targets. Validate what it finds. File every miss as a fix.
What you'll do
Point the workflows at real targets — bug-bounty programmes and authorised engagements — and answer the question the bench cannot: does it work on real code? Validate findings, write the proofs of concept, disclose responsibly, and file every miss and false positive back into the registry as an issue or a fix. Run max when it matters and tell us when it wasn't worth it.
What we look for
A track record on bug-bounty platforms or in pentest engagements under your name. You write reports people act on. You know the difference between a finding and a hunch, and you know how to get from one to the other.
What we offer
You hunt with the strongest open workflows on the strongest models with the budget covered, and the fixes you file ship to every user of the platform.