Theori
AppSec Engineer
United States · Canada
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Mid level
- Countries
- US, CA
- Work mode
- Remote-friendly
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
We're looking for a hands-on Cyber Security Engineer to sit at the intersection of AI-driven tooling and real-world security research. In this role, you'll own the end-to-end triage and validation lifecycle for vulnerability reports generated by our AI-powered static analysis platform, separating true positives from noise, writing proof-of-concept exploits, and reporting vulnerabilities upstream to the appropriate vendor.
This is a deeply technical role built for someone who thinks like an attacker, thrives in ambiguous environments, and has a track record of finding and exploiting vulnerabilities.
What You'll Do
Triage and validate vulnerability reports produced by our AI static analysis tool, verifying severity, exploitability, and business impact
Write proof-of-concept exploits for critical vulnerabilities to confirm true positives
Analyze false positives to identify patterns and provide structured feedback to engineering
Author detailed vulnerability reports that will be submitted to upstream vendors and open source projects
What We're Looking For
Experience in a security engineering, vulnerability research, or penetration testing role
Demonstrated CTF experience through participation in competitive CTFs (e.g. DEFCON, PlaidCTF) with writeups
Hands-on real-world vulnerability research and exploitation experience is preferred
Proficiency reading and auditing code across multiple programming languages
Prior bug bounty participation is preferred
Based in US or Canada
Similar jobs
- AppSec EngineerDigital Asset · New York CityFirst seen yesterday
- SecOps/AppSec Engineer (Clojure Required)Ladder33 · RemoteFirst seen 22d agoremote
- Sr. AppSec Engineer - Go Java C#Sentinellabs · United StatesFirst seen 28d agoremote
- AI AppSec Engineer LeadCapgroup · 4 LocationsFirst seen 2d ago
- Lead Cloud Security/AppSec EngineerFlagshippioneeringinc · Cambridge, MA USAFirst seen 26d ago
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job