hirly

Strix

Security Researcher

New York · San Francisco

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Strix first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Strix

We believe that software is the foundation of modern civilization, yet vulnerabilities threaten its integrity, security, and resilience. Strix is on a mission to solve security.

Strix builds autonomous AI penetration testing agents that think like attackers: discovering, validating, and helping fix real vulnerabilities across live applications, codebases, and infrastructure, continuously, not once a year. We are looking for strong technical people who want to work at the intersection of AI, security, and infrastructure.

About this role

We're looking for a Security Researcher to push the frontier of what our AI agents can find. You will hunt for real vulnerabilities, turn your offensive-security expertise into agent skills, benchmarks, and detection strategies, and validate that Strix finds what matters in real-world targets.

You're excited about this role because you will…

Discover and exploit vulnerabilities in web applications, APIs, cloud infrastructure, and open-source software

Encode offensive-security techniques into agent behaviors, tools, and playbooks that scale your expertise

Build and curate vulnerable environments and benchmarks that measure real agent capability

Analyze agent findings, separate signal from noise, and drive the false-positive rate toward zero

Qualifications

3+ years of hands-on offensive security experience (penetration testing, red teaming, bug bounty, or vulnerability research)

Deep understanding of web application security, exploitation techniques, and modern attack surfaces

Programming experience in Python or similar; comfort building your own tooling

CVEs, published research, CTF results, or a strong bug bounty track record are a plus

A tendency to leave things in a better way than you found them

What we offer

Competitive salary with meaningful equity

Health, vision, and dental insurance

Office lunch and dinner (when working from our New York office)

Strix is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

To all recruitment agencies: Strix does not accept agency resumes. Please do not forward resumes to Strix employees. Strix is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.

Original posting on Strix's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job