Vulnerability Researcher
פורסם לפני 19 ימים · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל פיתוח מערכות מבוססות בינה מלאכותית שמבצעות מחקר חולשות באופן עצמאי על מטרות אמיתיות כמו קושחה, מערכות הפעלה לנייד ורשתות. העבודה היומיומית כוללת שילוב של כלי אמולציה, כלי בדיקה וארגז כלים של ניצול חולשות לתוך ממשקי סוכנים חכמים, לצד בניית תשתיות הערכה.
- 2-3+ years across systems programming (C/C++, Rust) and ML infrastructure
- Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE)
- Hands-on work with agent harnesses — orchestration, tool-use, eval loops — in production or at benchmark scale
- Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE)
- Strong RE / debugger chops (GDB, IDA or Ghidra)
- Pwn-heavy CTF experience (DEF CON finals, PPP, DiceGang, Shellphish, Theori, Team Atlanta), public CVEs, conference talks, AIxCC / CGC participation, or kernel / baseband RE
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לחוקרי חולשות בעלי ניסיון קודם, השולטים בתכנות מערכות, ניתוח קבצים בינאריים ושימוש בכלי אמולציה והנדסה לאחור. הוא פחות יתאים למי שאינו מעוניין לעבוד באופן פרונטלי ממשרדי החברה בתל אביב או בניו יורק.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןZealot (zealotlabs.com) builds AI systems that find zero-days, emulate target devices, and develop working exploits for U.S. defense and intelligence customers. We're backed by tier-1 U.S. venture firms and industry leaders, and our team includes alumni of Anthropic, xAI, NSA, USCYBERCOM, Anduril, Unit 8200, and the Mossad.
We're looking for vulnerability researchers to help design and build our agentic systems that autonomously perform vulnerability research against real targets — firmware, network stacks, mobile OSes, IoT. That means wiring emulation (QEMU, Unicorn, Qiling), instrumentation (Frida, DynamoRIO), fuzzing, and exploit primitives into tool interfaces for agents, as well as the evaluation & benchmarking infrastructure to know whether any of it is working.
What we're looking for
• 2–3+ years across systems programming (C/C++, Rust) and ML infrastructure
• Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE)
• Hands-on work with agent harnesses — orchestration, tool-use, eval loops — in production or at benchmark scale
• Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE)
• Strong RE / debugger chops (GDB, IDA or Ghidra) and the patience to use them
Nice to have
Pwn-heavy CTF experience (DEF CON finals, PPP, DiceGang, Shellphish, Theori, Team Atlanta), public CVEs, conference talks, AIxCC / CGC participation, or kernel / baseband RE.
Read this part carefully
That list is what the fully-formed version of this role looks like. It's not a filter. If you're sharp, hungry, and funny, apply anyway — even if half the bullets read like a foreign language today. Tech can be learned. Spirit cannot. We've watched the right people pick up binary exploitation from scratch and outship ten-year veterans inside a year. Tell us what you've taught yourself recently and what you'd tear into first here.
Requirements
Prior Vulnerability Research experience, and willing to relocate to work in-person in our Tel Aviv office. Relocation to New York is also an option
What we offer
• Competitive cash, meaningful early equity, a mission that matters, and hard problems nobody has solved yet.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- מהמשרד
- 2-3+ years across systems programming (C/C++, Rust) and ML infrastructure, Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE), Hands-on work with agent harnesses — orchestration, tool-use, eval loops — in production or at benchmark scale, Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE), Strong RE / debugger chops (GDB, IDA or Ghidra)