About the role
You find the failures that matter before a user does, testing the product as a connected system of hardware, software and people. Finding the flaw is half the role; explaining it clearly and working with the team to close it is the other half, and it is the half that decides whether the finding actually helps.
The work
Conduct authorized research into device compromise, sandbox boundaries, agent manipulation, data exposure and recovery abuse. Build reproducible demonstrations and work with owners on repairs and regression coverage. Follow agreed scope and coordinated vulnerability handling.
What good looks like
In your first 90 days, complete one scoped assessment with reproducible findings, impact analysis and verified remediation.
Evidence we look for
Bring evidence of original security research, deep debugging or high-quality vulnerability discovery. Clear explanations and constructive collaboration are as important as finding a flaw.
What we need to see
- Original security research, deep debugging, or high-quality vulnerability discovery
- You explain a finding clearly enough that the fix is obvious to the team that owns it
- Constructive collaboration rather than adversarial theatre
- You test the whole system, including the human path, not only the code
Nice to have
- Hardware as well as software research
- Published CVEs, or bug-bounty standing
- Social engineering or physical security assessment
The exercise
Present a past finding with its root cause, practical impact, remediation and the assumptions that limited the test.
Where and how we work
In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.