Vulnerability Researcher II
- Onsite
- All ai & machine learning jobs
- Full-time
- Artificial Intelligence
About the role
Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we provide certainty.
We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud to serve 10% of the Fortune 500, protecting global icons such as Apple, Netflix, AT&T, Verizon, and Victoria’s Secret.
As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.
The Culture Memo: Our Operating System
Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.
-
Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.
-
The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.
-
Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.
-
Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.
-
The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.
The Perks & Ownership:
We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.
-
Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.
-
Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.
-
Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.
-
Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.
Core Responsibilities:
-
Primary role is to work with the Threat Research team focussing on vulnerability research to analyze affected products, versions, affected path, and trigger conditions for newly released vulnerabilities
-
Utilize vulnerability and exploit intel feeds to identify newly disclosed CVEs or critical vulnerabilities without CVEs which are being exploited in the wild
-
Setup a lab to generate PoC and detection queries using SAFE Query Language
-
Coordinate with the SAFE Exploit Research team to build exploits for these CVEs
-
Identify compensating controls that can be implemented to reduce the risk from these CVEs
-
Continuous research on latest security trends and novel attacks based on Threat & Vulnerability feeds
-
Proactively collaborate within the Threat Research and the Programme Management team
Essential Skills, Experience and Qualifications:
-
M.Tech or B.Tech / B.E. / BCA in Computer Science or Information Technology
-
Must have hands-on experience in solving CTF challenges
-
Must have experience in effectively utilizing LLMs for vulnerability research
-
Contributions to open source tools, CVEs advisories, or published research
-
Hands-on knowledge of port scanners, vulnerability scanners and exploitation framework
-
Hands-on experience with building modules/templates for detection or scanning in platforms like Nuclei, Metasploit, etc.
-
Able to work independently with minimum supervision
-
Effective communication, and interpersonal skills
-
OSCP
-
CPTS
-
CRTO
Any of the following certifications would be preferred:
Description as published by Safe Security.