About Job:
We are looking for a security researcher with strong software engineering skills to help build an AI product for vulnerability discovery and validation. You will turn offensive security knowledge into agent capabilities, tools, and backend workflows that investigate customer and open source systems reliably.
What you will build:
- Build backend components for agent execution, tool calling, model integration, and structured findings.
- Translate vulnerability research into agent workflows, reusable tools, and source code analysis capabilities.
- Implement controlled tool execution, sandbox isolation, scoped permissions, resource limits, and cleanup.
- Build persistent run state, retries, cancellation, crash recovery, and event streaming.
- Integrate security tools, independent verification, and evidence capture so findings are reproducible.
- Create realistic security scenarios, PoC-based checks, and regression tests to improve detection quality and reduce false positives.
Engineering experience:
- 3+ years in software engineering, security engineering, or security research, with a track record of building software or security tools.
- Robust TypeScript/Node.js skills and Python experience for tooling, automation, and integrations.
- Experience with APIs, asynchronous systems, databases, automated testing, and debugging complex failures.
- Comfort with Linux, Docker, process/network behavior,
and LLM tool calling; clear communication and ownership of components through delivery.
Security knowledge
- Bring broad awareness across these layers, with hands-on depth in at least two areas. Web/API or source code security should be one of your strongest areas.
- Web and APIs: injection, XSS, SSRF, IDOR/BOLA, authorization, tenant isolation, and business-logic abuse.
- Source code and dependencies: insecure deserialization, memory safety fundamentals, vulnerable libraries, malicious packages, and CVE reproduction.
- AI and LLMs: prompt injection, jailbreaks, unsafe tool use, and MCP trust boundaries.
- Identity and infrastructure: network security, Active Directory, cloud IAM, federation, and privilege escalation.
- Runtime and systems: container, sandbox, and VM isolation; operating-system permissions, service/library flaws, and kernel attack surfaces.
- Deep kernel research, exploit development, fuzzing, or agent-framework experience is a plus.
Show us what you have built
Share backend or agent systems, security tools, or open source contributions you have built. Explain what you owned, the security reasoning, design choices, and reliability challenges. CVEs, bug bounties, and research write-ups provide additional context. A high-level description is welcome for confidential work.
📌 Security Researcher (Mumbai)
🏢 Provue
📍 Mumbai