Research Safety Company
News

Security Researcher

Security · Remote


← Careers

Everything here is written rather than rented, which means every defect in it is ours. This role exists to find those defects before somebody else does, and to make the finding public. Not a compliance function and not a report that gets filed: an adversary on the payroll, pointed at our own work.

What you'll work on

You break what we build. The identity system, the session handling, the anti-abuse path, the risk decisions, the model behaviour, the infrastructure underneath all of it. The last full pass over the front ends returned zero findings, which is a fact about the pass rather than about the system, and the correct response to it is a better pass.

A large part of the job is the case nobody constructs. The failures found here have overwhelmingly been of one shape: something that reports success while not working. Our own bot defence answering our own monitoring probe. A liveness check that skips the database. Alarms wired to a key that could not grant the service permission to send. Those are not exotic bugs; they are the ordinary ones, and they survive because verification is easier to fake than to do.

You will also write. Internal findings, public writeups, and the postmortems, which go out including the part that is still wrong on the day of publication. Some of the work stays internal. The rule for the rest is that a claim you cannot let a stranger re-run is a claim not worth publishing.

What we're looking for

Someone who breaks things methodically rather than randomly: a theory of how the thing works, patience, and a willingness to try the approach that should not work. You have done adversarial testing against real systems, and whether those were models, web applications or binaries matters less than the habit.

You write clearly, because research that cannot be communicated is research that does not ship, and here it also has to survive being read by people outside. Published advisories, technical writing, competition play, or tooling you built all count as evidence.

One thing to weigh: what you find gets published, and your name goes on it only if you want it there. Nobody but the founder is named publicly by default.

How to apply

Email careers@neuraphic.com with the subject line "Security Researcher." Send a resume, links to published work, and a description of the most interesting flaw you have found: what made it interesting, and what made it survive as long as it did.