CONFISA INTERNATIONAL GROUP
Member of Technical Staff, Vulnerability Researcher

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description
Job Title: Member of Technical Staff, Vulnerability Researcher
Job Type: Full Time
Location: Remote
About the hiring company:
Our client is a rapidly growing, venture-backed AI company helping shape the next generation of intelligent systems. By combining world-class human expertise with advanced machine learning workflows, they enable leading AI organizations to build, evaluate, and improve cutting-edge models used across a wide range of industries.
The company works with highly accomplished professionals in fields such as software engineering, finance, healthcare, legal, operations, research, and other specialized domains. These experts contribute directly to the development of advanced AI systems by providing real-world knowledge, evaluations, feedback, and domain-specific judgment that help models reason more accurately and perform more effectively.
Leveraging a proprietary AI-driven talent assessment and matching platform, the organization identifies exceptional professionals globally and connects them with high-impact projects at the forefront of artificial intelligence.
Backed by more than $40 million in funding and supported by a rapidly expanding international network of experts, the company is building critical human intelligence infrastructure for the AI economy and creating meaningful opportunities for professionals to apply their expertise in entirely new ways.
Job Summary:
The Role
We're building AI systems that push the frontier of what software can do. As a Member of Technical Staff, Vulnerability Research, you'll operate like an internal adversary—discovering novel attack paths before anyone else does. You'll research emerging threats across AI agents, cloud infrastructure, developer platforms, and production systems, partnering closely with engineering to make our stack fundamentally more resilient.
What You'll Do
- Conduct advanced offensive security research across cloud infrastructure (AWS, GCP), production services, internal tooling, and AI platforms.
- Design and execute realistic adversary simulations targeting identity systems, cloud control planes, supply chains, and distributed architectures.
- Discover and exploit vulnerabilities across proprietary applications, APIs, infrastructure-as-code, CI/CD pipelines, and AI-powered developer workflows.
- Research emerging attack vectors against LLMs, AI agents, retrieval systems, MCP integrations, prompt orchestration, and autonomous workflows.
- Reverse engineer critical services to uncover architectural weaknesses, novel exploitation techniques, and previously unknown vulnerability classes.
- Simulate insider and advanced persistent threat scenarios, evaluating privilege escalation, lateral movement, and defense evasion techniques across modern enterprise environments.
- Build custom offensive tooling, automation frameworks, fuzzers, and proof-of-concept exploits to accelerate vulnerability discovery.
- Partner closely with infrastructure, product, and AI engineering teams to validate fixes, improve secure-by-design practices, and raise the overall security bar.
- Publish internal research, document attack methodologies, and help shape long-term security strategy.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We're Looking For
- Proven experience in offensive security, vulnerability research, red teaming, or exploit development.
- Deep understanding of cloud security across AWS and GCP, including IAM, networking, Kubernetes, containers, and identity systems.
- Strong background in application security, code auditing, reverse engineering, and vulnerability discovery.
- Experience identifying weaknesses across modern software supply chains, CI/CD systems, APIs, and infrastructure automation.
- Proficiency in Python, Go, Rust, C/C++, or similar languages used for security research and offensive tooling.
- Strong understanding of operating system internals, networking, authentication protocols, and modern security architectures.
- Ability to independently investigate ambiguous problems and develop novel attack techniques.
- Excellent written communication skills with the ability to explain complex vulnerabilities to engineering teams.
Preferred
- Experience researching AI/LLM security, including agentic systems, prompt injection, tool abuse, indirect prompt attacks, jailbreaks, model manipulation, RAG security, or autonomous workflows.
- Experience discovering zero-day vulnerabilities, developing exploits, or contributing to offensive security research.
- Published CVEs, conference talks, blog posts, open-source security tooling, or participation in bug bounty programs.
- Experience with macOS internals, endpoint security, virtualization, or hardware-backed security technologies.
- Familiarity with fuzzing, symbolic execution, binary analysis, or compiler security.
- Contributions to the broader security research community.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Compensation & Benefits Notice
The national pay range for this full-time position is base salary of $200,000 –$250,000. All employees are eligible for equity compensation, and employees may also receive performance-based bonuses, dependent on role and subject to company policies. micro1 provides a comprehensive benefits package, including up to 100% reimbursement for health-insurance premiums, paid time off, a 401(K) plan with a company match, and additional benefits designed to support a high-performing, remote-first workforce.
micro1 is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other characteristic protected by applicable local laws, regulations and ordinances.
Our hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making.
Disclaimer
The information contained in this job posting, including but not limited to role responsibilities, qualifications, compensation, and benefits, is provided for informational purposes only and does not constitute a binding offer of employment. micro1 reserves the right to amend, modify, or withdraw any portion of this posting at its sole discretion and without prior notice. All employment decisions are made in accordance with applicable laws and regulations.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location