Highlights
Be part of a dynamic team leading offensive and defensive cybersecurity efforts. Secure top-paying salaries and equity in one of the most active teams in the industry.
Description
Job Summary
pJoin the forefront of open-source security with CodeAnt AI, a Y Combinator-backed platform dedicated to defensive and offensive cybersecurity. In this role, you will hunt for zero-days in widely used OSS packages, contribute to CVE research, and help secure the global software ecosystem.
Responsibilities
- Hunt for zero-days in open-source software packages
- Conduct end-to-end CVE research from discovery to published advisory
- Ship upstream fixes to enhance overall security of the ecosystem
- Participate in responsible disclosure motions and feed findings back into the engine
- Present findings at major cybersecurity conferences such as BSidesSF, RSA, DEF CON, Black Hat
Required Skills
- Experience with open-source software
- Familiarity with security research methods
- Certified in ethical hacking or related field
- Proficiency in multiple programming languages
- Strong analytical and problem-solving skills
Required Skills Explained
- Experience in zero-day hunting and vulnerability discovery
- Proficiency in open-source security tools and platforms
- Strong background in CVE research, from initial discovery to published advisory
- Aptitude for responsible disclosure practices
- Excellent communication skills for effective collaboration and presentation of findings
Who is this for
pThis position is ideal for individuals passionate about open-source security, with a proven track record of discovering vulnerabilities. You should have a strong desire to contribute to the global software ecosystem's safety.
Why This Job is a Good Opportunity
ulliTop-of-market compensation package that exceeds industry standardsliUnique opportunity to work with leading offensive and defensive security teams in the industryliPotential equity stake that can significantly grow in value with company successliHigh-impact role contributing to widespread cybersecurity improvements
Interview Preparation Tips
- Research common vulnerabilities in open-source packages, especially those shipping to large user bases
- Prepare examples of your past successful zero-day discoveries and disclosures
- Practice explaining the responsible disclosure process clearly and concisely
- Be ready to discuss specific CVEs you have disclosed and their impact
Career Growth in This Role
pThis role offers substantial career growth potential. As a zero-day hunter, you will be at the forefront of identifying and addressing critical vulnerabilities that affect billions of devices. Your work can lead to significant advancements in open-source security practices.pThe opportunity for advancement exists through taking on more complex projects, leading teams, or contributing to high-impact initiatives such as large-scale vulnerability disclosures.pAdditionally, the exposure to top-tier cybersecurity conferences and events provides a platform to build your professional network and enhance your reputation in the industry.
Explore More Opportunities
Skills
Frequently Asked Questions
What kind of experience do you prefer in candidates?We are looking for experienced individuals with a strong background in open-source security, vulnerability research, and ethical hacking.
Will I have opportunities to present at conferences?Yes, this role includes the opportunity to present findings at major cybersecurity events such as BSidesSF, RSA, DEF CON, Black Hat.
What are the responsibilities of an OSS Security Researcher?Responsibilities include hunting for zero-days in OSS packages, conducting CVE research, shipping upstream fixes, and participating in responsible disclosure motions.