We are hiring a Senior Security Researcher to join the CTO Office and lead original research in identity security, bringing that work to the broader security community.
You'll have the autonomy to set your own research agenda and the visibility to shape product strategy with what you find.
The core of the role is offensive research targeting identity systems and protocols - identity providers, SSO, authentication and authorization standards (OAuth/OIDC/SAML, WebAuthn/FIDO2, etc.), MFA implementations, directory services, federation, session management, etc. When you find something, you'll drive responsible disclosure with the affected vendors and turn the work into technical write-ups and talks at conferences like Black Hat, DEF CON, CCC, and similar.
Building a public research presence is a central part of this role, not a side effect of it.
Alongside the research work, you'll contribute security feature ideas back into our product and periodically audit and pentest our own platform.
ResponsibilitiesHunt for novel vulnerabilities, design flaws, and attack techniques across identity providers, authentication and authorization protocols, and related infrastructure. Build proofs-of-concept that prove real-world impact.
Run responsible disclosure end-to-end with affected vendors, from initial report through patch validation and CVE assignment.
Publish your research as technical blog posts and whitepapers, and present it at top-tier security conferences. Represent the company on stage and in the community.
Feed what you learn from breaking things into our product — concrete security features, detections, and design improvements.
Periodically turn the same scrutiny on our own platform through internal pentests.
5+ years of hands-on offensive security or vulnerability research experience.
Strong grasp of identity, authentication, and authorization technologies: OAuth 2.0, OIDC, SAML, Kerberos, WebAuthn/FIDO2, session and token security, federation, and directory services (Active Directory, Entra ID, Okta, or equivalent).
A track record of published research - CVEs, technical write-ups, conference talks, bug bounty findings, or comparable public work.
Experience driving responsible disclosure with vendors.
Excellent technical writing and presentation skills in English. You can take a deep technical finding and make it land with both researchers and executives.
- Speaking experience at conferences such as Black Hat, DEF CON, CCC, or similar events.
- Reverse engineering experience using tools such as IDA, Ghidra, Frida, or equivalent.
- Familiarity with AWS IAM, Entra ID, GCP IAM, and modern cloud identity architectures.
- Background in red teaming or identity-focused offensive security operations.
- Contributions to open-source security projects.