Security Engineer
27 Days Old
Security Vulnerability Validation Engineer Get AI-powered advice on this job and access more exclusive features.
This range is provided by Russell Tobin. Your actual pay will depend on your skills and experience — please consult with your recruiter for more details.
Base pay range $60.00/hr - $84.00/hr
Direct message the job poster from Russell Tobin
Russell Tobin & Associates is seeking a Security Vulnerability Validation Engineer for our client, a leading AI research and deployment company committed to ensuring that artificial general intelligence (AGI) benefits all of humanity. They are recognized for their cutting-edge AI advancements. Apply now to be considered!
Pay: $60-$84/hr, based on experience
Location: Remote-US
The Security Vulnerability Validation Engineer will triage and validate security vulnerabilities across various platforms and technologies, including web applications, APIs, and system-level targets.
Core Responsibilities
Reproduce and validate security bugs (memory safety issues, logic bugs, web vulnerabilities).
Build minimal reproducible examples and proof-of-concept exploits.
Triage issues based on severity, exploitability, and real-world impact.
Validate LLM-generated findings in server-side and client-side environments.
Collaborate with the disclosure team on responsible vendor outreach.
Provide feedback to internal researchers to improve bug quality and ranking.
Must-Have Skills:
Systems Security
Deep understanding of memory corruption vulnerabilities: buffer overflows, UAFs, heap overreads, integer overflows, etc.
Proficiency with C/C++, and Python.
Experience with tools like ASan, Valgrind, GDB, strace, and OSS build systems.
Ability to reverse engineer binaries (Ghidra/Binary Ninja experience).
Web Security
Strong grasp of web application vulnerabilities: XSS, CSRF, SQLi, SSRF, auth bypasses, prototype pollution, etc.
Familiarity with modern web stacks: Node.js, Flask, Django, React/Vue, REST/GraphQL APIs.
Experience validating issues via tools like Burp Suite, mitmproxy, Chrome DevTools, or custom HTTP clients.
Nice-To-Have Skills:
Prior web vulnerability bounty or CVE contributions.
Familiarity with SAST/DAST tooling pipelines.
Benefits include comprehensive healthcare coverage (medical, dental, vision), supplemental coverage (accident, critical illness, hospital indemnity), a 401(k), life & disability insurance, employee assistance, identity theft protection, legal support, auto and home insurance, pet insurance, and discounts with preferred vendors.
Seniority level Mid-Senior level
Employment type Contract
Job function Engineering and Information Technology
Industries Technology, Information and Media
#J-18808-Ljbffr
- Location:
- San Francisco, CA, United States