Security Engineer

27 Days Old

Security Vulnerability Validation Engineer Get AI-powered advice on this job and access more exclusive features. This range is provided by Russell Tobin. Your actual pay will depend on your skills and experience — please consult with your recruiter for more details. Base pay range $60.00/hr - $84.00/hr Direct message the job poster from Russell Tobin Russell Tobin & Associates is seeking a Security Vulnerability Validation Engineer for our client, a leading AI research and deployment company committed to ensuring that artificial general intelligence (AGI) benefits all of humanity. They are recognized for their cutting-edge AI advancements. Apply now to be considered! Pay: $60-$84/hr, based on experience Location: Remote-US The Security Vulnerability Validation Engineer will triage and validate security vulnerabilities across various platforms and technologies, including web applications, APIs, and system-level targets. Core Responsibilities Reproduce and validate security bugs (memory safety issues, logic bugs, web vulnerabilities). Build minimal reproducible examples and proof-of-concept exploits. Triage issues based on severity, exploitability, and real-world impact. Validate LLM-generated findings in server-side and client-side environments. Collaborate with the disclosure team on responsible vendor outreach. Provide feedback to internal researchers to improve bug quality and ranking. Must-Have Skills: Systems Security Deep understanding of memory corruption vulnerabilities: buffer overflows, UAFs, heap overreads, integer overflows, etc. Proficiency with C/C++, and Python. Experience with tools like ASan, Valgrind, GDB, strace, and OSS build systems. Ability to reverse engineer binaries (Ghidra/Binary Ninja experience). Web Security Strong grasp of web application vulnerabilities: XSS, CSRF, SQLi, SSRF, auth bypasses, prototype pollution, etc. Familiarity with modern web stacks: Node.js, Flask, Django, React/Vue, REST/GraphQL APIs. Experience validating issues via tools like Burp Suite, mitmproxy, Chrome DevTools, or custom HTTP clients. Nice-To-Have Skills: Prior web vulnerability bounty or CVE contributions. Familiarity with SAST/DAST tooling pipelines. Benefits include comprehensive healthcare coverage (medical, dental, vision), supplemental coverage (accident, critical illness, hospital indemnity), a 401(k), life & disability insurance, employee assistance, identity theft protection, legal support, auto and home insurance, pet insurance, and discounts with preferred vendors. Seniority level Mid-Senior level Employment type Contract Job function Engineering and Information Technology Industries Technology, Information and Media
#J-18808-Ljbffr
Location:
San Francisco, CA, United States