Staff Security Researcher
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Researcher based in Canada
This is a senior security research role focused on securing AI-powered DevSecOps and modern software development environments. You will conduct cutting-edge research across complex application and AI security surfaces, identifying novel, systemic, and chained vulnerabilities before they can affect customers. The role combines hands-on offensive security research, penetration testing, exploit development, and security tooling with strategic influence across engineering teams. You will investigate emerging AI attack vectors, including prompt injection, agent manipulation, and workflow exploitation, while helping define security requirements for AI-enabled capabilities. Working in a highly collaborative and technically sophisticated environment, you will translate research findings into actionable remediation strategies and systemic security improvements. The position also offers opportunities to mentor researchers, shape security roadmaps, and contribute novel vulnerability research to the broader security community.
Accountabilities:- Security Research: Conduct advanced security research across at least two technical specialty areas, identifying novel, systemic, and chained vulnerabilities where multiple weaknesses can combine to create significant security impact.
- Vulnerability Validation & Exploitation: Perform hands-on testing and develop proof-of-concept exploits that demonstrate realistic attack scenarios, validating the severity and practical impact of identified vulnerabilities.
- AI & Agent Security: Research the security of AI-powered and agentic capabilities, investigate emerging attack vectors such as prompt injection and agent manipulation, and contribute to defining security requirements for AI-enabled systems.
- Vulnerability Class Research: Assess emerging industry vulnerability classes against complex codebases and drive remediation at the systemic level rather than addressing individual vulnerabilities in isolation.
- Security Tooling & Automation: Build tools, automation, and agent-assisted workflows that scale security research and improve the efficiency of vulnerability discovery and analysis.
- Open Source Security: Research the security posture of open-source tools and dependencies integrated into the platform, communicate findings responsibly to maintainers, and track remediation in accordance with responsible disclosure practices.
- Cross-Functional Security Leadership: Partner with engineering and security teams to communicate findings, provide constructive technical feedback, define security improvements, and influence remediation priorities.
- Technical Strategy & Mentorship: Contribute to the security team roadmap, solve high-scope and ambiguous technical problems, mentor other individual contributors, and advise teams beyond the immediate security function when appropriate.
- Knowledge Sharing: Share novel vulnerability classes, research findings, attack techniques, and security insights with internal teams and the broader security community through documentation, presentations, or other knowledge-sharing activities.
- Professional Experience: 7+ years of experience in security research, penetration testing, offensive security, application security, or a closely related discipline.
- Offensive Security Expertise: Demonstrated hands-on experience discovering, validating, and exploiting vulnerabilities, with the ability to develop realistic proof-of-concept attacks.
- Technical Specialization: Subject matter expertise in at least two technical areas that directly impact product security, with the ability to investigate complex vulnerabilities across multiple domains.
- Programming Skills: Proficiency in one or more of Ruby, Go, Python, TypeScript, or Rust. Experience with AI frameworks is an advantage.
- Code Analysis: Strong ability to read, understand, and analyze code across multiple programming languages and complex codebases.
- AI Security Knowledge: Practical understanding of AI attack vectors, including prompt injection, agent manipulation, workflow exploitation, and other emerging threats affecting AI-powered applications and agentic systems.
- Technical Leadership: Experience leading technical objectives and security initiatives across cross-functional teams, influencing engineering decisions without relying solely on direct authority.
- Communication: Excellent written and verbal communication skills, with the ability to explain complex security research clearly to both technical and non-technical stakeholders.
- Risk & Remediation: Ability to translate technical findings into clear risk assessments, business-relevant impact statements, and practical remediation recommendations.
- Analytical Thinking: Strong problem-solving skills and creative thinking, particularly when developing novel attack scenarios and investigating systemic security weaknesses.
- Preferred Experience: Published security research or conference presentations, software engineering experience with distributed systems, security certifications such as OSCP, OSCE, GPEN, or similar, and experience securing DevSecOps platforms are all valuable additions.
- Compensation: U.S. base salary range of $168,000–$238,000 USD , with the final level and compensation determined based on experience, skills, education, geographic location, and internal and market considerations.
- Equity: Equity compensation and an employee stock purchase plan.
- Health & Well-Being: Benefits designed to support physical health, financial security, and overall well-being.
- Flexible Time Off: Flexible paid time off to support work-life balance.
- Parental Leave: Paid parental leave for eligible employees.
- Professional Development: Dedicated growth and development resources to support continuous learning and career progression.
- Inclusive Community: Team member resource groups and an emphasis on creating an inclusive and equitable workplace.
- Remote Work: Remote-first employment model, with location eligibility determined by applicable hiring guidelines.
- Technical Impact: Opportunity to work on complex application security, AI security, DevSecOps, offensive research, and emerging vulnerability challenges at significant scale.
- Career Growth: Exposure to advanced security research, cross-functional technical leadership, mentorship, and opportunities to influence security strategy and engineering practices.
Requirements
Benefits
$147.6k - $184.5k per year
...make a difference at global scale. Job Overview: The Design & Research teams play a crucial role in Coursera's success by gathering... ...Coursera achieve a seamless experience across its platform. As a Staff Product Designer, you will lead the design strategy and execution...SuggestedInternshipWork at office$160k - $180k per year
...tracking into one place, donor prospect research tools that offer proactive insights and real... ...Position Summary: We are seeking a Staff Software Engineer, Payments to provide technical... ...technical decisions where reliability, security, compliance, or financial risk are...SuggestedInternship- ...DESCRIPTION : We are seeking a Senior User Experience (UX) Researcher for Canadian public sector projects. RESPONSIBILITIES :... ...Spoken and written English required. Government of Canada security clearance (Reliability) and former public sector work experience...SuggestedPermanent employmentFull timeInternship1 day per week
$147.6k - $184.5k per year
...make a difference at global scale. Job Overview: The Design & Research teams play a crucial role in Coursera's success by gathering... ...Coursera achieve a seamless experience across its platform. As a Staff Product Designer, you will lead the design strategy and execution...SuggestedInternshipWork at office$118.4k - $162.8k per year
..., we're building the operational infrastructure to match — and that starts with our People & Culture team. We're looking for a Senior Staff, People Technologist to serve as the strategic owner of our entire People Tech ecosystem. This role reports to the Senior Manager, People...SuggestedLong term contractLocal areaRemote workWork from homeHome office- ...Off-site Category: Engineering Remote Eligible Yes Hire Type: Employee Job ID 8617 Date posted 02/24/2025R&D Engineering, Senior Staff Engineer Description We Are: At Synopsys, we drive the innovations that shape the way we live and connect. Our technology is...Full timeRemote work
- ...to-end product development — from idea to production, for our AI security team. You’ll build and ship AI-powered products (LLM-driven... ...You Will Do Own end-to-end product development — from idea, research, and architecture to production. Build and ship AI-powered security...Remote jobLong term contract
- ...organization is disclosed to shortlisted candidates. About the Opportunity A Toronto-based practice is seeking an experienced securities lawyer to join at the partner level. The role suits a lawyer with an established capital markets or securities regulatory practice looking...
- ...an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. Research at Stripe Stripe’s mission is to increase the GDP of the internet and expand economic access globally. We design tools and...Long term contractTemporary work
- ...single AI-powered Command Center: Acquia Source. Acquia. Built for every audience, human or otherwise. The Role: Acquia is seeking a Staff AI Engineer to join our Data & Intelligence function . Acquia runs one of the largest Drupal and digital experience footprints in the...Remote jobLocal area
- ...to shape legendary play that lasts a lifetime. À propos du poste Hasbro est à la recherche d'un(e) analyste principal(e) de la sécurité SAP pour se joindre à son équipe de sécurité TI à Montréal. Ce poste de contributeur(trice) individuel(le) senior jouera un rôle clé...Long term contract
$170k - $210k per year
...Corporate & Securities Associate Location: Vancouver, BC Practice Area: Corporate / Securities Experience: 2-5 years Compensation: Commensurate with experience; comparable Vancouver market roles range $170,000–$210,000 This is a confidential search — the identity...- ...and lead by example. Authentication, Login, and general Account Security experiences are deeply cross-cutting areas at Stripe with critical... .... Responsibilities Build beautiful web experiences and secure full-stack authentication machinery that impacts millions of users...Full time
- ...magic of play. This is your chance to shape legendary play that lasts a lifetime. About the Role Hasbro is seeking a Principal SAP Security Analyst to join our IT Security team in Montreal. This senior individual contributor position will assist in steering access...Long term contractShift work
- ...Clinical Research Associate - Canada - Multi-TA or Oncology ICON plc is a world-leading healthcare intelligence and clinical research organization... ...and reporting. Providing training and guidance to site staff and other CRAs to maintain high standards of clinical trial...Remote jobFlexible hours
$150k - $210k per year
...globally. Our technology helps operators thrive while delivering unforgettable moments to travelers around the world. We’re looking for a Staff Software Engineer to join the Checkfront team. Checkfront is an established SaaS platform in the tours and activities industry with...Full time$85k - $100k per year
...with curiosity, grit, and drive. If you’re passionate about security, compliance, and helping teams work smarter and safer, this is your... ...focus on application security, vulnerability management, and secure development practices across Checkfront and our sister brands....Full timeManual labor$110k - $140k per year
...work environment that empowers you to excel. Our Offensive Security professionals are on a mission to make the world a safer place,... ...development, and controlled initial access scenarios Conduct research and development to improve Kroll’s red team tooling, tradecraft,...Remote work- ...Description Job Title: Workday Reporting, Security & HRIS Analyst (Remote – Canada) Company: Canadian Forces Morale and Welfare Services... ..., Benefits, Recruiting, Finance, IT, and Audit teams to deliver secure and scalable Workday solutions Technical Expertise Core...Remote work
$120k - $150k per year
...tracking into one place, donor prospect research tools that offer proactive insights and real... .... You will work closely with our Staff Engineer and Director of Engineering to design... ...features, reconciliation, reliability, security, incident response, and multi-codebase work...- ...The Opportunity We're looking for a Staff Security Engineer to join Fullscript's Security Engineering... ...; Understands how to build secure, scalable solutions in production environments... ...penetration testing, security research, or ethical hacking activities. Experience...Long term contractFull timeRemote workFlexible hours
- ...in conducting all the following activities: supporting user research; creating user personas; developing prototypes; performing... ...Spoken and written English required. Government of Canada security clearance (Reliability) and former public sector work experience...Permanent employmentFull timeInternship1 day per week
- ...insights and presentation of actionable recommendations. Applying research ethics, data privacy, accessibility, and inclusive lenses to all... ...Spoken and written English required. Government of Canada security clearance (Reliability) and former public sector work experience...Permanent employmentFull timeInternship1 day per week
- ...insights and presentation of actionable recommendations. Applying research ethics, data privacy, accessibility, and inclusive lenses to all... ...Spoken and written English required. Government of Canada security clearance (Reliability) and former public sector work experience...Permanent employmentFull timeInternship1 day per week
- ...commercial, and air-gapped buyers have different objections, different security reviews, and different reasons to answer. Own sender... ...the primary domain. Build agents and systems that do account research at a volume no person can match. Wire LLM providers into the stack...Full time
- ...tax strategies that fit business objectives and provide maximum security with regulatory bodies. ~Maintain full compliance with regulatory... ...to ensure accurate, complete, and timely tax filings. ~Research and interpret new regulatory and tax reporting requirements and...Full timeInternshipRemote workWork from home
- ...for open source. By delivering hardened, secure, and production-ready builds of all the open... ..., Sequoia Capital, and Spark Capital. Staff Product Security Engineer The role... ...security projects. Background in security research or offensive security (bug bounty, CTF, penetration...Full timeLocal areaRemote workFlexible hours
- ...of public and private content includes equity research, company filings, event transcripts, expert calls... ...About the Role We’re looking for a Staff Product Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products spanning AI...Full timeInternshipLocal areaRemote work
$191.25k - $225k per year
...About the team + role The Offensive Security team at Robinhood is responsible for proactively... ...our customers and the company. As a Staff Offensive Security Engineer, you will... ...stakeholders. Conduct vulnerability research, exploit development, and testing using both...Full timeWork at officeShift work- ...making an impact. Contract Duration: ASAP to Dec 31, 2026 Security Clearance: Current Government of Canada Reliability or higher is... ...Acceptance Criteria Analyze insights and learnings from Generative Research to inform, evolve, and refine the target platform experience...Contract workInternshipImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Researcher. Be the first to apply!
