Founding Security Researcher

CodeWall

Greater London

Hybrid

GBP 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid London office
Equity or meaningful equity
Direct access to founders
Hands-on customer work
Competitive salary

Job summary

CodeWall in London is seeking a Security Researcher & Penetration Tester to lead real engagements, research vulnerabilities, attack our own platform and help turn expert tradecraft into scalable AI capabilities.

You’ll work directly with founders, engineers and customers, owning offensive methodology and product direction while shaping a security culture in an early-stage company with a hybrid London setup.

Qualifications

  • Significant professional experience in penetration testing, offensive security or vulnerability research.
  • Strong expertise in web application security, API security, application security or source-code review.
  • Ability to lead complex engagements independently and communicate findings clearly to technical and executive audiences.
  • Depth in at least one additional area, such as cloud security, internal networks, AD, CI/CD or software supply chains.
  • Excellent vulnerability analysis, problem-solving and attention to detail.

Responsibilities

  • Lead authorised penetration-testing engagements from scoping through execution, reporting and remediation.
  • Test web applications, APIs, cloud environments, enterprise infrastructure and AI systems.
  • Validate and triage findings produced by our agents, eliminating false positives and proving real-world impact.
  • Penetration-test CodeWall’s platform and infrastructure as our most demanding internal customer.
  • Conduct original vulnerability research across authorised targets and open-source software.
  • Define new attack techniques, testing strategies and benchmarks for our AI agents.
  • Convert your tools, techniques and intuition into capabilities that operate at scale.
  • Work directly with technical teams, security leaders and senior customer stakeholders.
  • Help establish a world-class offensive-security team and raise the bar for everyone around you.

Skills

Penetration testing
Web security
Vulnerability research
AI security
Cloud security

Job description

Security Researcher & Penetration Tester

Build the hackers that will shape cybersecurity

CodeWall is building autonomous offensive-security agents—AI systems that attack real environments, prove exploitability and produce findings security teams can act on.

We’ve raised $4 million in pre-seed funding—the largest ever for a UK cybersecurity startup—and our technology is already uncovering critical vulnerabilities in systems operated by sophisticated organisations.

Now we’re looking for an exceptional security researcher and penetration tester to help define what the world’s best AI hacker should be.

Come hack the planet with us.

The opportunity

This is not a role where you simply review scanner output.

You’ll lead real penetration tests, research vulnerabilities, attack our own platform and help turn expert human tradecraft into scalable AI capabilities. You’ll influence how our agents reason, chain attacks, validate findings and learn from failure.

As one of our first security hires, you’ll have genuine ownership of our offensive methodology, research agenda, product direction and security culture.

You’ll work directly with founders, engineers and customers—and help build the team around you.

What you’ll do
  • Lead authorised penetration-testing engagements from scoping through execution, reporting and remediation.
  • Test web applications, APIs, cloud environments, enterprise infrastructure and AI systems.
  • Validate and triage findings produced by our agents, eliminating false positives and proving real-world impact.
  • Penetration-test CodeWall’s platform and infrastructure as our most demanding internal customer.
  • Conduct original vulnerability research across authorised targets and open-source software.
  • Define new attack techniques, testing strategies and benchmarks for our AI agents.
  • Convert your tools, techniques and intuition into capabilities that operate at scale.
  • Work directly with technical teams, security leaders and senior customer stakeholders.
  • Help establish a world-class offensive-security team and raise the bar for everyone around you.
What we’re looking for
  • Significant professional experience in penetration testing, offensive security or vulnerability research.
  • Strong expertise in web application security, API security, application security or source-code review.
  • The ability to lead complex engagements independently and communicate findings clearly to both technical and executive audiences.
  • Depth in at least one additional area, such as cloud security, internal networks, Active Directory, CI/CD or software supply chains.
  • Excellent vulnerability analysis, problem-solving skills and attention to detail.
  • A practical understanding of how AI can improve offensive security—and where human judgement remains essential.
  • Curiosity, initiative and the confidence to operate in an early-stage company where you’ll help create the playbook.
Especially valuable
  • You build offensive-security tools, automation or research frameworks.
  • You have published CVEs or GHSAs, contributed to bug-bounty programmes or achieved strong results in CTFs.
  • You understand AI/ML security, LLM red teaming, prompt injection or agentic systems.
  • You can review code across multiple languages.
  • You’ve presented research, contributed to open source or earned recognition in the security community.
  • You’ve mentored, hired or developed other security practitioners.

We care more about how you think and what you can discover than ticking every box. If you’re not a perfect match on paper but believe you’d be dangerous here, we want to hear from you.

What we offer
  • A chance to shape the future of offensive security from the ground up.
  • Meaningful ownership as one of our earliest security hires.
  • Competitive salary and meaningful early-stage equity.
  • Direct access to founders and exceptional technical peers.
  • Hands-on work across real customer environments, original research and AI product development.
  • London office with a hybrid model: typically 3–4 days per week together.

Read our manifesto and research at codewall.ai.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Founding Offensive Security Researcher
Founding Offensive Security Researcher

CodeWall • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid London office
Equity or meaningful equity
Direct access to founders
+2
Software Engineer
Software Engineer

CodeWall • Greater London

Hybrid
GBP 120,000 - 180,000
Senior Software Engineer
Senior Software Engineer

CodeWall • Greater London

On-site
GBP 120,000 - 160,000
AI Vulnerability Research Engineer
AI Vulnerability Research Engineer

WatchTowr Pte. Ltd. • Greater London

Hybrid
GBP 50,000 - 70,000
Competitive compensation
Access to cutting-edge tools
Opportunities for internal promotion
Principal Penetration Tester
Principal Penetration Tester

Addition • Watford

Hybrid
GBP 100,000 - 140,000
Hybrid working
Company bonus scheme
Matched pension contributions 8.5%
+4
Founding Security Researcher
Founding Security Researcher

Refractal • Greater London

On-site
GBP 90,000 - 140,000
Equity (founding)
Performance bonus
UK visa sponsorship
Founding Senior Software Engineer – AI Security Platform
Founding Senior Software Engineer – AI Security Platform

CodeWall • Greater London

On-site
GBP 120,000 - 160,000
Engineering Lead, Cyber Engineering
Engineering Lead, Cyber Engineering

WatchTowr Pte. Ltd. • Greater London

On-site
GBP 70,000 - 90,000
Competitive compensation
Meaningful role in a growing business
Access to advanced tools
+2
AI Security Engineer
AI Security Engineer

InfoSec People Ltd • United Kingdom

Remote
GBP 90,000 - 125,000
Remote work
Penetration Tester
Penetration Tester

Barlowe LLP • Greater London

On-site
GBP 90,000 - 130,000
Discretionary bonus
Lunch via Just Eat for Business
35 days annual leave
+5