Security Researcher

PI Security LLC

San Francisco (CA)

On-site

USD 150,000 - 260,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

PI Security LLC is seeking a Lead Security Researcher to head security research in San Francisco or Israel. This is a full-time onsite role focused on inventing novel, production-ready approaches to detect, triage, and remediate vulnerabilities using LLMs and program analysis.

You will own the research agenda, establish proofs of concept, and drive them through to production with engineering. You’ll define benchmarks, ensure quality, and help the company translate research into a scalable

Qualifications

  • 8+ years in security research or related field.
  • Startup environments, 0→1 mindset and ambiguity handling.
  • Track record turning research into shipped features or tools.
  • Deep knowledge of modern stacks (microservices, containers, cloud).
  • Proficiency in Python, Go or TypeScript across production code.
  • Ability to design experiments, datasets, and benchmarks.
  • Hands-on experience applying LLMs to real problems.
  • Proven vulnerabilities research with responsible disclosure.
  • Strong communication to engineers, executives, and customers.
  • US or Israel work authorization.

Responsibilities

  • Lead security research and invent novel approaches that become product capabilities.
  • Own the path from idea to shipped capability: hypothesis, POC, measurement, and production handoff.
  • Define datasets, benchmarks, and evaluation pipelines to ensure quality to customers.
  • Set and evolve the research agenda as the team grows.

Skills

Security research
Startup experience
Research-to-product
System design
Python
Go
TypeScript
Data analysis
LLM technology
Communication
US/Israel work authorization

Job description

Lead Security Researcher

Location: San Francisco, CA or Israel Type: Full-time, onsite

About Us

We are a well-funded security startup in San Francisco, founded by the teams who led Microsoft's vulnerability mitigation efforts and Tesla's offensive research. (If still in stealth, keep this line as-is; if launched, name Pi and use the standard boilerplate.)

We're building a platform that changes how companies handle security vulnerabilities — not by finding more of them, but by understanding them deeply enough to fix them at the root and keep whole classes from coming back. The hard problems behind that — what to detect, how to prove a finding is real, how to remediate the way a senior engineer would — are research problems. That's where you come in.

The Role

You will lead security research at the company. This is not a bug-hunting role. Your job is to invent the novel approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before customers ever see them.

You own the path from idea to shipped capability — forming the hypothesis, building the proof of concept, measuring whether it actually works, and partnering with engineering until it's in the product. You also own the quality bar: the benchmarks and evaluations that decide whether what we ship is good enough to put in front of customers.

You'll set the research agenda, not just execute one. As the team grows, you'll shape how research works here.

What You'll Own
  • The research agenda. Identify where novel approaches can meaningfully beat the state of the art in vulnerability detection, triage, and remediation — and decide what we pursue and what we kill. No one hands you a backlog.
  • Novel approaches, proven and shipped. Build proofs of concept for new detection and remediation techniques, validate them against real-world code and data, and carry the winners through to production with engineering. You're accountable for ideas becoming product, not staying research.
  • The quality bar. Design the datasets, benchmarks, and evaluation pipelines that measure precision, coverage, and false-positive rates. Nothing reaches customers past a bar you haven't signed off on — and if quality slips, you catch it first.
  • Vulnerability depth. Deep research into modern attack vectors across cloud (AWS/GCP), containers, microservices, APIs, AI-generated code, and LLM applications — not just how vulnerabilities are found, but how they're born, how they're fixed, and how a whole class gets eliminated.
  • The data foundation. The internal corpus of vulnerabilities, exploit patterns, and remediation strategies the platform learns from. Its depth and correctness are yours.
  • Our research voice. What we publish, where we speak, and the credibility the company earns in the security community. Your work should be visible.
What We're Looking For
  • Experience: 8+ years in security research, vulnerability analysis, or applied security engineering.
  • Startup DNA: You've worked in an early-stage or 0→1 environment — comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.
  • Research-to-product track record: You've turned research into things that shipped — features, tools, detections in production — not just papers or reports.
  • Technical depth: Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.
  • Builder skills: Strong programming ability in at least one modern language (Python, Go, TypeScript, etc.). Comfortable writing production-quality code.
  • Data rigor: Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You don't ship on vibes.
  • LLM fluency: Hands-on experience applying LLMs to real problems — evaluation, prompting, fine-tuning, or agentic systems — or a demonstrated ability to get there fast.
  • Proven findings: A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.
  • Communication: You can explain a complex attack and its real impact clearly to engineers, executives, and customers.
  • Work authorization: Permanent authorization to work in the US (for the San Francisco role) or in Israel (for the Israel role).
Bonus Points

We care about impact, not credentials. Things that get our attention:

  • Research that went public and mattered — publications, disclosures, or talks that changed how people think about a problem, not just filled a slot at a conference.
  • A product you built at a startup — something that shipped, that real users depended on, where you can point at your fingerprints.
  • Innovation around AI and workflows — novel ways of putting LLMs or agents to work inside real engineering or security workflows, beyond demos and prompt wrappers.
  • A healthy disrespect for "that's how we've always done it" — and a track record of actually building the better way.
Why Join

You'll define the research direction of a company at the stage where one person's ideas still shape the product. The team comes from top-tier security organizations, the funding is in place, and the problems are real: vulnerability management is broken in ways everyone in the industry can see and almost no one is positioned to fix. If you want your research to ship and to matter, we'd like to talk.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Researcher: AI-Driven Vulnerability Remediation
Lead Security Researcher: AI-Driven Vulnerability Remediation

PI Security LLC • San Francisco (CA)

On-site
USD 150,000 - 260,000
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic • United States

On-site
USD 140,000 - 200,000
Security Researcher
Security Researcher

QUORE IT : Talent Sourcing & Recruitment • New York (NY)

Hybrid
USD 250,000 - 300,000
Relocation support
Equity package
Security Researcher
Security Researcher

Aikido Security • United States

On-site
USD 110,000 - 150,000
Competitive salary package
Flexibility in working hours
Open and informal atmosphere
Security Research Engineer
Security Research Engineer

Runsybil • New York (NY)

Hybrid
USD 120,000 - 170,000
Equity options
Excellent health plans
Unlimited PTO
Senior Vulnerability Researcher
Senior Vulnerability Researcher

Research Innovations Inc • Saint Petersburg (FL)

On-site
USD 110,000 - 140,000
Senior Security Researcher
Senior Security Researcher

Ladders • United States

On-site
USD 120,000 - 150,000
Equity options
401(k) plan
Medical, dental, vision, and life ins.
+4
Staff Threat Researcher
Staff Threat Researcher

Illumio • San Jose (CA)

On-site
USD 120,000 - 150,000
Vulnerability Researcher
Vulnerability Researcher

Snatch UP Jobs • Miami (NM)

On-site
USD 140,000 - 180,000
AI security researcher
AI security researcher

0Labs • San Francisco (CA)

Hybrid
USD 140,000 - 210,000
Competitive compensation
Flexible work setup
Remote or hybrid work
+6