We believe that software is the foundation of modern civilization, yet vulnerabilities threaten its integrity, security, and resilience. Strix is on a mission to solve security.
Strix builds autonomous AI penetration testing agents that think like attackers: discovering, validating, and helping fix real vulnerabilities across live applications, codebases, and infrastructure, continuously, not once a year. We are looking for strong technical people who want to work at the intersection of AI, security, and infrastructure.
About this roleWe're looking for a Security Researcher to push the frontier of what our AI agents can find. You will hunt for real vulnerabilities, turn your offensive-security expertise into agent skills, benchmarks, and detection strategies, and validate that Strix finds what matters in real-world targets.
You're excited about this role because you will…Discover and exploit vulnerabilities in web applications, APIs, cloud infrastructure, and open-source software
Encode offensive-security techniques into agent behaviors, tools, and playbooks that scale your expertise
Build and curate vulnerable environments and benchmarks that measure real agent capability
Analyze agent findings, separate signal from noise, and drive the false-positive rate toward zero
3+ years of hands-on offensive security experience (penetration testing, red teaming, bug bounty, or vulnerability research)
Deep understanding of web application security, exploitation techniques, and modern attack surfaces
Programming experience in Python or similar; comfort building your own tooling
CVEs, published research, CTF results, or a strong bug bounty track record are a plus
A tendency to leave things in a better way than you found them
Competitive salary with meaningful equity
Health, vision, and dental insurance
Office lunch and dinner (when working from our New York office)
Strix is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
To all recruitment agencies: Strix does not accept agency resumes. Please do not forward resumes to Strix employees. Strix is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.
Skills Required
- 3+ years of hands-on offensive security experience, including penetration testing, red teaming, bug bounty, or vulnerability research
- Deep understanding of web application security, exploitation techniques, and modern attack surfaces
- Programming experience in Python or a similar language, with the ability to build personal tooling
- CVEs, published research, CTF results, or a strong bug bounty track record
- Tendency to leave things in a better way than found
What We Do
Strix is an autonomous, AI-driven penetration-testing platform delivered as software-as-a-service. It helps security teams continuously secure their full technology stack by testing code, APIs, web applications, infrastructure, and cloud environments. The platform discovers vulnerabilities, validates exploitability with proof-of-concept evidence, prioritizes real impact, and can generate merge-ready fixes, while supporting self-hosted, on-premise, VPC, and air-gapped deployments before vulnerable changes reach production.



.jpeg)





