The company is building production AI systems that automate cyber network operations end-to-end. It is already live with a paying customer and running pilots across the US, Europe, and APAC. Headquarters are in Washington DC, with auxiliary offices in Tel Aviv and London.
We are hiring Vulnerability Research Engineers to build systems for AI-driven vulnerability research and exploit development. This is not a prompt-engineering role. The work is low-level, technical, and close to the metal. You will help build systems that identify, analyze, reproduce, and scale vulnerability research workflows across real software and real environments. We are primarily looking for vulnerability researchers with strong low-level systems skills, reverse-engineering ability, and exploitation instincts. Exceptional low-level systems engineers with deep security-adjacent experience may also be considered.
What You’ll Own:
- Build production systems for AI-driven vulnerability research and exploit development.
- Develop tooling for vulnerability discovery, triage, reproduction, and validation at scale.
- Work across OS internals, binaries, runtimes, kernels, dynamic analysis, instrumentation, and low-level performance.
- Partner with vulnerability researchers, security operators, and engineers to automate manual cyber workflows.
- Own problems end-to-end, from research and design to shipped production code.
Requirements:
- 2+ years of vulnerability research, offensive security, or low-level engineering experience. Exceptional new grads with strong CTF, systems, or exploitation work will be considered.
- Hands-on experience with reverse engineering, binary analysis, exploit development, fuzzing, dynamic analysis, bug hunting, CTFs, or comparable low-level security work.
- Deep low-level systems fluency, including OS internals, kernels, runtimes, memory corruption, debugging, dynamic instrumentation, or performance-sensitive systems.
- Strong builder mindset and ability to ship reliable tools and production systems.
- Comfortable working in ambiguity and moving fast.
- Willing to relocate to Washington DC after an initial period, with full relocation support. The role is expected to be in-office 5 days per week.
Nice to Have:
- Strong CTF background, especially pwn, rev, kernel, browser, or systems-heavy challenges.
- Published vulnerability research, CVEs, exploit writeups, or security talks.
- Experience with fuzzing, symbolic execution, emulation, program analysis, or binary rewriting.
- Open-source contributions to low-level security, reversing, debugging, tracing, fuzzing, or OS tooling.
- Exposure to ML / AI systems, especially applied to code, binaries, security automation, or program analysis.
- Early-stage startup, founder, or early-engineer experience.
What We Look For:
- Strong vulnerability research instincts.
- Low-level technical depth.
- Builder mindset — able to turn research workflows into scalable systems.
- Comfort with ambiguity, speed, and high ownership.
- Motivation to help build a category-defining company in AI-native offensive cyber.
Skills Required
- 2+ years of vulnerability research, offensive security, or low-level engineering experience
- Hands-on experience with reverse engineering, binary analysis, exploit development, fuzzing, dynamic analysis, or bug hunting
- Deep low-level systems fluency (OS internals, kernels, runtimes, memory corruption, debugging, dynamic instrumentation, performance-sensitive systems)
- Strong builder mindset and ability to ship reliable tools and production systems
- Comfortable working in ambiguity and moving fast
- Willing to relocate to Washington DC after an initial period; role expected in-office 5 days per week (relocation support provided)
- Exceptional new grads with strong CTF, systems, or exploitation work will be considered
- Published vulnerability research, CVEs, exploit writeups, or security talks
- Experience with symbolic execution, emulation, program analysis, or binary rewriting
- Open-source contributions to low-level security, reversing, debugging, tracing, fuzzing, or OS tooling
- Exposure to ML/AI systems applied to code, binaries, or security automation
- Early-stage startup, founder, or early-engineer experience
What We Do
Commit is a global tech services company with offices in Israel, US, Canada, UK, and Europe. The company was founded in 2005 and has over 700 multi-disciplinary innovation experts who serve a broad range of companies, from small startups to large enterprises in multiple business sectors. Commit specializes in advanced technologies and applications with dedicated practices in Cloud, GenAI, Software, IoT, Big Data, Cyber, Collaboration, Data center migration projects, and more. Commit offers innovative, end-to-end technology solutions by developing custom software and IoT platforms for clients looking to build their next-gen products within the modern ICT world. Commit’s complete and comprehensive engineering powerhouse of resources, and proprietary Flexible R&D methodology helps transform its clients’ technology visions into high-quality products while reducing costs and improving time-to-market.









