Startups · AI

Security Researcher - Offensive Security

GhostEye · New York, NY, US · On-site

← All jobs
About GhostEye

Your always-on red team. Backed by Y Combinator.

About the role

GhostEye’s product is only as good as the attacks it can emulate. As our Lead Security Researcher, you will study how real adversaries move from human manipulation to technical compromise. Your research will span phishing, vishing, smishing, pretexting, deepfakes, penetration testing, identity attacks, endpoint tradecraft, and EDR evasion.

What they're looking for

  • A demonstrated history of building offensive-security tools, attack simulations, adversary-emulation capabilities, or penetration-testing infrastructure
  • Hands-on understanding of how attackers move from social engineering and initial access into endpoint execution and post-compromise activity
  • Experience researching endpoint tradecraft, EDR behavior, defensive telemetry, or security-control effectiveness
  • Strong programming and automation ability in Python, PowerShell, C, C++, C#, Go, Rust, or another relevant language
  • Familiarity with MITRE ATT&CK, OSINT, adversary-emulation methodologies, and common offensive-security tooling
  • Evidence of technical leadership through setting direction, leading projects, reviewing technical work, or mentoring engineers and researchers
More about this role

Most security programs answer whether a company appears compliant. GhostEye answers a harder question: could a real attacker get in today?

Our founder previously led red-team operations at BlackRock and conducted offensive cyber operations at MITRE. Through that work, he saw how quickly adversaries adapt and how often traditional security programs fail to test the complete attack chain, particularly when the initial access vector is a person.

GhostEye was built to close that gap. We are building the always-on red team for modern enterprises. Our platform emulates the attacks adversaries use today, including help-desk vishing, deepfaked executives, MFA fatigue, identity compromise, and the technical payloads that follow.

We identify what is actually exploitable, help customers close the gaps, and retest until the fixes hold. Our team brings together offensive-security research, AI, and engineering to turn real attacker tradecraft into repeatable security validation.

GhostEye’s product is only as good as the attacks it can emulate.

As our Lead Security Researcher, you will study how real adversaries move from human manipulation to technical compromise. Your research will span...

Read the full posting on GhostEye's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.