RunSybil is an autonomous offensive security solution. Find exploitable vulnerabilities before a breach, eliminate noise, and remediate at enterprise scale. Backed by Menlo and Conviction.
About the role
We are looking for a Security Analyst to join our security research team. You will work hands-on with web application vulnerabilities every day, assessing findings, confirming exploitability, rating severity, and delivering clear, accurate reports that customers rely on to understand and remediate their risk.
What they're looking for
- 2 or more years of hands-on experience with web application vulnerabilities through bug bounty, penetration testing, application security, or a similar role
- Solid, practical understanding of OWASP Top 10 and common web vulnerability classes: you have actually found and confirmed these, not just read about them
- Experience reproducing and validating findings manually, including in ambiguous or noisy environments
- Comfort with tools like Burp Suite, browser developer tools, or similar for hands-on verification
- Strong written communication: you can describe a vulnerability, its impact, and how to fix it in plain language
- Attention to detail and consistency: you apply the same standard to the hundredth finding that you applied to the first
More about this role
Founded in 2023 by Ari Herbert-Voss and Vlad Ionescu, RunSybil is on a mission to automate hacker intuition. We are building Sybil, an AI-driven pentester that discovers vulnerabilities before they are exploited. As adversaries adopt AI to expand their attack surface, we are putting cutting-edge offensive security into the hands of defenders. Backed by strong investor support and early customer traction, our team includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.
We are looking for a Security Analyst to join our security research team. You will work hands-on with web application vulnerabilities every day, assessing findings, confirming exploitability, rating severity, and delivering clear, accurate reports that customers rely on to understand and remediate their risk.
This role does not require software engineering experience. It requires deep familiarity with web vulnerabilities, sharp analytical judgment, and the ability to communicate findings precisely. If you have spent time in bug bounty, application security, or pentesting and have a strong eye for what is real and what is noise, we want to hear from you.
What You Will Do
Assess and...
Browse similar: AI jobs · AI startup jobs · Startup jobs · Remote jobs