- Break systems built to resist you. Compromise designs and production software whose authors had a proof assistant on their side, and demonstrate it with a working exploit rather than a written argument.
- Map the real attack surface of a proof. Establish the formal property, the level it holds, the threat model behind it, and the underlying assumptions, then show the client which of those give way under pressure.
- Build the tooling that decides your coverage. Design and extend the AI-driven discovery and triage systems that determine how much of a target a single engineer can reach within a short window.
- Write the assessment that becomes the record. Set out what held, what did not, and what you attempted without success, clearly enough that the result stands up to the product developers.
- Raise the practice around you. Publish tooling and methodology, write for the blog, present internally, and pull what one engagement learns into the next.
What You’ll Bring
- Red teaming. Direct experience with red teaming production software, personally responsible for finding and proving exploitable vulnerabilities. Hands-on offensive work, not exercise coordination or scanner triage.
- Building AI tools that find bugs. Experience building AI-driven tooling for vulnerability discovery, such as agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation. You have written this tooling, not only used someone else’s.
- Formal methods. Experience applying formal methods to system designs and code implementations, including reading specifications and proof artifacts and reasoning about what a machine-checked proof does and does not establish. You can read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust.
- Depth in a systems domain. Experience finding vulnerabilities in network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure.
- Software development. Experience in Python, C++, and/or Rust.
- Written findings for expert readers. Experience producing security assessment reports for an audience that will scrutinize every claim.
- Delivery to a fixed external schedule with defined acceptance criteria.
- Vulnerability Disclosure. Experience in the ethical reporting of vulnerabilities in technology.
Preferred Qualifications
- Published vulnerability research: CVEs, advisories, or talks at venues like OffensiveCon, RECon, CCC, or USENIX Security.
- Experience auditing or contributing to a formally verified codebase such as HACL*, EverCrypt, seL4, CompCert, or CakeML.
- Experience building automated bug-finding infrastructure at scale: cyber reasoning systems, fuzzing fleets, or symbolic execution engines.
- Experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling.
- Experience attacking AI inference infrastructure: weight confidentiality and integrity, tenant isolation, or output mediation.
- Participation in CTF competitions, Pwn2Own, DARPA’s AI Cyber Challenge, or similar.
- Experience with compiler technology, program analysis, or binary analysis.
- Experience in reading, writing, and publishing academic papers.
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#FintechCareersGCC
#GCCFintechJobs
#TechOpportunitiesGCC
#FinanceTechGulf
#GCCJobSearch
#FintechOpportunities
#GulfCareerHub
#TechJobsGCC
#FintechGCC
#CareerInFinanceGCC