Vulnerability Researcher
Listed on 2026-09-25
-
Security
Cybersecurity
Zealot () builds AI systems that find zero-days, emulate target devices, and develop working exploits for U.S. defense and intelligence customers. We’re backed by tier-1 U.S. venture firms and industry leaders, and our team includes alumni of Anthropic, xAI, NSA, USCYBERCOM, Anduril, Unit 8200, and the Mossad.
We’re looking for vulnerability researchers to help design and build our agentic systems that autonomously perform vulnerability research against real targets - firmware, network stacks, mobile OSes, IoT. That means wiring emulation (QEMU, Unicorn, Qiling), instrumentation (Frida, DynamoRIO), fuzzing, and exploit primitives into tool interfaces for agents, as well as the evaluation and benchmarking infrastructure to know whether any of it is working.
Whatwe’re looking for
- 2-3+ years across systems programming (C/C++, Rust) and ML infrastructure
- Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE)
- Hands-on work with agent harnesses - orchestration, tool-use, eval loops - in production or at benchmark scale
- Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE)
- Strong RE / debugger chops (GDB, IDA or Ghidra) and the patience to use them
Pwn-heavy CTF experience (DEF CON finals, PPP, Dice Gang, Shell phish, Theori, Team Atlanta), public CVEs, conference talks, AIxCC / CGC participation, or kernel / baseband RE.
Read this part carefullyThat list is what the fully-formed version of this role looks like. It’s not a filter. Tech can be learned. Spirit cannot. We’ve watched the right people pick up binary exploitation from scratch and outship ten-year veterans inside a year. Tell us what you’ve taught yourself recently and what you’d tear into first here.
RequirementsPrior Vulnerability Research experience, and willing to relocate to work in-person/hybrid in our New York City office.
What we offer- Competitive cash, meaningful early equity, a mission that matters, and hard problems nobody has solved yet.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).