SECTION I · THE BRIEF
Brief #14976Updated 04 SEP 2026NEW YORKAshbyANDREESSEN HOROWITZ
Employbl Company Profile

Security Researcher

Strix is an open-source AI security platform that uses autonomous agents to continuously pentest applications, APIs, and codebases.

Location
New York
Company size
1–10
Posted
Today
Via
Ashby
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Strix logo

Security Researcher · Strix

View company profile
Job title
Security Researcher
Job location
New York
Job description

About Strix

We believe that software is the foundation of modern civilization, yet vulnerabilities threaten its integrity, security, and resilience. Strix is on a mission to solve security.

Strix builds autonomous AI penetration testing agents that think like attackers: discovering, validating, and helping fix real vulnerabilities across live applications, codebases, and infrastructure, continuously, not once a year. We are looking for strong technical people who want to work at the intersection of AI, security, and infrastructure.

About this role

We're looking for a Security Researcher to push the frontier of what our AI agents can find. You will hunt for real vulnerabilities, turn your offensive-security expertise into agent skills, benchmarks, and detection strategies, and validate that Strix finds what matters in real-world targets.

You're excited about this role because you will…

  • Discover and exploit vulnerabilities in web applications, APIs, cloud infrastructure, and open-source software

  • Encode offensive-security techniques into agent behaviors, tools, and playbooks that scale your expertise

  • Build and curate vulnerable environments and benchmarks that measure real agent capability

  • Analyze agent findings, separate signal from noise, and drive the false-positive rate toward zero

Qualifications

  • 3+ years of hands-on offensive security experience (penetration testing, red teaming, bug bounty, or vulnerability research)

  • Deep understanding of web application security, exploitation techniques, and modern attack surfaces

  • Programming experience in Python or similar; comfort building your own tooling

  • CVEs, published research, CTF results, or a strong bug bounty track record are a plus

  • A tendency to leave things in a better way than you found them

What we offer

  • Competitive salary with meaningful equity

  • Health, vision, and dental insurance

  • Office lunch and dinner (when working from our New York office)

Strix is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

To all recruitment agencies: Strix does not accept agency resumes. Please do not forward resumes to Strix employees. Strix is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Strix headquarters

San Francisco, CA

Company size

110 employees

Founded

2025

Total raised

$6,700,000

View company profile ↗

Funding rounds