Security Researcher
Find the vulnerabilities that matter in hospitals before attackers do, and turn them into things our agents can enforce.
Why this role exists
Healthcare is attacked differently. The devices are old, the networks are flat, the protocols predate the web, and nobody can take an MRI offline for a patch window. Our agents are only as good as what we know about that world. We publish original research, we have watched a zero-day go from disclosure to protection in under an hour, and we monitor hundreds of thousands of connected medical devices. We need one more person whose whole job is finding what we do not know yet.
What you'll be doing
- Research the systems hospitals actually run: clinical networks, imaging and lab equipment, the vendor middleware nobody remembers installing, and the identity systems that tie them together.
- Find vulnerabilities, disclose them responsibly, and turn each one into a detection or a validation our agents run for every customer.
- Reproduce real incidents. When a hospital is breached, we write up how it happened from the inside; you will lead those write-ups.
- Publish. Our research blog is a large part of how customers find us, and you will put your name on the work.
- Sit with the engineers who build the agents so what you find becomes product within days, not quarters.
How we work
We are a small team and everything we claim is backed by something you can check: a proof of concept, a timeline, a diff. We publish what we find, we credit people, and we do not sit on findings for marketing timing. We are remote-first with a few hours of overlap with Tel Aviv.
What we need from you
- A track record you can point at: CVEs, disclosures, published research or bounty work.
- Comfort with protocols and binaries, not only web applications.
- You write clearly. Half of this job is explaining a finding to a hospital CISO who has ten minutes.
- Experience with medical devices or clinical protocols is a strong plus, not a requirement.
How hiring works
Apply with the form on this page; a resume and a few lines on why this role are enough. If it looks like a fit, you talk to the hiring manager, then spend a paid working session on a real problem from our backlog, then meet one of the founders. We tell you where you stand at each step, and the whole process takes two to three weeks.