Skip to content

Open nowPosted 7 hours ago

Security Researcher

Pi Security8 open roles

Where
San Francisco
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity ResearcherPi Security · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Pi Security's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Pi Security postings stay open a median of 14 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 7 hours ago

Pi Security median: 14 days open

The posting

LEAD SECURITY RESEARCHER

Pi.Security · San Francisco, CA · Full-time · Onsite, 5 days a week

ABOUT PI.SECURITY

Pi is building an agentic product security platform for teams that need to secure software at the speed they build it.

Modern development is accelerating, but security knowledge is still scattered across code, tickets, documents, incidents, reviews, and the people who remember why decisions were made. Pi turns that context into institutional security memory, helping teams triage faster, remediate in context, prevent repeat vulnerability classes, and embed security guardrails where engineering work already happens. We are building for a future where security is not a blocker at the end of the development process. It is part of how software gets designed, reviewed, shipped, and improved.

Pi was recognized on Fast Company's 2026 Next Big Things in Tech https://www.fastcompany.com/next-big-things-in-tech/list list and covered by Forbes https://www.forbes.com/sites/thomasbrewster/2026/06/10/elon-musk-favorite-hacker-launches-100-million-ai-cyber-startup/!

ABOUT THE ROLE

You will lead security research at Pi. This is not a bug hunting role. Your job is to invent the approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before a customer ever sees them.

You own the path from idea to shipped capability. You form the hypothesis, build the proof of concept, measure whether it actually works, and partner with engineering until it is in the product. You also own the quality bar: the benchmarks and evaluations that decide whether what we ship is good enough to put in front of customers.

You will set the research agenda, not just execute one. As the team grows, you will shape how research works here.

This role is based in our San Francisco office, five days a week. We build in person, alongside the founding team, and that is a deliberate choice.

WHAT YOU'LL DO

- The research agenda - Identify where new approaches can meaningfully beat the state of the art in vulnerability detection, triage, and remediation, then decide what we pursue and what we kill. No one hands you a backlog.

- Approaches that ship - Build proofs of concept for new detection and remediation techniques, validate them against real world code and data, and carry the winners through to production with engineering. You are accountable for ideas becoming product, not staying research.

- The quality bar - Design the datasets, benchmarks, and evaluation pipelines that measure precision, coverage, and false positive rates. Nothing reaches customers past a bar you have not signed off on, and if quality slips, you catch it first.

-

- Vulnerability depth - Deep research into modern attack vectors across cloud (AWS/GCP), containers, microservices, APIs, AI generated code, and LLM applications. Not just how vulnerabilities are found, but how they are born, how they are fixed, and how a whole class gets eliminated.

-

- The data foundation - The internal corpus of vulnerabilities, exploit patterns, and remediation strategies the platform learns from. Its depth and correctness are yours.

-

- Our research voice - What we publish, where we speak, and the credibility the company earns in the security community. Your work should be visible.

WHAT WE'RE LOOKING FOR

- Experience. 8+ years in security research, vulnerability analysis, or applied security engineering.

- Startup DNA. You have worked in an early stage or 0 to 1 environment. Comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.

- Research to product track record. You have turned research into things that shipped: features, tools, detections in production. Not just papers or reports.

- Technical depth. Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.

- Builder skills. Strong programming ability in at least one modern language (Python, Go, TypeScript). Comfortable writing production quality code.

- Data rigor. Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You do not ship on vibes.

- LLM fluency. Hands on experience applying LLMs to real problems, whether evaluation, prompting, fine tuning, or agentic systems, or a demonstrated ability to get there fast.

- Proven findings. A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.

- Communication. You can explain a complex attack and its real impact clearly to engineers, executives, and customers.

- Work authorization. Permanent authorization to work in the US for the San Francisco role, or in Israel for the Israel role.

- Willingness to work onsite in San Francisco five days a week

NICE TO HAVE

- Research that went public and mattered. Publications, disclosures, or talks that changed how people think about a problem, not just filled a slot at a conference.

- A product you built at a startup. Something that shipped, that real users depended on, where you can point at your fingerprints.

- Novel ways of putting LLMs or agents to work inside real engineering or security workflows, beyond demos and prompt wrappers.

- A healthy disrespect for "that's how we've always done it," and a track record of building the better way.

WHY PI

Pi is backed by a $35 million Series A led by Third Point Ventures and Brightmind Partners, with support from CrowdStrike CEO George Kurtz and Armis founders Yevgeny Dibrov and Nadir Izrael. Leading AI companies and enterprise innovators already rely on Pi, including xAI, Notion, Navan, Lemonade, and Teramind, and it's available through AWS Marketplace and a strategic partnership with Bugcrowd.

Our founders have lived inside this problem. Guy Arazi was a security researcher at Microsoft, and Yoni Ramon led offensive security work at Tesla. You'll work closely with both.

We're early enough that every hire shapes the product, the team, and how we work. You'll build alongside a humble, passionate, ambitious, and genuinely fun team that cares deeply about what we're building and about our customers.

We hire for four things, and we work this way every day:

- Speed. Velocity over polish. Something impactful this week beats a perfect plan for next quarter.

- Depth. You go past the point of requirement. That is usually where the interesting part starts anyway.

- Curiosity. The people who do best here ask the thing everyone assumed was already answered.

- Ambition. We take on assumptions this industry accepts as given, and disprove them.

COMPENSATION & BENEFITS

The base salary range for this role in San Francisco is $140,000 - $242,000 per year. This is our good-faith estimate of what we expect to pay at hire. Where an offer lands depends on experience, skills, and level. Base salary is one part of total compensation, which also includes equity.

- Meaningful equity in Pi.Security http://Pi.Security

- Medical, dental, and vision coverage for you and your family, starting the 1st of the month after you join.

- Flexible Spending Accounts (FSAs) for health and dependent care

- Commuter benefits

- Unlimited PTO

- 401(k)

- Health and wellness stipend

- Lunch allowance on in-office days

EQUAL OPPORTUNITY

Pi.Security http://Pi.Security is an equal opportunity employer. We welcome applicants of all backgrounds and are committed to building a diverse and inclusive team. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Pi Security's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Pi Security's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Pi Security's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.