apPosture is a self-hosted ASPM platform with one non-negotiable rule: a finding is raised only when the engine can prove exploitation, with a captured request, response and read-only evidence. The exploitation engine is the heart of the product, and this role owns it.
You will be the attacker in the loop - the person who breaks real applications by hand, then turns that intuition into a deterministic engine that does it at scale. Your single most important job is to find where the engine is blind: run it against real targets, see where it misses a bug or over-claims one, and close the gap.
What you will do
- Build and sharpen the autonomous exploitation engine - deterministic, read-only oracles that confirm a vulnerability with in-band or differential proof, never a heuristic guess.
- Own web and API vulnerability classes end to end: SQL / NoSQL / OS-command / template / expression injection, SSRF (including cloud-metadata and blocklist-bypass variants), XXE, insecure deserialization and gadget chains (Java, .NET, Ruby, Node, PHP, Python), JWT and auth flaws, access control / IDOR / BOLA, GraphQL, request smuggling, prototype pollution, and Log4Shell / Spring4Shell-class RCE.
- Design LLM-steered exploitation loops where the model chooses the next payload or mutation but a deterministic adjudicator decides the verdict - the model may flag a false positive, but it can never upgrade a finding to confirmed.
- Build and integrate exploitation techniques and offensive tooling while keeping every probe safe: benign markers and nonces only, no data exfiltration, no destructive verbs.
- Maintain the oracle tables that keep false positives near zero - proof markers, injection error signatures, differential baselines, time-based and arithmetic oracles, and OAST callbacks.
- Extend the SAST to DAST to IAST correlation so a static source-to-sink prediction is proven reachable at runtime, and stitch confirmed vulnerabilities into multi-step attack chains.
- Continuously red-team our own engine against live targets, and turn every miss and every false positive into a regression test and a fix.
What we are looking for
- You can find and exploit web and API vulnerabilities by hand - in pentests, bug bounty, CTFs or CVE research - and you prove exploitation rather than assert it.
- Deep, practical command of the modern attack surface: injection in all its forms, SSRF and cloud metadata, deserialization and gadget chains, auth / JWT / session flaws, broken access control and IDOR / BOLA, XXE, request smuggling.
- Strong Python. You write clean, deterministic, well-tested engine code and are comfortable with async HTTP clients, HTTP internals, parsing and regex-based oracles.
- You think in proof and false-positive discipline: differential testing, error-, time- and arithmetic-based oracles, OAST, and a clear separation of reachable from proven.
- You are safe by instinct - authorized testing only, read-only probes, and zero interest in weaponizing anything.
Nice to have
- Public CVEs, security advisories, exploit write-ups, or offensive tools you have released.
- You have built or extended offensive security tooling - scanners, fuzzers, proxy extensions or exploit frameworks.
- Static analysis or taint tracking, or IAST / runtime instrumentation.
- LLM-in-the-loop systems, or agentic pipelines built with deterministic guardrails.
- Working knowledge of a second ecosystem for gadget and SAST work - Java, Go, .NET, Ruby, PHP or Node.
Think you are a fit?Send your CV plus anything that shows how you break things - CVEs, write-ups, tools, a HackTheBox/CTF profile.
Apply for this role
apPosture will never ask for payment or financial details during hiring. Every official message comes from an @apposture.com address.