← All open positions

Security Researcher (Autonomous Pentest)

Security EngineeringBaku, Azerbaijan / RemoteFull-time

apPosture is a self-hosted ASPM platform with one non-negotiable rule: a finding is raised only when the engine can prove exploitation, with a captured request, response and read-only evidence. The exploitation engine is the heart of the product, and this role owns it.

You will be the attacker in the loop - the person who breaks real applications by hand, then turns that intuition into a deterministic engine that does it at scale. Your single most important job is to find where the engine is blind: run it against real targets, see where it misses a bug or over-claims one, and close the gap.

What you will do

  • Build and sharpen the autonomous exploitation engine - deterministic, read-only oracles that confirm a vulnerability with in-band or differential proof, never a heuristic guess.
  • Own web and API vulnerability classes end to end: SQL / NoSQL / OS-command / template / expression injection, SSRF (including cloud-metadata and blocklist-bypass variants), XXE, insecure deserialization and gadget chains (Java, .NET, Ruby, Node, PHP, Python), JWT and auth flaws, access control / IDOR / BOLA, GraphQL, request smuggling, prototype pollution, and Log4Shell / Spring4Shell-class RCE.
  • Design LLM-steered exploitation loops where the model chooses the next payload or mutation but a deterministic adjudicator decides the verdict - the model may flag a false positive, but it can never upgrade a finding to confirmed.
  • Build and integrate exploitation techniques and offensive tooling while keeping every probe safe: benign markers and nonces only, no data exfiltration, no destructive verbs.
  • Maintain the oracle tables that keep false positives near zero - proof markers, injection error signatures, differential baselines, time-based and arithmetic oracles, and OAST callbacks.
  • Extend the SAST to DAST to IAST correlation so a static source-to-sink prediction is proven reachable at runtime, and stitch confirmed vulnerabilities into multi-step attack chains.
  • Continuously red-team our own engine against live targets, and turn every miss and every false positive into a regression test and a fix.

What we are looking for

  • You can find and exploit web and API vulnerabilities by hand - in pentests, bug bounty, CTFs or CVE research - and you prove exploitation rather than assert it.
  • Deep, practical command of the modern attack surface: injection in all its forms, SSRF and cloud metadata, deserialization and gadget chains, auth / JWT / session flaws, broken access control and IDOR / BOLA, XXE, request smuggling.
  • Strong Python. You write clean, deterministic, well-tested engine code and are comfortable with async HTTP clients, HTTP internals, parsing and regex-based oracles.
  • You think in proof and false-positive discipline: differential testing, error-, time- and arithmetic-based oracles, OAST, and a clear separation of reachable from proven.
  • You are safe by instinct - authorized testing only, read-only probes, and zero interest in weaponizing anything.

Nice to have

  • Public CVEs, security advisories, exploit write-ups, or offensive tools you have released.
  • You have built or extended offensive security tooling - scanners, fuzzers, proxy extensions or exploit frameworks.
  • Static analysis or taint tracking, or IAST / runtime instrumentation.
  • LLM-in-the-loop systems, or agentic pipelines built with deterministic guardrails.
  • Working knowledge of a second ecosystem for gadget and SAST work - Java, Go, .NET, Ruby, PHP or Node.
Think you are a fit?

Send your CV plus anything that shows how you break things - CVEs, write-ups, tools, a HackTheBox/CTF profile.

Apply for this role

apPosture will never ask for payment or financial details during hiring. Every official message comes from an @apposture.com address.