Member of Technical Staff, Vulnerability Researcher | $7-$8/hr Remote
Overview
micro1 is looking for a Vulnerability Researcher to act as the company's internal adversary — probing AI systems, cloud infrastructure, and developer platforms for weaknesses before attackers find them. You'll collaborate closely with engineering teams to harden defenses and shape long-term security strategy. This fully remote role offers a chance to work at the intersection of offensive security and cutting-edge AI.
What You'll Do9
- 1Perform advanced offensive security research across cloud environments like AWS and GCP, production services, internal tools, and AI platforms, identifying novel attack paths.
- 2Design and run realistic adversary simulations targeting identity systems, cloud control planes, supply chains, and distributed architectures to test resilience.
- 3Uncover vulnerabilities in proprietary applications, APIs, infrastructure-as-code, CI/CD pipelines, and AI-powered developer workflows using manual and automated techniques.
- 4Investigate emerging attack vectors against LLMs, AI agents, retrieval systems, MCP integrations, and autonomous workflows — including prompt injection, tool abuse, and jailbreaks.
- 5Reverse-engineer critical services to reveal architectural flaws and develop novel exploitation techniques that go beyond known vulnerability classes.
- 6Simulate insider threats and advanced persistent threat scenarios, testing privilege escalation, lateral movement, and defense evasion across enterprise environments.
- 7Build custom offensive tooling, automation frameworks, fuzzers, and proof-of-concept exploits to accelerate vulnerability discovery.
- 8Partner with infrastructure, product, and AI engineering teams to validate fixes, promote secure-by-design practices, and raise the overall security bar.
- 9Document attack methodologies and publish internal research to help shape the company's long-term security roadmap.
Requirements8
- 1Proven hands-on experience in offensive security, vulnerability research, red teaming, or exploit development.
- 2Deep understanding of cloud security across AWS and GCP, including IAM, networking, Kubernetes, containers, and identity systems.
- 3Strong background in application security, code auditing, reverse engineering, and vulnerability discovery across modern stacks.
- 4Experience identifying weaknesses in software supply chains, CI/CD systems, APIs, and infrastructure automation.
- 5Proficiency in Python, Go, Rust, C/C++, or similar languages used for security research and tooling.
- 6Solid grasp of operating system internals, networking protocols, authentication mechanisms, and modern security architectures.
- 7Ability to independently investigate ambiguous problems and develop novel attack techniques with minimal supervision.
- 8Excellent written communication skills to clearly explain complex vulnerabilities to engineering teams and stakeholders.
Who Should Apply
This role is for a security researcher who thinks like an attacker — someone who enjoys breaking things, finding creative exploit paths, and pushing the boundaries of what's possible. You're comfortable with both deep technical work (reverse engineering, fuzzing, exploit development) and collaborating with engineers to fix what you find. If you have a passion for AI/LLM security and want to shape the defenses of next-generation software, this is your opportunity.
Salary Insight
Base salary ranges from $200,000 to $250,000 per year for this full-time remote position. You'll also be eligible for equity compensation and performance-based bonuses. Benefits include up to 100% reimbursement for health-insurance premiums, paid time off, and a 401(K) plan with company match.
Required Skills
Application Tip
When applying, include a brief write-up of one or two of your most challenging vulnerability discoveries — even if they're unpublished or from bug bounty programs. Concrete examples of unique attack techniques you've developed will immediately demonstrate your research mindset.
Similar open positions
Explore active roles that match your skills and interests.
Micro1
VerifiedRed Team Lead (Offensive Cybersecurity) | $50-$90/hr Remote
This remote contractor role with micro1 puts your offensive cybersecurity expertise to work in a unique way: you'll help train next-generation AI systems by designing evaluation frameworks and attack simulations. No prior AI experience is required—your hands-on knowledge of exploit chains, cloud/appsec, and social engineering is what makes you the ideal candidate. You'll shape how models learn about real-world threats while operating under strict ethical boundaries.
Micro1
VerifiedPenetration Tester | $25-$80/hr Remote
micro1 is looking for an experienced penetration tester to contribute your security expertise to the development of next-generation AI systems. You won't need an AI background — your hands-on knowledge of ethical hacking and vulnerability assessment is exactly what's needed to help train smarter models. This is a remote contract opportunity paying $25–$80 per hour.
Mercor
VerifiedCybersecurity Experts | $70-$90/hr Remote
Mercor is teaming up with a premier AI research lab to recruit seasoned cybersecurity professionals for a short-term, high-impact project. In this role, you'll leverage your expertise in low-level systems programming and security vulnerability classification to help train AI models in threat detection and reasoning. The engagement starts with a paid work trial and could extend into a roughly two-month project, all fully remote.
Micro1
VerifiedProduct Security Engineer | $400k/yr Remote
This is a chance to shape the future of security engineering at a company building AI-native systems. As a Product Security Engineer, you'll design autonomous security platforms that use machine learning and large language models to find and fix vulnerabilities at scale. You'll work remotely with a team that values deep technical expertise and a proactive approach to securing modern software and AI workloads.
Micro1
VerifiedCyber Security Analyst | $20-$80/hr Remote
This role lets you put your cybersecurity expertise to work in a unique way—helping train next-generation AI systems. You won't need any prior AI experience; your domain knowledge in security is what counts. As a part-time, remote contractor, you'll test and guide AI models through hands-on prompts and analysis.
Micro1
VerifiedAI Jailbreak & Prompt-Injection Security Expert | $50-$90/hr Remote
micro1 is looking for a contractor to join a forward-thinking client project focused on hardening AI systems against exploitation. Your mission: design creative adversarial tests—think ethical jailbreaks, prompt injection, and tool-use abuse—to uncover weaknesses in modern LLMs. No deep AI background is required; your hands-on security expertise and adversarial mindset are what count.