davidjoseph-co
New

Zealot — Vulnerability Researcher

United StatesUnited States·New Yorkmid
OtherVulnerability Researcher
2 views0 saves0 applied

Quick Summary

Key Responsibilities

C / C++ / Rust; GDB, IDA, Ghidra; QEMU, Unicorn, Qiling, PANDA, FirmAE; Frida, DynamoRIO; Linux (kernel internals, system-level debugging); fuzzing pipelines; modern mitigations (ASLR, CFI, PAC,

Technical Tools
OtherVulnerability Researcher

Type: Full-time | On-site | New York City, NY Compensation: $220,000–$350,000 + Competitive Equity Hiring count: 2 Visa sponsorship: None Available. US citizen or clearance-eligible preferred; foreign nationals from countries Zealot Labs does not sell to cannot be considered. Reports to: R&D team, led by Ilya (~8 engineers). Intro call with Oliver.

Zealot Labs builds AI systems that autonomously perform vulnerability research against real targets, collapsing a manual process that once took roughly six months into a matter of days using coordinated agents. It sells exclusively to governments — paying clients include the CIA and the German federal law enforcement agency — and is backed by tier-1 US venture firms. The team is approaching 20 people and scaling toward 30, with alumni from Anthropic, xAI, NSA, USCYBERCOM, and Anduril.

Founded: 2025 | Team size: ~11–50 (approaching 20) | Total funding: Not disclosed (tier-1 US VC-backed) Industry: Security / Offensive Cyber Website: zealotlabs.com Office: New York City, NY

  • Frontier mission: Build AI agents that autonomously run offensive vulnerability research against real firmware, network stacks, mobile OSes, and IoT — compressing six months of manual work into days.
  • Elite team: Alumni from Anthropic, xAI, NSA, USCYBERCOM, and Anduril; R&D led by Ilya.
  • Real customers, real stakes: Government clients, tier-1 US VC backing, seed stage with meaningful equity upside.
  • Deeply technical, low-level work at the intersection of offensive security and AI agent infrastructure — not a side capacity.
  • An intake video is present on the Contrario role page but was not transcribed — no text intake summary is available. If you share a transcript or notes, I'll fold the key points in here.

Zealot Labs is hiring multiple Vulnerability Researchers to help design and build agentic systems that autonomously hack into real targets across firmware, network stacks, mobile operating systems, and IoT. Deeply technical, low-level work wiring emulation, instrumentation, fuzzing, and exploit primitives into tool interfaces that agents can operate. Vulnerability research must be the central, primary function of the day-to-day — not a secondary responsibility.

Responsibilities

~1 min read
  • Own vulnerability discovery end-to-end against real firmware, network stacks, mobile OSes, and IoT targets using emulation stacks, instrumentation, and fuzzing pipelines.
  • Wire emulation environments (QEMU, Unicorn, Qiling) and instrumentation tooling (Frida, DynamoRIO) into agent-accessible tool interfaces.
  • Design and build evaluation and benchmarking infrastructure that measures whether the agentic vulnerability research pipeline is working.
  • Develop and weaponize exploits from discovered vulnerabilities, turning raw findings into working exploit primitives.
  • Contribute to agent harness orchestration, tool-use design, and eval loops that power autonomous vulnerability research at scale.
  • Collaborate directly with the R&D team to push the boundary of what agents can autonomously discover and exploit across target device classes.

Tech stack: C / C++ / Rust; GDB, IDA, Ghidra; QEMU, Unicorn, Qiling, PANDA, FirmAE; Frida, DynamoRIO; Linux (kernel internals, system-level debugging); fuzzing pipelines; modern mitigations (ASLR, CFI, PAC, MTE); agent harnesses / orchestration / eval loops.

Requirements

~1 min read
  • Vulnerability research as primary current role function
  • Strong RE and debugger chops (GDB, IDA, or Ghidra)
  • 2 to 3 or more years C, C++, or Rust systems programming
  • Deep Linux systems fluency
  • NYC in-person 5 days, relocation required
  • US citizen or clearance-eligible preferred
  • Exploit weaponization experience
  • Offensive security firm background (NSO, Paragon, or equivalent)
  • Competitive CTF background or public CVEs
  • AI enthusiast with genuine technical interest in agents
  • Startup-suitable culture fit
  • Vulnerability research is a minority function in current role
  • Corporate or enterprise-only background without startup fit
  • Not willing or able to work in-person in New York five days per week
  • Foreign national from a country Zealot Labs does not sell to
  • Salary — $220,000–$350,000
  • Equity — Competitive Equity
  • On-site policy — In-person New York City, 5 days per week; no remote option; relocation required
  • Visa sponsorship — None Available; US citizen or clearance-eligible preferred
  • Employment type — Full-time
  • Location — New York City, NY
  1. Have you done any exploit weaponization? (Contrario "Required Candidate Q&A" — a required field on the submission form, not just a call question.)

Stage 1 — Pending Approval — Candidates awaiting initial approval. Stage 2 — Introductory call with Oliver. Stage 3 — Technical interview with a member of the R&D team (15 to 30 minutes). Stage 4 — In-person interview in New York — On-site meeting with the team; happens as soon as scheduling allows, with a team member in New York approximately every two weeks. Stage 5 — Offer Extended. Stage 6 — Candidate Hired — Candidate accepts and starts.

Updated Jul 20, 2026 No dedicated "Ideal Companies" section was present on the role page. The only company signals are in the Green Flags: offensive security firms — NSO, Paragon, or equivalent US/allied-ecosystem organizations.

For reference only — do not source these specific profiles (Contrario "DO NOT CONTACT"). Stratos Tiganourias — LinkedIn URL not captured in the pasted HTML (only a LinkedIn button was present). Aviv Yahav — LinkedIn URL not captured in the pasted HTML (only a LinkedIn button was present).

Location & Eligibility

Where is the job
New York, United States
On-site at the office
Who can apply
US

Listing Details

First seen
July 20, 2026
Last seen
July 21, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
51%
Scored at
July 20, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

davidjoseph-coZealot — Vulnerability Researcher