Quantro Security
← All roles
Role · Security Research

Vulnerability Research Engineer

Break things first. Research vulnerabilities, build the exploits, and prove what is exploitable end to end — so the agents can too.

Apply for this role → Remote-first · salary + equity
What you'll do
  • Research vulnerabilities across the stack — from freshly disclosed CVEs to novel findings — deeply enough to weaponize them.
  • Build working exploits and proof-of-concepts end to end, against real targets in safe, isolated environments.
  • Design and harden the exploit harness that powers the Research Agent to generate and test PoCs in minutes.
  • Encode how attackers actually think into the workforce — turning offensive expertise into agent capability.
  • Separate what is genuinely exploitable from what is theoretical, and keep the agents grounded in ground truth.
What we're looking for
  • Deep, hands-on vulnerability research and exploit development — you have found, weaponized, and tested exploits end to end.
  • Strong grasp of exploitation in your area of depth — memory safety, web, cloud, or infrastructure — and how attack paths chain together.
  • Comfortable reversing, fuzzing, and building tooling in Python/C/Rust/Go as the target demands.
  • You know the difference between a theoretical risk and one that breaches a customer next Tuesday — and can prove it.
  • You operate exploits responsibly, in controlled environments. Rigor and safety are non-negotiable.
Bonus points
  • Published CVEs, CTF, red team, or offensive-security research background.
  • Built exploit automation or harnesses before.
  • Interested in coupling offensive research with LLM/agent systems.
  • You have shipped tooling other researchers rely on.

Sound like you?

Tell us about yourself and attach your résumé. We read every application.

Apply for this role →