# AppSec Engineer

- Company: [Theori](<https://jobstar.asia/company/theori>)
- Location: United States · Canada
- Remote: Yes
- Team: Engineering
- Employment type: Full Time
- Posted: June 5, 2026

## Job description

We're looking for a hands-on Cyber Security Engineer to sit at the intersection of AI-driven tooling and real-world security research. In this role, you'll own the end-to-end triage and validation lifecycle for vulnerability reports generated by our AI-powered static analysis platform, separating true positives from noise, writing proof-of-concept exploits, and reporting vulnerabilities upstream to the appropriate vendor.

This is a deeply technical role built for someone who thinks like an attacker, thrives in ambiguous environments, and has a track record of finding and exploiting vulnerabilities.

## **What You'll Do**

* Triage and validate vulnerability reports produced by our AI static analysis tool, verifying severity, exploitability, and business impact
* Write proof-of-concept exploits for critical vulnerabilities to confirm true positives
* Analyze false positives to identify patterns and provide structured feedback to engineering
* Author detailed vulnerability reports that will be submitted to upstream vendors and open source projects

## **What We're Looking For**

* Experience in a security engineering, vulnerability research, or penetration testing role
* Demonstrated CTF experience through participation in competitive CTFs (e.g. DEFCON, PlaidCTF) with writeups
* Hands-on real-world vulnerability research and exploitation experience is preferred
* Proficiency reading and auditing code across multiple programming languages
* Prior bug bounty participation is preferred
* Based in US or Canada

## Apply

[Apply on Theori](<https://jobs.ashbyhq.com/theori/bc072f72-2e83-4bbe-9962-1276055415b9>)

Canonical job page: <https://jobstar.asia/job/appsec-engineer-theori-united-states-ee1d4da1a5945033>
