Security Research Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

AI Security Assurance · 2 days ago

Security Research Engineer

AI Security Assurance is a new, remote‑first startup building AI‑Storm, an AI‑powered platform that bridges high‑level systems‑theoretic security analysis with actual source code. The Security Research Engineer will help build the core AI-powered analysis engine, develop a multi-language ingestion pipeline, and collaborate with team members to ensure the pipeline's outputs are accessible.

Computer Software
badNo H1BnoteU.S. Citizen Onlynote
Hiring Manager
Lori Pickering
linkedin

Responsibilities

Build and extend the AI-powered Ingestion Engine: work with our team members to develop a multi‑language ingestion pipeline that generates syntactic, semantic, focus and hierarchical labels
Integrate hierarchical abstraction and data‑flow: extend the engine with data‑flow extraction, a pattern‑matching library for scenario mitigations, and attack‑tree structures
Expose backend APIs to the web UI: collaborate with the front‑end specialist to ensure the pipeline’s outputs are accessible in both cloud and on‑prem deployments
Support evaluation and dataset creation: help collect test data, generate multi‑level datasets and contribute to our LLM‑as‑a‑judge evaluation metrics
Collaborate across the stack: work with our STPA‑Sec and formal‑verification leads to integrate mitigation constraints, proofs, and assurance evidence into the backend

Qualification

Security engineeringStatic/dynamic analysisThreat modelingBackend services designThreat-modelling frameworksVulnerability databasesData-flow analysisKnowledge graphsOpen-source contributionsCloud deploymentDevOps practicesCritical thinkingCollaboration

Required

Bachelor's degree or higher in Computer Science or a related technical discipline
4+ years of professional experience in security engineering, static/dynamic analysis, threat modeling, or related roles with a demonstrated ability to deliver
Experience designing and implementing backend services or pipelines and exposing APIs for other components
Familiarity with threat‑modelling frameworks and vulnerability databases (e.g., CWE/CVE) and the ability to map findings back to code
Strong critical thinking about trade‑offs in performance, accuracy and scalability in security tooling
Ability to work independently, collaborate with domain experts, and wear multiple hats in a fast‑moving environment
Ability to work with complex datasets, such as natural language and knowledge graphs, and develop robust evaluation metrics
Ability to work in the US without sponsorship. Future work may require ability to obtain a U.S. security clearance

Preferred

Experience with STPA‑Sec or formal methods (e.g., theorem provers, formal verification frameworks)
Knowledge of graph‑based representations of code (Code Property Graphs), knowledge graphs, and pattern‑matching techniques
Contributions to open‑source security tools or static/dynamic analysis projects
Familiarity with cloud/on‑prem deployment, DevOps practices and database technologies (e.g., PostgreSQL)
Publications, conference presentations, or blog posts in the area of software or systems security or related areas
Preference for East Coast residents who can travel to the D.C./Virginia area for occasional meetings

Benefits

Health / Dental / Vision benefits / etc.
Life Insurance, Short-Term and Long-Term Disability coverage.
401(k) retirement plan.

Company

AI Security Assurance

twitter
company-logo
AI Security Assurance automates end-to-end security analysis—from high-level threat modeling to code implementation.

Funding

Current Stage
Early Stage
Company data provided by crunchbase