§What You'll Do
- Help design and build our agentic systems that autonomously perform vulnerability research against real targets: firmware, network stacks, mobile OSes, and IoT.
- Wire emulation (QEMU, Unicorn, Qiling), instrumentation (Frida, DynamoRIO), fuzzing, and exploit primitives into tool interfaces for agents.
- Build the evaluation and benchmarking infrastructure that tells us whether any of it is actually working.
§Requirements
- 2–3+ years across systems programming (C/C++, Rust) and ML infrastructure.
- Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE).
- Hands-on work with agent harnesses — orchestration, tool-use, eval loops — in production or at benchmark scale.
- Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE).
- Strong RE / debugger chops (GDB, IDA or Ghidra) and the patience to use them.
§Nice to Have
- Pwn-heavy CTF experience (DEF CON finals, PPP, DiceGang, Shellphish, Theori, Team Atlanta).
- Public CVEs, conference talks, or AIxCC / CGC participation.
- Kernel or baseband RE.
§You Are
- That requirements list is what the fully-formed version of this role looks like. It's not a filter. If you're sharp, hungry, and funny, apply anyway, even if half the bullets read like a foreign language today.
- Tech can be learned. Spirit cannot. We've watched the right people pick up binary exploitation from scratch and outship ten-year veterans inside a year.
- Tell us what you've taught yourself recently and what you'd tear into first here.
Ready?
Apply for Vulnerability Researcher, New York
Email team@zealotlabs.com with a resume and a paragraph on what you want to build with us.
Apply now