OX Security
OX Security
51 – 200 Employees
CybersecurityEnterpriseSaaS
OX Security develops Application Security Posture Management (ASPM) software for organizations focused on securing the software supply chain. Its platform connects with CI/CD workflows to give security and development teams a centralized view of application risks, help prioritize vulnerabilities, and coordinate remediation across the software development lifecycle. By bringing AppSec data and processes together, OX Security supports earlier security checks in development, reduces fragmented workflows, and helps enterprises manage application security at scale. The company operates in the cybersecurity, SaaS, and enterprise technology sectors.

Application Security Researcher — OX Security (Remote, Argentina)

Investigate vulnerabilities, attack paths, and autonomous penetration testing for OX Security’s AI-powered security platform. Develop detection engines and deliver offensive security capabilities to production.

Description

  • Investigate vulnerability chains, business-logic weaknesses, and complex attack paths across applications and infrastructure.
  • Create detection engines and decision-making systems for autonomous security workflows.
  • Assess AI models for application security, identifying their strengths, limitations, and practical effectiveness.
  • Turn security research into tested capabilities and deploy them in production environments.
  • Examine large-scale security datasets to identify exploitable paths and improve detection precision.
  • Work with Product, Engineering, and Data teams to develop the company’s next generation of security features.
  • Help define the research roadmap and lead initiatives from initial concept through production delivery.

Requirements

  • Master’s degree in Computer Science, Cyber Security, or a related discipline.
  • At least five years of practical experience in offensive security, vulnerability research, or application security.
  • Advanced knowledge of web application and API vulnerabilities, including business-logic weaknesses and multi-stage attack chains.
  • Strong programming ability in Python, Go, or a comparable language, with a record of delivering production-ready software.
  • Experience creating or refining detection logic for SAST, DAST, SCA, secrets, or custom rule engines while minimizing false positives.
  • Working knowledge of contemporary application and infrastructure environments, including CI/CD, containers, Kubernetes, and at least one major cloud platform.
  • Practical experience applying LLMs or other AI models to security work, along with the judgment to evaluate their effectiveness and limitations.
  • Ability to work with substantial datasets using SQL, BigQuery, or similar tools to guide research and assess detection accuracy.
  • Capacity to move research concepts from prototype to production with limited supervision.
  • Strong written communication skills and the ability to explain complex attack paths to engineering and product stakeholders.

Related Jobs