Lazarus AI provides an API-first, on-premise-capable, multimodal document-understanding platform combining OCR and proprietary models (RikAI, ATLS) for explainable extraction, classification, summarization and evidence-based workflows in regulated industries.
<div class="content-intro"><p>We help organizations move AI out of experimentation and into production — safely, reliably, and at scale. From inconsistent performance to limited transparency and challenges with integration and long-term viability, our Applied Intelligence Engine solves the risks that cause most AI initiatives to stall.</p> <p>Built for some of the most highly regulated industries in the world, we enable teams to deploy AI systems that are auditable, explainable, and aligned with real-world constraints. Our solutions introduce structure, visibility, and control into how AI operates, turning advanced capabilities into a dependable, production-grade infrastructure so our customers can move faster and scale with confidence.</p></div><p><strong>Job Overview</strong></p> <p class="p1">You’ll help build Clearwing: an AI-native cybersecurity system for autonomous vulnerability discovery, exploit validation, pen-testing, reverse engineering, and security reporting. You’ll combine hands-on offensive security work with LLM agent development, eval design, and product engineering. The ideal candidate can chase real bugs, validate exploitability, write production-quality Python, and turn exploratory research into repeatable security capabilities.</p> <p><strong>Responsibilities</strong></p> <ul> <li>Develop AI-assisted vulnerability discovery workflows for source code, binaries, networks, and live systems.</li> <li>Build and improve Clearwing’s source-code hunting, network pen-testing, N-day exploit, reverse engineering, and validation pipelines.</li> <li>Design agentic workflows for reconnaissance, static analysis, dynamic testing, exploit development, patch validation, and reporting.</li> <li>Perform static analysis to identify vulnerable patterns, reachable attack surfaces, and exploitability conditions.</li> <li>Conduct authorized live testing against networks, services, containers, lab targets, and operational environments.</li> <li>Develop and validate proof-of-concept exploits in controlled, authorized settings.</li> <li>Build evaluation harnesses for vulnerability discovery quality, false positives, exploitability, reproducibility, and model/tool performance.</li> <li>Improve safety, authorization, auditability, guardrails, and human-in-the-loop controls for dual-use cybersecurity capabilities.</li> <li>Work with AI researchers and engineers to improve prompts, tools, agent loops, memory systems, scoring systems, and model-routing strategies.</li> <li>Produce clear technical reports with evidence, reproduction steps, impact analysis, and remediation guidance.</li> </ul> <p><strong>Requirements</strong></p> <ul class="ul1"> <li class="li1">3+ years of hands-on cybersecurity experience in vulnerability research, penetration testing, exploit development, reverse engineering, or security engineering.</li> <li class="li1">Practical experience with at least two of: <ul class="ul1"> <li class="li1">Static analysis</li> <li class="li1">Dynamic analysis</li> <li class="li1">Binary exploitation</li> <li class="li1">Web application security</li> <li class="li1">Network penetration testing</li> <li class="li1">Cloud/container security</li> <li class="li1">Malware analysis or reverse engineering</li> <li class="li1">Detection engineering</li> </ul> </li> <li class="li1">Strong Python skills and comfort building automation around security tools</li> <li class="li1">Familiarity with Linux, Docker, Kali/security tooling, Git, CI, and shell workflows</li> <li class="li1">Ability to reason from vulnerability signal to exploitability, impact, evidence quality, and remediation</li> <li class="li1">Experience working with LLMs, agents, prompt engineering, evals, or AI-assisted security workflows</li> <li class="li1">Strong written communication skills for technical findings, customer-facing reports, and internal research notes</li> <li class="li1">Clear judgment around authorization, responsible disclosure, and dual-use security tooling</li> </ul> <p><strong>Nice-to-haves</strong></p> <ul class="ul1"> <li class="li1">Experience with Ghidra, IDA, Binary Ninja, angr, Semgrep, CodeQL, Joern, AFL++, libFuzzer, ASan/UBSan, or OSS-Fuzz</li> <li class="li1">Experience developing exploits for memory corruption, deserialization, auth bypass, SSRF, RCE, sandbox escape, or supply-chain vulnerabilities</li> <li class="li1">Experience with CVE reproduction, N-day analysis, patch diffing, or exploit validation</li> <li class="li1">Experience building LLM agents, tool-using systems, ReAct loops, eval harnesses, or synthetic-data pipelines</li> <li class="li1">Familiarity with SARIF, CVSS, CWE, MITRE ATT&CK, MITRE CVE workflows, HackerOne/Bugcrowd-style disclosure, or government security reporting</li> <li class="li1">Experience with Rust, Go, C/C++, or systems programming</li> <li class="li1">Prior work with security products, autonomous agents, fuzzing infrastructure, or government/security customers</li> </ul> <p><strong>Benefits</strong></p> <ul> <li>Comprehensive benefits package, including health, dental, and vision insurance, as well as retirement savings plans</li> <li>Opportunities for growth and professional development</li> <li>A collaborative and supportive company culture that values diversity and inclusion</li> <li>Access to cutting-edge technology and resources for research and development</li> <li>Compensation (commensurate with experience): $180,000 - $200,000 (base salary) + equity</li> </ul> <p><strong>Preferred Locations: </strong>AZ, CA, CO, CT, DC, FL, KS, ME, MD, MA, MN, NV, NH, NJ, NM, NY, PA, SC, TX, VA, WA</p><div class="content-conclusion"><p>Lazarus AI is an equal opportunity employer. We are committed to equal employment opportunity and nondiscrimination for all employees and qualified applicants without regard to a person's race, color, gender, age, religion, national origin, ancestry, disability, veteran status, genetic information, sexual orientation or any characteristic