Curated, verified where possible, for AppSec / Security Researcher / Vuln Researcher / Product Security / AI-ML Security. Remote-worldwide or Canada preferred, ~100k+ USD (or CAD equiv). You are Canadian in Calgary, so Canada + Canada-remote roles are work-auth-clean; US-only-remote roles may need visa (flagged).
Your receipts to lead with: File Browser CVE-2026-55667 (HIGH 8.2) = flagship self-hosted-web-app CVE; OpenBao CVE-2026-63131 = secrets/Vault-adjacent (Go); Gitea CVE-2026-27761 = git-forge-adjacent (Go); the coordinated IBM MCP advisory + the MCP/AI-agent SSRF/credential-forwarding/auth-boundary body of work = your AI-security angle; dYdX/Polymarket + Immunefi-cleared = smart-contract audit angle; the autonomous multi-agent vuln-research pipeline = your standout differentiator.
| Company | Role | Remote / Location | Salary | Apply link (verified live) | Why you fit + lead-with | Honesty flag |
|---|---|---|---|---|---|---|
| Mozilla | Senior Product Security Engineer | Remote CANADA (also EU/UK) | CAD 104-139k | www.mozilla.org/en-US/careers/position/gh/7583 | AMO add-on/self-hosted-app security; lead File Browser CVE 8.2 + variant analysis | None major. Confirm the exact req title when you open it. |
| Runlayer | MTS, Security | Remote (US timezones) / hybrid NYC | competitive + equity (not listed) | jobs.ashbyhq.com/runlayer/42c0ccf3-7d33-405d-a | Builds MCP-server/agent scanning + shadow detection; lead MCP/AI-agent angle | Asks 8+ yrs security eng = tenure stretch; MCP depth offsets |
| Canonical | Security Software Engineer | Home-based WORLDWIDE | not listed | canonical.com/careers/5146620 | Ubuntu/product hardening, Go; lead OpenBao + Gitea CVEs | Pay band region-adjusted (verify vs 100k USD); long hiring process; 2-4x/yr travel |
| Chainguard | Senior Product Security Engineer | Remote UNITED STATES | $157-184k USD | job-boards.greenhouse.io/chainguard/jobs/46889 | Supply-chain/secure-container; lead incomplete-fix/variant + File Browser CVE | Says "United States" - confirm Canada eligibility; senior bar |
| Anthropic | Staff+ Application Security Engineer | Remote-friendly (travel req) | $320-485k USD | job-boards.greenhouse.io/anthropic/jobs/450250 | Bug-bounty ownership + LLM-driven vuln pipeline = your build; lead File Browser CVE + pipeline | Staff+ seniority = stretch; travel required |
| Aikido Security | Customer Security Engineer (Pentest) | Remote (US/UK/SG/BE +) | not listed | aikidosecurity.recruitee.com/o/customer-securi | Offensive/pentest + AppSec at a scanner firm; lead bug-bounty + 3 CVEs | Canada not explicitly listed but remote-flexible - ask; first-of-role |
| Company | Role | Remote / Location | Salary | Apply link (verified live) | Why you fit | Honesty flag |
|---|---|---|---|---|---|---|
| Noma Security | Senior Security Researcher | Tel Aviv (on-site) | not listed | noma.security/careers/co/tel-aviv/5D.A5A/senio | Agentic/MCP vuln research is the core; lead MCP angle | Tel-Aviv-only relocation; not remote |
| Zenity | Senior Security Researcher | Tel Aviv (hybrid) | not listed | zenity.io/careers | Agentic AI / LLM attack-vector research; lead MCP angle | Tel-Aviv relocation; US-remote roles are non-research only |
| Anthropic | Security Labs Engineer | San Francisco (on-site heavy) | ~320-405k (unverified) | job-boards.greenhouse.io/anthropic/jobs/515356 | Offensive security / research, prototype-building; lead MCP + CVEs | SF relocation, some airgapped work; 7+ yrs |
| Anthropic | Lead, Frontier Red Team (Cyber) | SF hybrid + DC travel | $485-755k USD | job-boards.greenhouse.io/anthropic/jobs/532635 | Frontier autonomous-vuln research | Leadership role = big stretch; shown for ceiling only |
| Datadog | Staff Application Security Engineer | Hybrid Boston / NYC | $244-305k USD | careers.datadoghq.com/detail/7777798/ | AppSec at scale; lead File Browser CVE | Staff + hybrid + likely US-only = stretch |
| Wiz | Security Engineer, Product & Prod Infra | Remote NETHERLANDS | not listed | www.wiz.io/careers/job/4595651006/ | Cloud/product security | NL-based, no sponsorship = geo mismatch |
| Company | Role | Remote / Location | Salary | Link to verify | Why you fit | Honesty flag |
|---|---|---|---|---|---|---|
| Greenhouse (the company) | Senior Product Security Engineer (AI/ML) | Remote, Canada-eligible | $155-233k CAD | job-boards.greenhouse.io/greenhouse/jobs/75456 | "SME on AI security / securing emerging AI-ML features" = bullseye; lead MCP/AI angle + File Browser CVE | UNVERIFIED - fetch returned an error/redirect = possibly closed; if 404 watch www.greenhouse.com/careers/opportunities |
| GitHub Security Lab | Staff / Senior Security Researcher | Remote (US-stated) | not listed | www.github.careers/careers-home/jobs (search "Security Lab", IDs 5391/4807) | Literally "find + report vulns in OSS, coordinate disclosure, publish tooling" = your CVEs + pipeline | UNVERIFIED (github.careers JS-blocked) + confirm Canada work-auth; senior bar |
| Coinbase | Blockchain Security Engineer | Remote - CANADA | not listed | www.coinbase.com/careers/positions/6863712 | Secure code review + threat modeling; web3-adjacent = your DeFi audit plus; lead source-review + OpenBao/Gitea | UNVERIFIED (Coinbase blocks fetch); Canada-tagged so geo-clean if open |
| Chainlink Labs | Blockchain Application Security Engineer (SC Auditor) | 100% remote, no geo limit | ~$60-110k (one listing) | chainlink.link/open-roles or chain.link careers | Audit angle; most explicitly Canada-friendly; lead dYdX/Polymarket + Immunefi | UNVERIFIED; comp on the one salaried listing seen is below your target; wants ~5yr SWE |
| OpenZeppelin | Security Researcher (blockchain) | Fully remote, global | market ~150-250k | www.openzeppelin.com/careers | Audit angle, remote-global Canada-friendly; lead dYdX/Polymarket + Immunefi | UNVERIFIED; some listings are "future openings" pipelines |
| Wealthsimple | Security Engineer (App & Cloud) / Sr Dev, AppSec | Remote anywhere in CANADA | not listed | www.wealthsimple.com/careers (Ashby/GH) | AppSec + source review at a fintech; lead File Browser CVE | UNVERIFIED (startup.jobs 403); some reqs may be older - verify on their site |
| Arctic Wolf | Security Researcher, Threat Intelligence | Remote, Canadian company (Waterloo) | not listed | arcticwolf.com/careers | Research + findings write-up; your CVE track record | UNVERIFIED; threat-intel-flavored (not pure VR) = moderate fit |
| 1Password | Security Engineer / Vuln Management / Detection | Remote US or CANADA | CAD 143-193k band | jobs.ashbyhq.com/1password (filter Security) | Password/secrets product; lead OpenBao CVE (vault relevance) + File Browser | UNVERIFIED; NOTE their "Senior AppSec" req is CONFIRMED CLOSED - check the others only |
| Elastic | Security-Elasticsearch engineering (incl. a Canada-remote role) | US / Canada remote | not listed | jobs.elastic.co/jobs/team/security | Security-product engineering; fresh (posted ~07-23) | UNVERIFIED (JS); leans feature-dev over pure AppSec |
| GitLab | Senior Software Security Engineer / AppSec | All-remote (filter Remote-Canada) | US band $139-196k on one listing | job-boards.greenhouse.io/gitlab (filter Security) | Secure-SDLC + source review; runs a bug-bounty; lead File Browser CVE 8.2 | UNVERIFIED at req level (several specific IDs now redirect = filled); use the live board + filter |
| Company | Role | Remote / Location | Salary | Link to verify | Why you fit | Honesty flag |
|---|---|---|---|---|---|---|
| Socket (socket.dev) | Vulnerability Research Engineer | Remote USA | not listed | jobs.ashbyhq.com/socket/91b38c09-d291-4fb4-805 | JS/TS + vuln research + CVEs = bullseye; lead 3 CVEs + variant method | UNVERIFIED (Ashby JS); US-only remote = confirm Canada |
| HackerOne | Product Security Analyst | Washington DC | $120-155k | jobs.ashbyhq.com/hackerone/379afa88-fca8-40ed- | Validates bug-bounty findings = your exact background | UNVERIFIED (Ashby JS); DC-located, remote variant unconfirmed |
| Trail of Bits | Security Engineer, AppSec / Blockchain / Agentic AI / Apprenticeship | US Remote (apprenticeship = worldwide) | R&E band ~$125-185k | www.trailofbits.com/careers | CVE-publishing-auditor culture fit; apprenticeship = global entry path; lead CVEs (AppSec) or dYdX/Polymarket (blockchain) | UNVERIFIED (Workable metadata-only); non-apprentice roles want ToB-grade depth |
| Horizon3.ai | Security Researcher / WebApp Offensive Sec Engineer | Remote-first (US broadband) | remote band cited up to ~$234k median | jobs.ashbyhq.com/horizon3ai | "Weaponize newly-disclosed vulns, patch-diff" = your incomplete-fix work; lead 3 CVEs + pipeline | UNVERIFIED; leans exploit-dev / OSCP-OSWE depth; US-centric |
| Bugcrowd | Application Security Engineer / II | 100% remote | not listed | www.bugcrowd.com/about/careers/ | Bug-bounty triage = perfect fit | UNVERIFIED (Greenhouse IDs expired); check live board |
| Docker | Senior Security Engineer (Docker Desktop) | Remote-first | not listed | jobs.ashbyhq.com/docker | Container/runtime security; lead source-review + CVEs | UNVERIFIED (Ashby JS) |
| Sysdig | Senior Security Engineer | Remote | not listed | jobs.lever.co/sysdig | Go/Python secure-code + AppSec | UNVERIFIED (Lever 403) |
| Grafana Labs | Software Engineer, Security Assurance | US Remote | not listed | job-boards.greenhouse.io/grafanalabs | AppSec at a self-hosted-product company; lead File Browser CVE | UNVERIFIED; older Sr AppSec role appears stale |
| Assetnote / Searchlight Cyber | (Browser) Vulnerability Researcher | (verify) | not listed | slcyber.io/careers/ (or careers@slcyber.io) | Best culture fit for a CVE-publishing researcher; lead 3 CVEs + method | UNVERIFIED (BambooHR 403); apply direct |
| Spearbit / Cantina | Security Researcher (tiered) | Remote, global | ~$90k salaried SR + marketplace | cantina.xyz | Immunefi/contest receipts plug into their tiered model; lead dYdX/Polymarket + Immunefi | UNVERIFIED; marketplace/curated model, income track-record-gated (not classic W2) |