Security job openings for Kingsley - compiled 2026-07-27

Curated, verified where possible, for AppSec / Security Researcher / Vuln Researcher / Product Security / AI-ML Security. Remote-worldwide or Canada preferred, ~100k+ USD (or CAD equiv). You are Canadian in Calgary, so Canada + Canada-remote roles are work-auth-clean; US-only-remote roles may need visa (flagged).

HOW TO READ THIS (honesty key - important)

Your receipts to lead with: File Browser CVE-2026-55667 (HIGH 8.2) = flagship self-hosted-web-app CVE; OpenBao CVE-2026-63131 = secrets/Vault-adjacent (Go); Gitea CVE-2026-27761 = git-forge-adjacent (Go); the coordinated IBM MCP advisory + the MCP/AI-agent SSRF/credential-forwarding/auth-boundary body of work = your AI-security angle; dYdX/Polymarket + Immunefi-cleared = smart-contract audit angle; the autonomous multi-agent vuln-research pipeline = your standout differentiator.


TOP 5 TO HIT FIRST (best blend of confirmed-live + geo/pay fit + topical match)

1
Mozilla - Senior Product Security Engineer (CONFIRMED-LIVE, Remote CANADA, CAD ~104-139k). Cleanest fit: Canada-remote, pay-in-band, and it is add-on/self-hosted-app security = lead with File Browser CVE 8.2 + your incomplete-fix/variant method. Apply: www.mozilla.org/en-US/careers/position/gh/7583
2
Runlayer - Member of Technical Staff, Security (CONFIRMED-LIVE, Remote US-timezones). Almost bespoke to you: they build MCP-server/agent scanning + shadow-MCP detection. Lead with the MCP/AI-agent angle. Stretch on their "8+ yrs" ask, but your MCP depth offsets. Apply: jobs.ashbyhq.com/runlayer/42c0ccf3-7d33-405d-a
3
Canonical - Security Software Engineer (CONFIRMED-LIVE, Home-based WORLDWIDE). Best geography (worldwide remote), Go-heavy product hardening = lead with OpenBao + Gitea (Go) CVEs. Verify pay band (region-adjusted, sometimes below 100k USD). Apply: canonical.com/careers/5146620
4
Chainguard - Senior Product Security Engineer (CONFIRMED-LIVE, Remote US, $157-184k USD). Supply-chain / secure-container firm; your variant-analysis + CVE portfolio maps to product hardening. Confirm they accept Canada-based before investing. Apply: job-boards.greenhouse.io/chainguard/jobs/46889
5
Anthropic - Staff+ Application Security Engineer (CONFIRMED-LIVE, Remote-friendly, $320-485k USD). Their JD literally describes "an increasingly autonomous vulnerability pipeline - LLM-driven code analysis finds the issue, scores it for exploitability, opens the fix PR" = your exact build. Stretch on Staff+ seniority, but the topical + differentiator match is extraordinary; worth a strong application. Lead File Browser CVE + the pipeline. Apply: job-boards.greenhouse.io/anthropic/jobs/450250

GROUP A - CONFIRMED-LIVE, best fit, geo/pay-viable (apply first)

CompanyRoleRemote / LocationSalaryApply link (verified live)Why you fit + lead-withHonesty flag
MozillaSenior Product Security EngineerRemote CANADA (also EU/UK)CAD 104-139kwww.mozilla.org/en-US/careers/position/gh/7583AMO add-on/self-hosted-app security; lead File Browser CVE 8.2 + variant analysisNone major. Confirm the exact req title when you open it.
RunlayerMTS, SecurityRemote (US timezones) / hybrid NYCcompetitive + equity (not listed)jobs.ashbyhq.com/runlayer/42c0ccf3-7d33-405d-aBuilds MCP-server/agent scanning + shadow detection; lead MCP/AI-agent angleAsks 8+ yrs security eng = tenure stretch; MCP depth offsets
CanonicalSecurity Software EngineerHome-based WORLDWIDEnot listedcanonical.com/careers/5146620Ubuntu/product hardening, Go; lead OpenBao + Gitea CVEsPay band region-adjusted (verify vs 100k USD); long hiring process; 2-4x/yr travel
ChainguardSenior Product Security EngineerRemote UNITED STATES$157-184k USDjob-boards.greenhouse.io/chainguard/jobs/46889Supply-chain/secure-container; lead incomplete-fix/variant + File Browser CVESays "United States" - confirm Canada eligibility; senior bar
AnthropicStaff+ Application Security EngineerRemote-friendly (travel req)$320-485k USDjob-boards.greenhouse.io/anthropic/jobs/450250Bug-bounty ownership + LLM-driven vuln pipeline = your build; lead File Browser CVE + pipelineStaff+ seniority = stretch; travel required
Aikido SecurityCustomer Security Engineer (Pentest)Remote (US/UK/SG/BE +)not listedaikidosecurity.recruitee.com/o/customer-securiOffensive/pentest + AppSec at a scanner firm; lead bug-bounty + 3 CVEsCanada not explicitly listed but remote-flexible - ask; first-of-role

GROUP B - CONFIRMED-LIVE but geo-stretch or senior-stretch (great topical fit; relocation/level caveats)

CompanyRoleRemote / LocationSalaryApply link (verified live)Why you fitHonesty flag
Noma SecuritySenior Security ResearcherTel Aviv (on-site)not listednoma.security/careers/co/tel-aviv/5D.A5A/senioAgentic/MCP vuln research is the core; lead MCP angleTel-Aviv-only relocation; not remote
ZenitySenior Security ResearcherTel Aviv (hybrid)not listedzenity.io/careersAgentic AI / LLM attack-vector research; lead MCP angleTel-Aviv relocation; US-remote roles are non-research only
AnthropicSecurity Labs EngineerSan Francisco (on-site heavy)~320-405k (unverified)job-boards.greenhouse.io/anthropic/jobs/515356Offensive security / research, prototype-building; lead MCP + CVEsSF relocation, some airgapped work; 7+ yrs
AnthropicLead, Frontier Red Team (Cyber)SF hybrid + DC travel$485-755k USDjob-boards.greenhouse.io/anthropic/jobs/532635Frontier autonomous-vuln researchLeadership role = big stretch; shown for ceiling only
DatadogStaff Application Security EngineerHybrid Boston / NYC$244-305k USDcareers.datadoghq.com/detail/7777798/AppSec at scale; lead File Browser CVEStaff + hybrid + likely US-only = stretch
WizSecurity Engineer, Product & Prod InfraRemote NETHERLANDSnot listedwww.wiz.io/careers/job/4595651006/Cloud/product securityNL-based, no sponsorship = geo mismatch

GROUP C - UNVERIFIED (open yourself), strong fit, CANADA / remote-friendly (highest-value to check tonight)

CompanyRoleRemote / LocationSalaryLink to verifyWhy you fitHonesty flag
Greenhouse (the company)Senior Product Security Engineer (AI/ML)Remote, Canada-eligible$155-233k CADjob-boards.greenhouse.io/greenhouse/jobs/75456"SME on AI security / securing emerging AI-ML features" = bullseye; lead MCP/AI angle + File Browser CVEUNVERIFIED - fetch returned an error/redirect = possibly closed; if 404 watch www.greenhouse.com/careers/opportunities
GitHub Security LabStaff / Senior Security ResearcherRemote (US-stated)not listedwww.github.careers/careers-home/jobs (search "Security Lab", IDs 5391/4807)Literally "find + report vulns in OSS, coordinate disclosure, publish tooling" = your CVEs + pipelineUNVERIFIED (github.careers JS-blocked) + confirm Canada work-auth; senior bar
CoinbaseBlockchain Security EngineerRemote - CANADAnot listedwww.coinbase.com/careers/positions/6863712Secure code review + threat modeling; web3-adjacent = your DeFi audit plus; lead source-review + OpenBao/GiteaUNVERIFIED (Coinbase blocks fetch); Canada-tagged so geo-clean if open
Chainlink LabsBlockchain Application Security Engineer (SC Auditor)100% remote, no geo limit~$60-110k (one listing)chainlink.link/open-roles or chain.link careersAudit angle; most explicitly Canada-friendly; lead dYdX/Polymarket + ImmunefiUNVERIFIED; comp on the one salaried listing seen is below your target; wants ~5yr SWE
OpenZeppelinSecurity Researcher (blockchain)Fully remote, globalmarket ~150-250kwww.openzeppelin.com/careersAudit angle, remote-global Canada-friendly; lead dYdX/Polymarket + ImmunefiUNVERIFIED; some listings are "future openings" pipelines
WealthsimpleSecurity Engineer (App & Cloud) / Sr Dev, AppSecRemote anywhere in CANADAnot listedwww.wealthsimple.com/careers (Ashby/GH)AppSec + source review at a fintech; lead File Browser CVEUNVERIFIED (startup.jobs 403); some reqs may be older - verify on their site
Arctic WolfSecurity Researcher, Threat IntelligenceRemote, Canadian company (Waterloo)not listedarcticwolf.com/careersResearch + findings write-up; your CVE track recordUNVERIFIED; threat-intel-flavored (not pure VR) = moderate fit
1PasswordSecurity Engineer / Vuln Management / DetectionRemote US or CANADACAD 143-193k bandjobs.ashbyhq.com/1password (filter Security)Password/secrets product; lead OpenBao CVE (vault relevance) + File BrowserUNVERIFIED; NOTE their "Senior AppSec" req is CONFIRMED CLOSED - check the others only
ElasticSecurity-Elasticsearch engineering (incl. a Canada-remote role)US / Canada remotenot listedjobs.elastic.co/jobs/team/securitySecurity-product engineering; fresh (posted ~07-23)UNVERIFIED (JS); leans feature-dev over pure AppSec
GitLabSenior Software Security Engineer / AppSecAll-remote (filter Remote-Canada)US band $139-196k on one listingjob-boards.greenhouse.io/gitlab (filter Security)Secure-SDLC + source review; runs a bug-bounty; lead File Browser CVE 8.2UNVERIFIED at req level (several specific IDs now redirect = filled); use the live board + filter

GROUP D - UNVERIFIED (open yourself), strong fit, US-remote (visa/eligibility to confirm)

CompanyRoleRemote / LocationSalaryLink to verifyWhy you fitHonesty flag
Socket (socket.dev)Vulnerability Research EngineerRemote USAnot listedjobs.ashbyhq.com/socket/91b38c09-d291-4fb4-805JS/TS + vuln research + CVEs = bullseye; lead 3 CVEs + variant methodUNVERIFIED (Ashby JS); US-only remote = confirm Canada
HackerOneProduct Security AnalystWashington DC$120-155kjobs.ashbyhq.com/hackerone/379afa88-fca8-40ed-Validates bug-bounty findings = your exact backgroundUNVERIFIED (Ashby JS); DC-located, remote variant unconfirmed
Trail of BitsSecurity Engineer, AppSec / Blockchain / Agentic AI / ApprenticeshipUS Remote (apprenticeship = worldwide)R&E band ~$125-185kwww.trailofbits.com/careersCVE-publishing-auditor culture fit; apprenticeship = global entry path; lead CVEs (AppSec) or dYdX/Polymarket (blockchain)UNVERIFIED (Workable metadata-only); non-apprentice roles want ToB-grade depth
Horizon3.aiSecurity Researcher / WebApp Offensive Sec EngineerRemote-first (US broadband)remote band cited up to ~$234k medianjobs.ashbyhq.com/horizon3ai"Weaponize newly-disclosed vulns, patch-diff" = your incomplete-fix work; lead 3 CVEs + pipelineUNVERIFIED; leans exploit-dev / OSCP-OSWE depth; US-centric
BugcrowdApplication Security Engineer / II100% remotenot listedwww.bugcrowd.com/about/careers/Bug-bounty triage = perfect fitUNVERIFIED (Greenhouse IDs expired); check live board
DockerSenior Security Engineer (Docker Desktop)Remote-firstnot listedjobs.ashbyhq.com/dockerContainer/runtime security; lead source-review + CVEsUNVERIFIED (Ashby JS)
SysdigSenior Security EngineerRemotenot listedjobs.lever.co/sysdigGo/Python secure-code + AppSecUNVERIFIED (Lever 403)
Grafana LabsSoftware Engineer, Security AssuranceUS Remotenot listedjob-boards.greenhouse.io/grafanalabsAppSec at a self-hosted-product company; lead File Browser CVEUNVERIFIED; older Sr AppSec role appears stale
Assetnote / Searchlight Cyber(Browser) Vulnerability Researcher(verify)not listedslcyber.io/careers/ (or careers@slcyber.io)Best culture fit for a CVE-publishing researcher; lead 3 CVEs + methodUNVERIFIED (BambooHR 403); apply direct
Spearbit / CantinaSecurity Researcher (tiered)Remote, global~$90k salaried SR + marketplacecantina.xyzImmunefi/contest receipts plug into their tiered model; lead dYdX/Polymarket + ImmunefiUNVERIFIED; marketplace/curated model, income track-record-gated (not classic W2)

DEAD - do NOT chase (verified closed/removed, so you skip them)

Positioning cheat-sheet (which receipt to lead with)

Reminders

Compiled by Buddy, reviewed by your coordinator. No links invented. Nothing auto-applies, every submit is your button.