Security Analyst

RunSybil Corp.
United States
2 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$130,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Burp Suite Programming Tools Open Web Application Security Software Engineering Web Applications Software Security

Job description

We are looking for a Security Analyst to join our security research team. You will work hands-on with web application vulnerabilities every day, assessing findings, confirming exploitability, rating severity, and delivering clear, accurate reports that customers rely on to understand and remediate their risk., * Assess and validate web application vulnerabilities across a range of targets and confirm exploitability and scope

  • Reproduce findings hands-on using tools like Burp Suite
  • Rate severity accurately using established frameworks such as CVSS and OWASP
  • Write clear, accurate, customer-facing finding descriptions and remediation guidance that security practitioners trust and developers can act on
  • Maintain consistent standards across a high volume of findings
  • Surface patterns, edge cases, and unusual behaviors to the broader team
  • Identify patterns across findings and share feedback on where and how Sybil can improve

Requirements

This role does not require software engineering experience. It requires deep familiarity with web vulnerabilities, sharp analytical judgment, and the ability to communicate findings precisely. If you have spent time in bug bounty, application security, or pentesting and have a strong eye for what is real and what is noise, we want to hear from you., * 2 or more years of hands-on experience with web application vulnerabilities through bug bounty, penetration testing, application security, or a similar role

  • Solid, practical understanding of OWASP Top 10 and common web vulnerability classes: you have actually found and confirmed these, not just read about them
  • Experience reproducing and validating findings manually, including in ambiguous or noisy environments
  • Comfort with tools like Burp Suite, browser developer tools, or similar for hands-on verification
  • Strong written communication: you can describe a vulnerability, its impact, and how to fix it in plain language
  • Attention to detail and consistency: you apply the same standard to the hundredth finding that you applied to the first
  • Self-direction: you manage your own work without needing someone to structure your day

Benefits & conditions

Compensation: The base salary for this full-time position ranges from $130,000-$160,000. In addition to base salary, we offer meaningful equity. We want everyone here to have ownership in what we’re building.

About the company

Founded in 2023 by Ari Herbert-Voss and Vlad Ionescu, RunSybil is on a mission to automate hacker intuition. We are building Sybil, an AI-driven pentester that discovers vulnerabilities before they are exploited. As adversaries adopt AI to expand their attack surface, we are putting cutting-edge offensive security into the hands of defenders. Backed by strong investor support and early customer traction, our team includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:30 min

Evaluating and selecting an AI pair programming tool

Alexander Trusheim Alexander Trusheim +1 · World Congress 2025

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

Videos

See all

Related articles

See all