Design and build agentic systems that autonomously perform vulnerability research against real targets including firmware, network stacks, mobile OSes, and IoT. Wire emulation, instrumentation, fuzzing, and exploit primitives into tool interfaces for AI agents. Develop evaluation and benchmarking infrastructure to measure system effectiveness.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Zealot (zealotlabs.com) builds AI systems that find zero-days, emulate target devices, and develop working exploits for U.S. defense and intelligence customers. We're backed by tier-1 U.S. venture firms and industry leaders, and our team includes alumni of Anthropic, xAI, NSA, USCYBERCOM, Anduril, Unit 8200, and the Mossad.
We're looking for vulnerability researchers to help design and build our agentic systems that autonomously perform vulnerability research against real targets — firmware, network stacks, mobile OSes, IoT. That means wiring emulation (QEMU, Unicorn, Qiling), instrumentation (Frida, DynamoRIO), fuzzing, and exploit primitives into tool interfaces for agents, as well as the evaluation & benchmarking infrastructure to know whether any of it is working.
What we're looking for
- 2–3+ years across systems programming (C/C++, Rust) and ML infrastructure
- Comfort with binary analysis, memory corruption classes, and modern mitigations (ASLR, CFI, PAC, MTE)
- Hands-on work with agent harnesses — orchestration, tool-use, eval loops — in production or at benchmark scale
- Fluency with at least one emulation stack (QEMU, Unicorn, Qiling, PANDA, FirmAE)
- Strong RE / debugger chops (GDB, IDA or Ghidra) and the patience to use them
Looking to advance your Development & Programming career with relocation support? Explore Development & Programming Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
Nice to have
Pwn-heavy CTF experience (DEF CON finals, PPP, DiceGang, Shellphish, Theori, Team Atlanta), public CVEs, conference talks, AIxCC / CGC participation, or kernel / baseband RE.
Read this part carefully
That list is what the fully-formed version of this role looks like. It's not a filter. If you're sharp, hungry, and funny, apply anyway — even if half the bullets read like a foreign language today. Tech can be learned. Spirit cannot. We've watched the right people pick up binary exploitation from scratch and outship ten-year veterans inside a year. Tell us what you've taught yourself recently and what you'd tear into first here.
If Relocation is a dealbreaker, there is an option to work in TLV
Similar Jobs
Explore other opportunities that match your interests