Safety Spot
Cybersecurity Researcher
Canada · Vp
Sponsorship not specifiedDetected 223 days ago
JavaScriptPythonJavaFull-Stack DevelopmentMachine LearningData EngineeringNLPLLMsCybersecurityDetection EngineeringSupply ChainFirewallResearchLeadershipCommunicationCollaborationPublic SpeakingAdaptability
About the role
- As a Cybersecurity Researcher, you'll be the engine behind what makes Safety's security offering better than alternatives.
- Your research will directly contribute to protecting thousands of developers worldwide and millions of package installations across Python, Java, and JavaScript ecosystems.
Responsibilities
- Enrich Vulnerability Data: Review and validate vulnerabilities, adding reachability analysis and context that makes Safety's database more accurate than baseline sources like OSV
- Reduce False Positives: Refine our own tooling and the detection logic by analyzing flagged packages, documenting patterns, and optimizing rules to improve customer trust
- Build AI-Driven Detection Systems: Collaborate with data engineers to develop LLM-assisted analysis tools and automated detection processes that scale to 70,000+ daily package releases
- Drive Research Innovation: Experiment with AI-powered techniques for vulnerability detection, changelog analysis, and threat identification to stay ahead of emerging attacks
- Ship with Velocity: Embrace fast-paced iteration, deliver detection improvements quickly, refine based on customer feedback, and see your work protect thousands of developers and environments within days
- Detection Development: Track record of building or improving automated security detection systems, including writing rules, reducing false positives, and scaling analysis to large datasets
- Experience building or contributing to security tools, malware analysis frameworks, or threat intelligence platforms
Requirements
- Security Research Experience: multi-year experience in cybersecurity research with hands-on experience investigating both accidental vulnerabilities and intentionally malicious components in software supply chains
- Ecosystem Expertise: Deep understanding of package ecosystems (PyPI, npm, Maven) including how they work, common attack vectors, and vulnerability patterns, with programming ability in Python, Java, or JavaScript
- AI-Powered Analysis: Experience using LLMs (GPT, Claude, Copilot) for security research, code analysis, or threat detection.
- Experience with data engineering pipelines or working closely with ML/data teams
Skills
- Safety secures the software supply chain for the world's data and development teams.
- Your research becomes the intelligence layer behind Safety's Firewall.
- This isn't research in isolation.
Compensation
- 20 days paid vacation per year
- Ability to work remotely and thrive in an adaptable, inclusive environment
- Competitive salary: 120,000 CAD - 150,000 CAD (depending on experience)
- Our Team Culture
- We believe in building products that make a real difference in the security landscape.
- One of our core commitments to our team and the culture is fostering belonging.
Benefits
- We prioritize supporting our team's growth, wellness, and success.
- Compensation & Benefits
- Benefits include:
- Private Healthcare Plan
- Generous equity stock options to share in our success
- Flexible working hours, providing responsibilities are effectively managed
Company info
- We protect everywhere packages are actually used, from local developer machines to production environments, from traditional IDEs to AI coding assistants without disrupting existing workflows.
- Our mission is to make open source packaging secure by default, providing complete visibility, governance, and protection across Python, Java, and JavaScript ecosystems.
- We're building the infrastructure that will secure companies and shape how enterprises adopt AI-driven development safely.
- If you're passionate about defending critical infrastructure at scale and want your work to directly protect millions of installations, we want you to join us.
- Analyze suspicious packages across PyPI, npm, and Maven in real-time, developing detection rules that protect customers before threats reach production
- Hunt Malicious Packages: Analyze suspicious packages across PyPI, npm, and Maven in real-time, developing detection rules that protect customers before threats reach production
Apply directly at Safety Spot →Create a free account for alerts like thisView Safety Spot immigration profile
This listing is sourced directly from Safety Spot's careers page and normalized into a canonical job model.