Safety Spot

Safety Spot

Cybersecurity Researcher

Canada · Vp

Sponsorship not specifiedDetected 223 days ago
JavaScriptPythonJavaFull-Stack DevelopmentMachine LearningData EngineeringNLPLLMsCybersecurityDetection EngineeringSupply ChainFirewallResearchLeadershipCommunicationCollaborationPublic SpeakingAdaptability

About the role

  • As a Cybersecurity Researcher, you'll be the engine behind what makes Safety's security offering better than alternatives.
  • Your research will directly contribute to protecting thousands of developers worldwide and millions of package installations across Python, Java, and JavaScript ecosystems.

Responsibilities

  • Enrich Vulnerability Data: Review and validate vulnerabilities, adding reachability analysis and context that makes Safety's database more accurate than baseline sources like OSV
  • Reduce False Positives: Refine our own tooling and the detection logic by analyzing flagged packages, documenting patterns, and optimizing rules to improve customer trust
  • Build AI-Driven Detection Systems: Collaborate with data engineers to develop LLM-assisted analysis tools and automated detection processes that scale to 70,000+ daily package releases
  • Drive Research Innovation: Experiment with AI-powered techniques for vulnerability detection, changelog analysis, and threat identification to stay ahead of emerging attacks
  • Ship with Velocity: Embrace fast-paced iteration, deliver detection improvements quickly, refine based on customer feedback, and see your work protect thousands of developers and environments within days
  • Detection Development: Track record of building or improving automated security detection systems, including writing rules, reducing false positives, and scaling analysis to large datasets
  • Experience building or contributing to security tools, malware analysis frameworks, or threat intelligence platforms

Requirements

  • Security Research Experience: multi-year experience in cybersecurity research with hands-on experience investigating both accidental vulnerabilities and intentionally malicious components in software supply chains
  • Ecosystem Expertise: Deep understanding of package ecosystems (PyPI, npm, Maven) including how they work, common attack vectors, and vulnerability patterns, with programming ability in Python, Java, or JavaScript
  • AI-Powered Analysis: Experience using LLMs (GPT, Claude, Copilot) for security research, code analysis, or threat detection.
  • Experience with data engineering pipelines or working closely with ML/data teams

Skills

  • Safety secures the software supply chain for the world's data and development teams.
  • Your research becomes the intelligence layer behind Safety's Firewall.
  • This isn't research in isolation.

Compensation

  • 20 days paid vacation per year
  • Ability to work remotely and thrive in an adaptable, inclusive environment
  • Competitive salary: 120,000 CAD - 150,000 CAD (depending on experience)
  • Our Team Culture
  • We believe in building products that make a real difference in the security landscape.
  • One of our core commitments to our team and the culture is fostering belonging.

Benefits

  • We prioritize supporting our team's growth, wellness, and success.
  • Compensation & Benefits
  • Benefits include:
  • Private Healthcare Plan
  • Generous equity stock options to share in our success
  • Flexible working hours, providing responsibilities are effectively managed

Company info

  • We protect everywhere packages are actually used, from local developer machines to production environments, from traditional IDEs to AI coding assistants without disrupting existing workflows.
  • Our mission is to make open source packaging secure by default, providing complete visibility, governance, and protection across Python, Java, and JavaScript ecosystems.
  • We're building the infrastructure that will secure companies and shape how enterprises adopt AI-driven development safely.
  • If you're passionate about defending critical infrastructure at scale and want your work to directly protect millions of installations, we want you to join us.
  • Analyze suspicious packages across PyPI, npm, and Maven in real-time, developing detection rules that protect customers before threats reach production
  • Hunt Malicious Packages: Analyze suspicious packages across PyPI, npm, and Maven in real-time, developing detection rules that protect customers before threats reach production

This listing is sourced directly from Safety Spot's careers page and normalized into a canonical job model.