Point Wild
Cybersecurity
SeniorSecurityResearcher
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Security Researcher at Point Wild. Skills: Security research, Detection systems, Vulnerability analysis. Own detection pipeline end-to-end. Design detection systems”
What You'll Achieve.
Protect customers; Establish thought leadership; Drive community engagement; Produce actionable signal
Industry & Context.
Catching malicious packages; Catching compromised CI/CD pipelines; Turn findings into actionable intelligence; Triage findings; Summarize package diffs; Cluster related campaigns
What They're Looking For.
Must Have
4+ years of security research experience, published CVEs, GHSAs, or equivalent advisories, Deep expertise in multiple vulnerability classes, malicious packages, RCE, prototype pollution, deserialization, SSRF, auth bypasses, CI/CD attack paths, Experience designing and operating detection, scanning, or analysis pipelines at scale, programming skills in TypeScript, Python, Go, or Rust, ability to read code across multiple languages (JavaScript, Ruby, Java, PHP), Proven track record of writing high-quality technical blog posts quickly, hands-on experience using LLMs as research tools
Nice to Have
Contributions to OpenSSF, OSV, Sigstore, SLSA, or adjacent open source security projects, Reverse engineering experience with obfuscated JavaScript droppers, packed binaries, or malicious post-install scripts, Conference speaking experience at DEF CON, Black Hat, BSides, OffensiveCon, or Kaspersky SAS
What You'll Do.
Own detection pipeline end-to-end
Design detection systems
Hunt novel malicious packages
Coordinate with maintainers
Build internal tooling
Publish technically rigorous blog posts
Tune detection signals
How You'll Work.
Team & Collaboration
Coordinate with maintainers, foundations, and registries; Work with GitHub Security Advisories
Communication Scope
Publishing research; Writing technical blog posts
Full Job Description
Point Wild helps customers monitor, manage, and protect against the risks associated with their identities and personal information in a digital world. Backed by WndrCo, Warburg Pincus and General Catalyst, Point Wild is dedicated to creating the world’s most comprehensive portfolio of industry-leading cybersecurity solutions. Our vision is to become THE go-to resource for every cyber protection need individuals may face - today and in the future. Join us for the ride! About the Role You'll own the detection pipeline end-to-end for our software supply chain security platform, catching malicious packages and compromised CI/CD pipelines before they reach production systems. This hands-on role involves designing detection systems, hunting threats, disclosing vulnerabilities, and publishing research that protects customers and establishes our voice in the security community. You'll work directly with detection systems that scan open-source packages at scale and turn findings into actionable intelligence. What You'll Do Design systems that scan open-source packages (npm, PyPI, RubyGems, Maven, crates.io, Go modules, GitHub Actions, container images) for malicious behavior at scale Hunt novel malicious packages, typosquats, dependency confusion attempts, compromised maintainers, and CI/CD abuse patterns Coordinate with maintainers, foundations, and registries to file CVEs and work with GitHub Security Advisories and OSV schema Build internal tooling using static analysis and AI models to triage findings, summarize package diffs, and cluster related campaigns Publish technically rigorous blog posts for every significant finding that establish thought leadership and drive community engagement Tune detection signals, reduce false positives, and develop countermeasures against evolving sandbox evasion techniques What We're Looking For 4+ years of security research experience with published CVEs, GHSAs, or equivalent advisories with your name on them Deep expertise in multiple
Applying for this Senior Security Researcher role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Point Wild?
Real rants from real employees. Read before you apply.