Source description
About the role
Role Overview: You are required to be a highly skilled Cybersecurity Expert at MillionLogics, where you will be responsible for designing and developing advanced evaluation tasks for frontier AI models. Your main tasks will include creating realistic adversarial security scenarios to test AI models' understanding of code, vulnerability detection, and reasoning abilities in complex software security problems. This role will not be traditional security work as you will be at the intersection of offensive security, defensive engineering, and AI evaluation. Key Responsibilities: - Design and develop multi-vulnerability (multi-CWE) codebases in languages like Go, Python, Node.js, or Rust - Create multi-stage attack chains by combining various vulnerability classes into realistic exploit scenarios - Build deterministic evaluation frameworks using containerized environments and automated verification systems - Write security test cases and exploit checks to ensure proper detection and mitigation of vulnerabilities - Analyze AI model outputs and reasoning traces to pinpoint failure points in security understanding - Craft adversarial scenarios such as misleading documentation, obfuscated code, and edge-case logic - Balance real-world CVE-based scenarios with synthetic vulnerability classes for robust evaluation - Ensure reproducibility, scalability, and resistance to data contamination in evaluation tasks Qualifications Required: - 4+ years of experience in cybersecurity, application security, or vulnerability research - Hands-on experience in vulnerability discovery, secure code review, and production-grade patching - Deep understanding of web security, SSRF, injection attacks, access control, cryptographic vulnerabilities, and filesystem vulnerabilities - Experience in building or using security tools and proficiency in at least two of Go, Python, Node.js, Rust - Familiarity with Docker, containerized environments, Linux internals, and system-level behavior - Strong problem-solving and analytical skills, especially in attack chain reasoning - Ability to read and analyze obfuscated or minified code - Commitment of 40 hours per week with a 4-hour overlap with PST - Engagement Type: Contractor assignment (no medical/paid leave) Role Overview: You are required to be a highly skilled Cybersecurity Expert at MillionLogics, where you will be responsible for designing and developing advanced evaluation tasks for frontier AI models. Your main tasks will include creating realistic adversarial security scenarios to test AI models' understanding of code, vulnerability detection, and reasoning abilities in complex software security problems. This role will not be traditional security work as you will be at the intersection of offensive security, defensive engineering, and AI evaluation. Key Responsibilities: - Design and develop multi-vulnerability (multi-CWE) codebases in languages like Go, Python, Node.js, or Rust - Create multi-stage attack chains by combining various vulnerability classes into realistic exploit scenarios - Build deterministic evaluation frameworks using containerized environments and automated verification systems - Write security test cases and exploit checks to ensure proper detection and mitigation of vulnerabilities - Analyze AI model outputs and reasoning traces to pinpoint failure points in security understanding - Craft adversarial scenarios such as misleading documentation, obfuscated code, and edge-case logic - Balance real-world CVE-based scenarios with synthetic vulnerability classes for robust evaluation - Ensure reproducibility, scalability, and resistance to data contamination in evaluation tasks Qualifications Required: - 4+ years of experience in cybersecurity, application security, or vulnerability research - Hands-on experience in vulnerability discovery, secure code review, and production-grade patching - Deep understanding of web security, SSRF, injection attacks, access control, cryptographic vulnerabilities, and filesystem vulnerabilities - Experience in building or using security tools and proficiency in at least two of Go, Python, Node.js, Rust - Familiarity with Docker, containerized environments, Linux internals, and system-level behavior - Strong problem-solving and analytical skills, especially in attack chain reasoning - Ability to read and analyze obfuscated or minified code - Commitment of 40 hours per week with a 4-hour overlap with PST - Engagement Type: Contractor assignment (no medical/paid leave)
More at MillionLogics