About the job
NVIDIA, widely recognized as one of the world’s most desirable employers, believes open-weight models are foundational to American AI leadership, cybersecurity, and defense through broad scientific scrutiny. As part of this mission, our AI Safety & Security Engineering team builds and evaluates AI-powered tooling that finds, validates, and patches software vulnerabilities, recognizing that finding a bug is only the beginning. We are seeking a Security Research Engineer to advance our Validate and Patch capabilities by establishing what counts as a confirmed vulnerability and defining what constitutes a truly correct, safe fix. In this critical role, you will apply rigorous security judgment to well-defined categories of vulnerabilities. These affect NVIDIA-internal targets. You will turn complex analysis into repeatable methods that improve software people rely on daily.
Responsibilities
Validation methods: Develop techniques that confirm vulnerabilities are real and reachable.
Patch methods: Advance approaches for generating and verifying safe fixes.
Quality standards: Define correctness, regression, and revalidation standards with reviewers.
Applied research: Work bounded vulnerability classes against internal targets.
Qualifications
Minimum
Bachelor's degree (or equivalent experience) with 5+ years in security research or software engineering.
Security foundations: Hands-on vulnerability research, fuzzing, program analysis, or secure development in C, C++, or Python.
Fix quality: Rigor about what makes a fix correct and safe, including regression and behavior preservation.
AI-assisted workflows: Comfort using AI-assisted tools for analysis and development.
Preferred
Public research: CVEs, advisories, or publications in vulnerability research.
Analysis tooling: Experience building or extending fuzzers, static analyzers, or symbolic-execution tools.
Agentic ML: Familiarity with LLM-based coding or analysis agents.