Cryptography
Security Researcher, Key Management
Break our key management before anyone else does, then help us fix it.
- team: Cryptography
- location: Remote
- type: Full-time
- level: Mid–Senior
The role
We publish our falsifiers because we would rather be wrong in private than in production. You are the person who makes us wrong: you attack the key lifecycle — generation, storage, rotation, and destruction — and report what you find.
The best version of this role puts itself out of a job by making the system boring to attack.
What you will do
Build a standing threat model for the key management surface and keep it current.
Run adversarial reviews of issuance, storage, and revocation paths.
Turn findings into reproducible tests that ship as regressions.
Contribute to the public falsifiers we hold ourselves to.
What we look for
A track record of finding real cryptographic or key-handling flaws — research, CTFs, disclosures, or production incidents.
You write clear, reproducible reports.
You are curious about systems, not just bugs.
Apply for this role
Your details go straight to the hiring team — every application gets a human read.