Skip to content

Site search

Type to search Pages

All open roles

Cryptography

Security Researcher, Key Management

Break our key management before anyone else does, then help us fix it.

  • team: Cryptography
  • location: Remote
  • type: Full-time
  • level: Mid–Senior

The role

We publish our falsifiers because we would rather be wrong in private than in production. You are the person who makes us wrong: you attack the key lifecycle — generation, storage, rotation, and destruction — and report what you find.

The best version of this role puts itself out of a job by making the system boring to attack.

What you will do

Build a standing threat model for the key management surface and keep it current.

Run adversarial reviews of issuance, storage, and revocation paths.

Turn findings into reproducible tests that ship as regressions.

Contribute to the public falsifiers we hold ourselves to.

What we look for

A track record of finding real cryptographic or key-handling flaws — research, CTFs, disclosures, or production incidents.

You write clear, reproducible reports.

You are curious about systems, not just bugs.

Apply for this role

Your details go straight to the hiring team — every application gets a human read.