Orchid Security

Application Security Researcher

Orchid Security  •  Illinois (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Who are we?

With $36M in seed funding and customers from Fortune 500 companies such as Costco and Repsol, Orchid Security is already on an exciting journey to deliver the next infrastructure layer in the security space. Behind our platform are advanced technologies, including Large Language Models (LLMs), enabling Orchid to provide unprecedented insight and action for enterprise identity security.

Core mission

In this role, you’ll analyze real-world environments, identify potential attack vectors, and work along our AI engineering team to translate your domain expertise into actionable, defined workflows. You’ll play a key role in guiding how our product analyzes and surfaces findings across fortune 500 enterprises.

What will you do?

  • Analyze large-scale data to identify attack opportunities and improve detection accuracy of identity-related security risks
  • Encode security expertise into AI-driven analysis - translating your understanding of how applications manage access into prompts, decision logic, and agentic workflows that power Orchid's AI analysis engine
  • Propose how AI agents detect and reason about real-world identity attack scenarios - including authentication bypasses, privilege escalation paths, and cross-system credential exposure, by collaborate with our AI engineering team to bring ideas from concept to shipped product
  • Conduct research on chaining vulnerabilities, logic flaws, and complex attack paths and actively contribute to research direction, ideation, and innovation within the team
  • Collaborate with product and engineering, ensuring AI-driven identity decisions stay grounded in how applications actually work in the wild
  • Participate in customer engagements across the full lifecycle, from POC to onboarding, delivering findings and presenting identity risk insights to technical and business stakeholders

Requirements

Requirements:

  • Proven cybersecurity expertise, offensive or defensive — security research, penetration testing, malware analysis, network forensics, incident response, or similar
  • Hands-on programming ability, with experience performing code-level analysis across modern development stacks
  • Ability to operate in a fast-paced startup environment, work under pressure
  • Ability to communicate complex technical concepts clearly
  • Team player who thrives in fast-paced, high-impact environments

Why Join Orchid Security?

  • Join Orchid Security at an exciting stage and make a real impact on shaping the future of security infrastructure! We’re building cutting-edge technology and looking for brilliant, curious, and creative minds to grow with us.
  • Great culture & perks – Competitive benefits, stock options, and exciting growth opportunities.
  • Purpose-driven workplace – We actively support local communities and encourage employees to be ambassadors of change.
Orchid Security

About Orchid Security

Orchid delivers an identity-first security orchestration platform. It enables organizations to continuously discover both self-hosted and SaaS applications, assess their native identity controls (and gaps), and remediate compliance and cyber exposure from a single point of control— without extensive effort or application recoding.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
New York, New York
Year Founded
Unknown
Social Media