Vulnary
The Arsenal · By invitation

We don’t hire headcount. We keep an arsenal.

Vulnary runs lean and adversarial. When an engagement outgrows the core team, we don’t scramble; we reach into a pre-vetted arsenal of operators we already trust. This is the door to that Arsenal.

OPEN ROLES

FOUR POSITIONS OPEN

Everything else runs through the Arsenal. These four are core hires: one builds the platform, one takes it to market, one builds the channel, and one owns the voice.
ENGINEERING · CORE TEAM

AI ENGINEER, OFFENSIVE SECURITY

Cairo, Egypt (Hybrid)
ROLE DETAILS +

Build the researcher that never leaves the chair.

This is the core engineering role at the company. You will design and ship the autonomous agent systems that plan, act, and verify against real-world targets with no human in the loop. Not a chatbot, not a copilot. A system that does offensive work end to end and proves its results.

The hard part is not calling a model. The hard part is making an autonomous, model-driven system that is reliable, reproducible, and safe to run unattended against live targets. That is the deterministic control layer we wrap around every decision, and it is where a lot of your work will live. If you have ever looked at agent demos and thought “impressive, but I would never let that run alone against something that matters,” this is the role where you work on that.

WHAT YOU'LL OWN
Design, build, and ship the autonomous offensive agents at the heart of the platform: long-running systems that operate across code, infrastructure, and models
Engineer the deterministic control and orchestration layer that makes model-driven decisions reproducible, auditable, and recoverable under failure
Own agent state, evaluation, and the guardrails that let the system run with no one watching
Turn current offensive research into production capability, and keep it fast, observable, and hard to fool
Set the engineering bar: testing, provenance, and determinism as defaults, not afterthoughts
WHAT YOU BRING
Python and Go are mandatory. You are fluent and production-grade in both.
Strong systems engineering: concurrency, distributed workloads, clean interfaces, code that holds up under load and under scrutiny
A real offensive-security background. You have done vuln research, exploit development, red teaming, or serious pentesting, and you think like an attacker by instinct
Fluency with LLM and agent tooling, and firm opinions about determinism and provenance over vibes
The judgment to build systems that are powerful and controlled at the same time
NICE TO HAVE
CVEs to your name, a competitive CTF history, or published research
Reverse engineering and low-level chops
Experience running agentic or ML systems in production, including the ops around them
Send proof, not a cover letter. [email protected] APPLY FOR THIS ROLE
COMMERCIAL · CORE TEAM

ACCOUNT EXECUTIVE

Enterprise & strategic accounts · Hybrid · Arabic and English
ROLE DETAILS +

Sell proof, not probability.

You will be one of the first commercial hires at a company whose product does something buyers have been told is impossible: prove exploitability, autonomously, and stand behind it. That is a rare thing to sell. Your job is to get the right people in the room and let the proof do the closing.

ROLE OVERVIEW

This is an early sales seat. There is a story to tell, an early pipeline to build, and a playbook to write that every future rep will inherit. You will work shoulder to shoulder with the operators who do the technical work, so you always sell exactly what we ship and never a word more.

WHAT YOU WILL DO
Drive B2B cybersecurity and offensive security sales across enterprise and strategic accounts.
Own new-logo acquisition, pipeline generation, forecasting, and revenue growth.
Build and execute account plans and stakeholder maps for high-value strategic accounts.
Engage CISOs, CIOs, CTOs, and security leadership to uncover and shape business opportunities.
Position and sell AI-powered cybersecurity and Adversarial Exposure Validation solutions.
Lead complex, multi-stakeholder sales cycles from prospecting through negotiation and close.
Develop and scale strategic partners, resellers, and channel relationships.
Own quota achievement, deal strategy, and revenue targets.
Translate customer security challenges into clear business value and compelling solutions.
Represent Vulnary with strong executive communication, negotiation, and closing skills.
WHAT YOU WILL BRING
3-5 years of proven B2B cybersecurity / enterprise sales experience.
Strong track record of winning new logos and closing complex, high-value deals.
Experience selling SaaS, cybersecurity, cloud, or technology solutions to enterprise and strategic accounts.
Proven ability to build account plans, pipeline, and GTM strategies that drive measurable revenue.
Strong access to and experience engaging CISOs, CIOs, CTOs, and senior security decision-makers.
Experience building channel, partner, and ecosystem relationships to accelerate growth.
Entrepreneurial mindset with the ability to build the market, not just manage it.
Strong communication, negotiation, presentation, and closing skills in Arabic and English.
WHAT YOU’LL GET
Competitive compensation with performance-based incentives.
High growth startup environment with significant ownership and impact.
Career growth with opportunities to build and lead the sales organization.
Flexible and hybrid working environment.
Direct exposure to cutting edge AI and cybersecurity technologies.
Be part of a team building the next generation of offensive security and continuous validation.
JOIN VULNARY

If you are driven to build, sell, and shape the future of cybersecurity, we want to hear from you. Bring your experience, ambition, and unique perspective to help Vulnary scale and make a real impact.

This job description provides a general overview of the role and is not intended to be exhaustive. Responsibilities and requirements may evolve as Vulnary grows.

EQUAL EMPLOYMENT OPPORTUNITY

Vulnary is committed to providing equal employment opportunities to all employees and applicants. We value diversity and make employment decisions based on skills, qualifications, experience, and business needs, without discrimination based on any characteristic protected by applicable laws.

This commitment applies across all aspects of employment, including recruitment, hiring, compensation, development, promotion and benefits.

Send proof, not a cover letter. [email protected] APPLY FOR THIS ROLE
COMMERCIAL · 1 OPENING

CHANNEL ACCOUNT MANAGER

Partner & reseller ecosystem · Remote — EU timezones
ROLE DETAILS +

Build the channel that carries the proof.

Vulnary sells something buyers have been told is impossible: proven exploitability, produced autonomously, and stood behind. Eastern Europe has a dense, technical reseller market already selling security into regulated industries. Your job is to find the partners who can carry that claim credibly, and to make them good at it.

ROLE OVERVIEW

This is a senior regional seat with a blank sheet. There is no partner programme in Eastern Europe yet: you decide who we work with, on what terms, and what good looks like. You will work directly with the operators who run engagements, so what a partner promises is always what we ship.

WHAT YOU WILL DO
Recruit, onboard, and grow resellers, MSSPs, and integrators across Eastern Europe.
Build the partner programme from nothing: tiers, margins, enablement, and rules of engagement.
Own regional channel revenue, including pipeline, forecasting, and partner-sourced growth.
Enable partner sales and technical teams to position adversarial exposure validation accurately.
Run joint go-to-market with partners: campaigns, events, and co-selling into named accounts.
Work alongside direct sales so channel and direct never collide on the same account.
Bring partners into conversations with CISOs, CIOs, and security leadership, and stay in the room.
Hold partners to agreed targets, and act on what the numbers say rather than on the relationship.
Represent Vulnary at regional security events and in partner executive conversations.
Feed what the region is telling you back into product, pricing, and positioning.
WHAT YOU WILL BRING
5-8 years in channel, partner, or alliance management within cybersecurity or enterprise software.
A working reseller, MSSP, or distributor network across Eastern Europe that you can activate.
A track record of building a partner programme, not only managing one you inherited.
Experience selling security into regulated industries: finance, telco, public sector, critical infrastructure.
Enough technical depth to hold a credible conversation about exploitation and validation.
Strong communication, negotiation, and presentation skills in English.
Willingness to travel across the region for partner and customer meetings.
An entrepreneurial mindset: this region is a blank sheet, not a territory to maintain.
WHAT YOU’LL GET
Competitive compensation with performance-based incentives.
Ownership of an entire region, with the mandate to build it your way.
High growth startup environment with significant ownership and impact.
Career growth toward regional or channel leadership as the programme scales.
Remote working across EU timezones, with travel where it earns its keep.
Direct exposure to cutting edge AI and cybersecurity technologies.
JOIN VULNARY

If you are driven to build, sell, and shape the future of cybersecurity, we want to hear from you. Bring your experience, ambition, and unique perspective to help Vulnary scale and make a real impact.

This job description provides a general overview of the role and is not intended to be exhaustive. Responsibilities and requirements may evolve as Vulnary grows.

EQUAL EMPLOYMENT OPPORTUNITY

Vulnary is committed to providing equal employment opportunities to all employees and applicants. We value diversity and make employment decisions based on skills, qualifications, experience, and business needs, without discrimination based on any characteristic protected by applicable laws.

This commitment applies across all aspects of employment, including recruitment, hiring, compensation, development, promotion and benefits.

Send proof, not a cover letter. [email protected] APPLY FOR THIS ROLE
COMMUNICATIONS · 1 OPENING

COMMUNITY MANAGER

Remote-friendly · outcome-driven
ROLE DETAILS +

Own the voice of an adversarial research lab.

We do work worth talking about, and right now almost no one outside our clients gets to see it. That is your mandate: build the audience, own the voice, and turn genuinely hard technical work into a following that trusts us, all without ever leaking a thing that is sealed under engagement.

You will be the connective tissue between a heads-down, senior team and the outside world. You do not need to pop shells, but you have to speak the language, respect the culture, and know instantly when something reads as fake.

WHAT YOU'LL OWN
The voice: channels, social, and the narrative that makes a technical crowd pay attention
Turning our public research and technical work into stories that land and get shared
Growing and tending a real community, not a follower count
Keeping the hiring and partner funnels warm, so the right people find us at the right moment
Being the outside world’s read on us, and our read on it
WHAT YOU BRING
A strong writer with real security and tech literacy. A terminal does not scare you, and jargon does not fool you.
A genuine feel for hacker and research culture and its low tolerance for spin
A track record building a community, newsletter, publication, or research following from a standing start
Self-starting ownership: you can run the voice end to end without a committee
NICE TO HAVE
An existing presence in infosec circles
Design, video, or multimedia chops
Experience running a security-focused community or event
HOW WE WORK
Senior and small. No layers, no busywork, no proving yourself to a committee. Ownership from day one.
Fast and honest. We ship, we measure, we say what is true even when it is inconvenient. Especially then.
Remote-friendly, outcome-driven. We care what you ship, not where you sit.
Deep work respected. The team is heads-down by design. We protect focus.
WHAT WE OFFER
Competitive base and a front-row seat as the company is built
Work that is genuinely hard and genuinely matters, alongside people at the top of this field
A rare chance to define a category rather than iterate inside one
Send proof, not a cover letter. [email protected] APPLY FOR THIS ROLE
A · WHY THE ARSENAL

AN ELITE NETWORK, NOT A ROSTER

Most consultancies grow by hiring people they then have to keep busy. We grew the other way: a tiny core of principals, an autonomous researcher wired into our clients’ pipelines, and a curated network of specialists we call in when the work demands a particular edge. You stay independent. We bring you the engagements your skills were sharpened for, and the proof-driven culture to do them in.

Real work, not busywork.
You’re called for engagements that fit your edge: overflow on Sprints and Campaigns, second pairs of eyes, specialist passes the core team can’t cover alone.
Proof over paperwork.
We sell working exploits and the fixes that end them, not risk scores. The culture rewards the operator who lands the shell, not the one who writes the longest caveat.
Stay independent.
No exclusivity, no quota. You keep your own practice; we keep your number for when something interesting lands.
Work beside The Resident.
Our autonomous adversary does the grind (recon, reconstruction, triage), so your hours go where the human edge actually matters.
B · WHAT WE LOOK FOR

OPERATORS WHO LAND THE PROOF

Discipline-agnostic about titles, obsessive about evidence. Depth in one of these wins over a shallow sweep of all four.
THE OPERATOR
PENETRATION TESTING

Walk the whole kill-chain, not the scanner’s first door. Web, network, application and cloud, plus the AI/agent layer most teams never test. End to end, proven.

web & network cloud / AD red-team ops full kill-chain
THE AUDITOR
CODE REVIEW

Read a codebase like an attacker. Reason across call-flows to the sink, and prove each finding with a working exploit: white-box or black-box, source or binary.

source audit taint & call-flow SAST triage proof-driven
THE ARMORER
EXPLOIT DEVELOPMENT

Turn a flaw into a receipt. Discover the bug, weaponize a reliable PoC, and reverse what you have to along the way. Memory corruption to logic abuse.

CVE / 0-day weaponized PoC reverse engineering fuzzing
THE ADVERSARY
RED-TEAM & LLM ATTACKS

Apply nation-state pressure to models, agents and pipelines: prompt injection, jailbreak automation, model extraction, guardrail bypass, agent abuse at scale.

prompt injection jailbreak automation model extraction agent abuse

Self-taught and decorated welcome alike. We weight a public CVE, a clean write-up, a CTF podium, or a bug-bounty wall over any certification. Bring links.

C · THE MODEL

APPLY. SCREEN. STAY ON-CALL.

The Arsenal is vetted, not crowdsourced. Everyone on it has been screened by a principal and proven they can land a result.
01
APPLY

Send your strongest evidence: a CVE, a PoC, a write-up, a CTF result, a repo. One real thing you broke beats a polished CV. No cover letters.

02
SCREEN

A principal reads your work. We’re looking for depth, sound method, and proof rather than breadth. If the work lands, you move forward.

03
INTERVIEW

A working conversation with the people you’d actually run beside; sometimes a small hands-on challenge in your discipline. Technical, candid, two-way.

04
IN THE ARSENAL

You join the vetted network as a trusted reference and on-call capacity. We reach out when an engagement needs your edge: overflow, specialist passes, second eyes. Independent, no quota.

D · APPLY

Think you’d sharpen the Arsenal?

No quota, no exclusivity. Send proof, we read every one.

THE ARSENAL
an elite arsenal, by invitation · proof over paperwork
Vulnary

Controlled attack operations against production environments. Demonstrated findings, documented method, reproducible results.

DISCLOSURE [email protected]
PLATFORM
The Resident
ENGAGEMENTS
Rules of engagement Scoping & methodology Independent review Request an engagement
LEGAL
Terms of Use Terms & Conditions Privacy Policy Cookies Policy
COMPANY
About Careers Press Partners Contact
Put your defenses to the proof.
Under NDA. We start by trying to break it.
United States Egypt United Arab Emirates
LinkedIn © 2026 Vulnary