Job Description
Nullify runs autonomous security work most teams can't staff for. This role is the human edge of that — validating what our agents find, going after what they can't, and feeding every technique back into the system so it gets sharper.
n
What You'll Do
n
n
Run deep, manual web app pentests against customer surface area that automated scanning alone won't catch — auth flows, business logic, multi-step exploit chains.
n
Turn novel findings into reproducible techniques that get encoded back into Nullify's detection and validation agents.
n
Partner with customer security teams during engagements, from scoping through report-back.
n
Keep pace with the frontier: new frameworks, current auth patterns, new classes of vulnerability.
n
n
What You Bring
n
n
Real-world experience finding and exploiting vulnerabilities in production web applications — OWASP Top 10 and beyond.
n
Comfort working close to the metal: reading application code, tracing requests, building custom tooling when off-the-shelf doesn't cut it.
n
A bias toward proof over speculation — you validate before you report.
n
Bonus: experience training or evaluating AI systems on security tasks.
n
📌 Web Application Penetration Tester - Nullify (New South Wales)
🏢 Black Nova Venture Capital
📍 New South Wales
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.