AppSec Labs is a small team of application security specialists. We test web applications, REST APIs and mobile apps for a living — deep, manual, hands-on-keyboard work on real products, not scanner triage.

Who tends to do well here

  • You can find the bug that the tool did not: authorisation logic, tenant isolation, workflow abuse, chained issues that only make sense once you understand the business.
  • You can write a finding a developer can actually act on, and defend it in a room.
  • You are comfortable being the person who says “this is not exploitable” when it is not, and proving it either way.
  • Curiosity about how things break, and enough patience to keep going after the first three ideas fail.

What the work looks like

Real applications, varied stacks, and a lot of autonomy. We use our own platform to take the repetitive work out of an engagement, which means more of your time goes on the parts that need a human: attack strategy, business context, and judgement about what actually matters to the customer.

Open roles

We do not always have a role posted, but we always read applications from people who are good at this. Send us what you have worked on — research, write-ups, CVEs, bug bounty reports, a tool you built — and tell us what you want to be doing.

Who you would be joining

People who have worked here have gone on to write tools the industry still uses and to found companies acquired by Snyk, Check Point, Contrast Security and Zimperium — that story is here. The pattern is not an accident: on a small team, if you think a tool should exist, you build it, which is exactly how Autorize came to be written here.

Contact us or email info@appsec-labs.com.