DevJobs

Solution Architect (Researcher) — CTO Office

Overview
Skills
  • Go Go
  • Python Python
  • TypeScript TypeScript
  • AWS AWS

Huskeys is building an intelligent security control layer for modern web applications. We work alongside existing WAFs to help security teams understand traffic behavior, reduce false positives, and protect applications without disrupting business.


This is a founding CTO Office role for a security researcher who can operate as an independent technical force multiplier. You will investigate hard web, API, cloud, WAF, and customer-security problems where the path is often unclear. You will turn incomplete signals into evidence, make judgment calls about what matters, build the minimum tooling or proof required, and convert the result into customer impact, product capability, or a clear decision to stop.

This is not a pure research role, a conventional solutions-architect role, or a strategy-only role. You must be equally comfortable reading traffic and infrastructure behavior, writing and running code, speaking with customers, and deciding what should become product versus a one-off solution.

What You'll Do


  • Own ambiguous technical investigations from initial hypothesis to reproducible evidence and a concrete next action.
  • Partner with the Solution Architect to combine security research, systems engineering, and customer context into decisive technical outcomes.
  • Operate jointly when the problem demands it, and independently when speed, focus, or ownership require it.
  • Research web, API, cloud, WAF, CDN, network, and application-security behavior in real customer and market environments.
  • Build small, working tools, experiments, detectors, integrations, or proofs of concept when they are the fastest way to establish truth.
  • Distinguish a technically interesting observation from material customer risk, product opportunity, or noise.
  • Work directly with customers and internal teams to understand real deployment constraints, business impact, and operational tradeoffs.
  • Decide whether an outcome belongs in product, a customer-specific solution, the research backlog, external tooling, or nowhere.
  • Translate validated work into detection logic, findings, product requirements, remediation guidance, or an executive technical narrative.
  • Move rapidly between research, implementation, customer context, and product decisions; discard work quickly when evidence changes the answer.
  • Help shape Huskeys’ technical point of view through clear internal documentation and, where appropriate, external research.


Your First 90 Days


First 30 days — learn the terrain and establish technical credibility


  • Build a practical model of the Huskeys product, customer environments, WAF/log data, external scanning, and the security decisions customers need to make.
  • Reproduce and document one meaningful web, API, cloud, or WAF security behavior in a local lab or controlled environment.
  • Identify a focused investigation with the CTO: the decision it needs to support, the evidence required, the smallest credible experiment, and its expected outcome.
Days 31–60 — own a real investigation


  • Drive that investigation independently through data collection, technical validation, and a working artifact: a tool, experiment, detector, integration, or reproducible proof.
  • Communicate the evolving evidence, uncertainty, and tradeoffs clearly to the CTO and relevant Engineering or Product partners.
  • Make a recommendation grounded in the evidence: ship, investigate further, turn it into a customer-specific solution, escalate, or stop.


Days 61–90 — turn evidence into impact


  • Deliver one concrete, reviewable outcome that improves customer security, research capability, product direction, or technical decision-making.
  • Translate the work into an owned next step—such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a customer technical narrative.
  • Demonstrate that you can receive a loosely framed problem, choose the right scope, produce credible technical evidence, and move it to the correct owner or outcome without continuous direction.
Requirements


  • Demonstrated hands-on depth in at least two of: web application security, API security, cloud security, network security, WAF/CDN behavior, attack-surface management, bot/abuse defense, or infrastructure security.
  • Strong first-principles understanding of HTTP, DNS, TLS, proxies, load balancers, authentication, web applications, APIs, and cloud networking.
  • Evidence of independently taking a vague security problem to a working tool, reproducible proof, detection, investigation, or product outcome.
  • Ability to write and operate code for research and technical validation—Python, TypeScript, Go, or equivalent.
  • Judgment to decide what requires more investigation, what is ready to ship, what belongs to another team, and what should be killed.
  • Comfortable with customer ambiguity: incomplete data, competing priorities, non-technical stakeholders, and real delivery constraints.
  • Clear written communication for engineers, security teams, and executives.
  • Strong curiosity without confusing breadth of ideas with depth of understanding.


Especially Valuable


  • Research experience in WAF bypasses, origin exposure, cloud misconfiguration, API security, attack-surface discovery, or bot/agent abuse.
  • Familiarity with AWS and modern cloud environments.
  • Experience building detections, security products, or research tooling.
  • Experience working directly with enterprise customers on technical investigations or security outcomes.
  • Published research, open-source tools, CTF experience, or an equivalent research portfolio.


Why Huskeys


You’ll work on difficult, real-world web security problems with direct access to the people building the product. The goal is not research for its own sake: it is to make the internet harder to attack and give security teams a clearer path to action.


You will have unusual ownership, high context, and the ability to turn evidence into product and customer impact. In return, the role demands technical rigor, speed, judgment, and the willingness to own an outcome end to end.

Huskeys Security