PhD Intern — Offensive Security & AI
hawksbillDenver (CO)
About the role
PhD Intern — Offensive Security & AI
Company: Hawksbill
Location: Honolulu, Hawaii / remote eligibility
About the Role:
Hawksbill develops offensive security capabilities that help organizations discover exploitable weaknesses, understand their consequences, and verify that defenses work. We combine hands-on security research with AI to advance vulnerability discovery and adversarial testing across software, firmware, and connected systems. We are seeking a PhD Research Intern to investigate how AI can improve offensive security. You will work on a focused problem involving vulnerability discovery, program analysis, reverse engineering, or exploitability validation. The role combines experimental cybersecurity research with hands-on implementation: developing techniques, testing them against realistic targets, and producing reproducible evidence of what works and where current approaches fail.
Responsibilities:
Investigate vulnerabilities in software or firmware using techniques such as source-code analysis, reverse engineering, fuzzing, and dynamic testing. Develop and evaluate AI-assisted methods for identifying weaknesses, reasoning about program behavior, and validating potential vulnerabilities. Build prototypes that connect AI agents with security tools, debuggers, analysis frameworks, and controlled testing environments. Develop proof-of-concept demonstrations to establish exploitability and characterize security impact within authorized research environments. Design experiments that compare proposed methods with established approaches, measuring discovery effectiveness, false positives, reproducibility, and researcher effort.
Minimum Qualifications:
Currently pursuing a PhD in Computer Science, Cybersecurity, Computer Engineering, or a related field.experience in at least one relevant area: vulnerability research, software security, program analysis, reverse engineering, fuzzing, or systems security. Proficiency in Python and working knowledge of C/C++ or another language relevant to systems and security research. Familiarity with operating systems, software execution, debugging, and common vulnerability classes. Ability to implement research ideas, design rigorous experiments, and communicate technical findings clearly.
Preferred Qualifications:
Experience applying large language models or agentic systems to software analysis or security tasks. Familiarity with tools such as Ghidra, IDA Pro, GDB, LLVM, AFL++, or comparable frameworks. Experience with binary analysis, firmware analysis, symbolic execution, or exploit development. Evidence of hands-on security work through research publications, disclosed vulnerabilities, CTF participation, open-source contributions, or independent projects. What You Will Gain An opportunity to own a focused research project, test ideas against realistic security problems, and contribute to offensive security capabilities with practical applications. Depending on project results and disclosure constraints, the work may support publications, open-source contributions, or vulnerability disclosures.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
