Root (root.io) Logo

Root (root.io)

Research Team Lead

Posted Yesterday
Be an Early Applicant
In-Office
Boston, MA
Senior level
In-Office
Boston, MA
Senior level
Lead and manage a research team to develop AI-powered solutions for vulnerability detection and patch generation in open source environments. Collaborate with engineering and product teams to translate research into practical applications and represent the company in the security community.
The summary above was generated by AI

Location: Preference for Boston area (Hybrid/Flexible)
Reports to: CTO

About Root

Root helps companies secure containerized software without disrupting workflows or requiring extensive retooling. We embed into existing CI/CD pipelines and registries to automatically remediate vulnerabilities—not just detect them. Our core technology powers deep, in-place security for open source and container ecosystems.

At the center of this is Patch Platoon: our agentic system that performs patch research and backport generation for open source libraries. Patch Platoon explores public advisories, source code, and changelogs to autonomously generate and test security patches, providing practical fixes even where upstream patches don’t yet exist.

About the Role

We’re looking for a hands-on and strategic Research Team Lead to drive Root’s agentic security research efforts. This role blends applied security research, AI/agentic system development, and software engineering—with a focus on turning innovation into production-level capabilities inside Patch Platoon and Root's broader platform.

You will build and lead a small, high-impact research team working on vulnerability detection, patch synthesis, and backport generation for real-world open source packages across ecosystems like Python, Go, Java, and C/C++. You’ll collaborate closely with Engineering, Product, and the CTO to convert research into reliable product functionality and cutting-edge automation.

Responsibilities
  • Build and lead Root’s research team focused on containerized and open source environments.
  • Direct the evolution of Patch Platoon—designing workflows that allow AI agents to discover, synthesize, and validate security patches autonomously.
  • Drive research into emerging threats, vulnerability patterns, and patch strategies across OSS ecosystems.
  • Develop PoCs, patch candidates, and validation harnesses that integrate directly into Root’s remediation pipeline.
  • Partner with Engineering to translate research into stable, repeatable capabilities embedded in the Root platform.
  • Represent Root’s thought leadership in the security community through blogs, CVE disclosures, conference talks, and OSS contributions.
  • Maintain strong feedback loops between real-world threat intelligence and Root’s remediation engine.
Requirements
  • 5+ years of experience in security research, vulnerability analysis, reverse engineering, or patch development.
  • Deep understanding of Linux internals, container technologies (e.g., Docker, Kubernetes), and cloud-native architectures.
  • Strong familiarity with open source ecosystems and package managers (e.g., pip, npm, apt, go mod).
  • Hands-on experience building and debugging agentic systems, LLM-based workflows, or autonomous security tools.
  • Proficiency in scripting and systems programming languages (e.g., Python, Go, C/C++).
  • Demonstrated experience converting research into deployable, product-grade solutions.
  • Experience mentoring or leading research-focused technical teams.
  • Excellent collaboration and communication skills across technical and product stakeholders.
  • Comfortable operating in a fast-paced, research-heavy startup environment.
Nice to Have
  • Experience building patch generators, diff analyzers, or backporting automation.
  • Familiarity with software supply chain risks, CI/CD pipeline security, or SBOM/VEX tooling.
  • Publications, CVEs, or talks at security conferences (e.g., Black Hat, DEF CON, Usenix, FIRST).
  • Familiarity with open source security tooling (e.g., Trivy, Syft, osv-scanner).
  • Based in the Boston area (or willing to travel occasionally to HQ).
Why Join Root?
  • Shape the future of container and OSS vulnerability remediation through AI-powered automation.
  • Help evolve the industry’s first production-grade agentic patch research and remediation system.
  • Work closely with experienced founders and CTO in a high-trust, low-ego environment.
  • Influence Root’s research and technical culture from the ground up.
  • Competitive salary, early-stage equity, and full benefits package.


Top Skills

C/C++
Docker
Go
Kubernetes
Python
HQ

Root (root.io) Boston, Massachusetts, USA Office

100 Summer St, Boston, MA , United States, 02136

Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
Boston, MA, USA
Easy Apply
Entry level
Entry level
Information Technology • Productivity • Professional Services • Software
As a SOC Analyst, you will monitor security events, investigate incidents, provide technical guidance, and document security processes. You will also work with customers on implementations and be involved in infrastructure migration projects.
Top Skills: Cloud Native TechnologiesDatadogSIEMSplunkSumologic
An Hour Ago
Easy Apply
Remote or Hybrid
Boston, MA, USA
Easy Apply
5-5
Senior level
5-5
Senior level
Information Technology • Productivity • Professional Services • Software
Develop software and web applications, analyze existing applications, integrate with third-party services, and work on customer implementations.
Top Skills: AWSAzureGCPGitJenkinsRestServicenowSoap
An Hour Ago
In-Office
5 Locations
Entry level
Entry level
Hardware • Information Technology • Internet of Things • Security • Semiconductor • Cybersecurity • Defense
The Computer Scientist at the FBI conducts forensic analyses, performs reverse engineering, and develops software solutions, focusing on vulnerability identification in mobile platforms and system integrity.
Top Skills: CC++JavaPythonSwift

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account