Engineering Roles

Formal Methods Researcher

You’ll develop approaches to make guarantees about code—proving that a program, or a patch to it, actually has the properties it claims. As AI systems learn to find and exploit vulnerabilities faster than people can analyze and patch them, the bottleneck is shifting to trust: can we be sure a fix is correct, and correct quickly enough to matter? You’ll build lightweight formal methods to answer that question at speed.

The Work
You’ll design and develop formal methods that prove properties of code. The resulting tools will determine whether a new patch holds the assurance properties it claims, so patching pipelines can be automated. That means designing tailorable definitions of correctness that separate real findings from noise, letting users tune the scope and formalization level of the properties they care about. You’ll build the query languages and tooling that make verification efficient enough to keep pace with discovery.
Much of the challenge is combining formal rigor with real-world speed: systems of interest are often obscure, may be embedded, and almost certainly lack documentation. Frontier AI is about to make the gap between discovery and patch much more dangerous. Your work will shrink that gap and develop new ways to reason about whether a proof or a lighter-weight property check is called for.
Who You Work With
You’ll collaborate with reverse engineers and vulnerability researchers who surface the flaws you reason about, cyber-physical systems engineers who build the models and analysis infrastructure you plug into, and program managers who translate assured fixes into mission impact. You’ll interact with customers who bring you real systems, real patches, and real deadlines, and you’ll help shape how AI-generated findings and fixes are validated before anyone relies on them.
What We Look For
A strong foundation in formal methods—theorem proving, model checking, abstract interpretation, SMT solving, or program analysis—and the judgment to apply it pragmatically rather than exhaustively. Fluency in a language like Rust, C, C++, OCaml, or Python; experience reasoning about code without source, low-level software, or security properties is valued, as is familiarity with applying AI to program analysis and with the challenge of validating AI-generated patches.

Open Positions

Ready to find your place?

Browse every open position for this role across all capability areas and all U.S. locations.

No current job openings were found.