* If you're interested in web security, you'd want to be conversant in protocol-level HTTP; a good acid test might be "could quickly implement chunked encoding".
* If you're interested in OS security, you'd want to be conversant in virtual memory management and system call interfaces; a good acid test might be "could implement the userland side of a system call without using the library stubs".
* If you're interested in software security, you'd want to be conversant in C/C++.
If you're interested in security research at all, feel free to email me. You can't waste my time. The only reason any of these technical items are here is that we hope they'll be attractive to the people we want to hire; we're not trying to disqualify anyone.