At Coverity (http://coverity.com) we are looking for a security researcher with interest in static analysis. The candidate must be a strong in websec, doesn't be afraid to write code (checker prototypes, etc.), and the best would be to have some prior knowledge in static analysis (which doesn't need to be you wrote your own static analysis tool for brainf*ck or something).
We have a description here on linkedin (http://linkd.in/VxL5bx) and you can apply there or just contact me directly (@rgaucher || rgaucher /at/ coverity.com). To have an idea of what we're doing, some of it is on our blog (https://communities.coverity.com/blogs/security).
Nope, it's just a spoofing issue, that doesn't affect (as far as I tested) the actual implementation of Same Origin Policy by Safari. I.e., you cannot get access to my-cool-site.com DOM, if you're leveraging this bug.