Staff Security Researcher (Europe Remote)
Brak informacji o wynagrodzeniu
SeniorFull-time
#449203·Dodano 3 dni temu·2
Źródło: Invicti SecurityTech Stack / Keywords
JavaScriptPythonOpenGrepSemgrepBurp SuitesqlmapnmapffufKubernetesYARA
Firma i stanowisko
Invicti Security delivers an industry-leading application security platform with nearly 20 years of experience, serving over 3,600 organizations worldwide. The company focuses on continuous scanning and securing of web applications and APIs using DAST and runtime testing.
Wymagania
- 8+ years of offensive security or application security research experience.
- Broad knowledge of programming languages; JavaScript mandatory, Python a strong plus.
- Strong understanding of security principles, standards, and best practices.
- Deep knowledge of vulnerability classifications, exploitation methods, and secure software development.
- Proficiency in detection writing for DAST scanners, fuzzers, or comparable systems.
- Experience designing testing frameworks, evaluation harnesses, or validation systems for security tools.
- Deep web application pentesting experience covering OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL APIs.
- Comfortable with complex problem solving and algorithmic challenges (e.g., parsing with ASTs).
- Fluent with offensive tools like Burp Suite, sqlmap, nmap, ffuf, and HTTP/web protocol fundamentals.
- Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
- Practical experience with securing or researching LLM-powered applications, AI agents, prompt injection, model abuse, and emerging AI attack techniques.
- Fluent English with strong technical communication skills.
- Ability to collaborate across multidisciplinary teams and exercise judgment on issue escalation.
- Hands-on attitude, intellectual curiosity, and interest in application security, cloud-native security, and AI ecosystems.
Bonus Points:
- Experience with OpenGrep or Semgrep.
- Static analysis experience.
- Experience building production-ready systems.
- Public security research output (CVEs, advisories, talks, open-source tools).
- YARA experience.
Obowiązki
- Create new detection rules (primarily OpenGrep) for malware and vulnerability patterns to improve detection accuracy.
- Extend support for new programming languages in the analysis pipeline.
- Explore and experiment with cutting-edge tools to detect threats and malware at scale.
- Research exploitation techniques on modern web applications and APIs, building proof-of-concept attacks and shippable capabilities.
- Research new vulnerability classes, cloud-native attack paths, and AI-specific attack vectors, converting research into production-ready detections.
- Contribute to research policies, standards, and attack methodologies.
- Build attack chain templates combining low-severity findings into high-impact exploitations.
- Contribute to and design evaluation harnesses and benchmarking systems measuring detection effectiveness, false positives, coverage, and exploit reproducibility.
- Write and publish blog posts on novel attacks and incidents; represent Invicti in the security community through CVEs, tool releases, and conferences.
- Stay current on AppSec, AI red-teaming, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
- Triage analysis packages and validate findings.
- Mentor junior and mid-level researchers in detection writing and exploitation techniques.
- Collaborate across engineering, product, AI/ML, and infrastructure teams to maintain research outputs.
- Partner with platform and infrastructure teams to improve security automation in CI/CD pipelines and cloud environments.
- Maintain detection quality, triaging difficult or ambiguous findings.
Benefity
- Tailored health, pension, and statutory perks based on country of residence.
- Employee Assistance Program offering 24/7 emotional support, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new parent support.
- Flexible remote working options.
- Quarterly Thrive-Wellness Days (one extra vacation day per quarter).
- Five days of paid volunteer time off annually.
- Paid birthday off.
- Ongoing employee recognition and rewards.
- Culture supporting personal and professional growth.
- Competitive compensation and meaningful benefits structured globally with regional adaptation.
Elastyczne godziny
Płatny urlop
Opieka zdrowotna
Karta sportowa
Inne informacje
Open to candidates residing anywhere in Europe within CET ± 2 hours time zones.
Invicti Security
2 aktywne oferty