Senior Security Operations Engineer (Europe Remote)

Brak informacji o wynagrodzeniu
SeniorFull-time
#449204·Dodano 3 dni temu·1
Źródło: Invicti Security
Aplikuj teraz

Tech Stack / Keywords

JavaScriptPythonDASTOpenGrepSemgrepBurp SuitesqlmapnmapffufYARA

Firma i stanowisko

Invicti Security delivers an application security platform recognized as a leader in Application Security Testing and a DAST innovator. Headquartered in Austin, Texas, the company serves more than 3,600 organizations worldwide with continuous web application and API security solutions.

Wymagania

  • 5+ years of offensive security or application security research experience (Bachelor's plus 2 years or equivalent).
  • Broad programming language knowledge; JavaScript required, Python is a significant plus.
  • Strong understanding of vulnerability classifications, exploitation techniques, and software weakness taxonomies.
  • Experience writing detections for DAST scanners, fuzzers, or similar with knowledge of detection logic and false-positive management.
  • Hands-on web application penetration testing experience covering OWASP Top 10, authentication, authorization, business logic, and modern APIs (REST, GraphQL).
  • Capable of tackling complex problems and algorithms, including parsing with ASTs.
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems beneficial.
  • Familiarity with offensive security tools like Burp Suite, sqlmap, nmap, ffuf, and HTTP/web protocols.
  • Knowledge of cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
  • Fluent in English, able to communicate technical details to both technical and non-technical audiences.
  • Collaborative across multidisciplinary teams with ability to escalate issues appropriately.
  • Hands-on attitude with intellectual curiosity for both traditional AppSec and emerging areas like AI security, LLM vulnerabilities, and agentic systems.

Nice to have:

  • Experience with OpenGrep or Semgrep.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Exposure to LLMs and prompt engineering.
  • Public security research output (CVEs, advisories, talks, open-source tools) or interest in technical writing.
  • Experience with YARA.

Obowiązki

  • Build and maintain security checks and detection content with focus on accuracy and low false-positive rates.
  • Create new detection rules primarily using OpenGrep to identify malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns and translate them into detection content.
  • Extend support for new programming languages in the analysis pipeline.
  • Triage analysis pipeline packages and validate findings.
  • Build attack chain templates combining low-severity findings into higher-impact scenarios.
  • Contribute to evaluation harnesses and benchmarks measuring detection effectiveness.
  • Build and maintain testing frameworks validating detection quality and exploit reproducibility.
  • Maintain detection quality across the platform, including triaging difficult findings.
  • Apply and refine internal detection and exploitation standards and methodologies.
  • Explore new tools and techniques to detect threats and malware at scale.
  • Stay updated on AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, and emerging attack techniques.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
  • Work with cloud-native infrastructure and CI/CD pipelines to integrate detection and validation into development lifecycle.

Benefity

  • Tailored health, pension, and statutory perks customized to the country of residence.
  • Employee Assistance Program offering 24/7 emotional support counseling, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new parent support.
  • Remote work options.
  • Quarterly Thrive-Wellness Days: one extra vacation day per quarter for company-wide refresh.
  • Five days paid volunteerism time off annually.
  • Paid birthday off.
  • Ongoing employee recognition and rewards.
  • Culture emphasizing personal and professional growth.
  • Competitive compensation, meaningful benefits, and opportunities for recognition and development aligned globally with regional needs.
Opieka zdrowotna
Elastyczne godziny

Inne informacje

Location requirement: Candidates must reside anywhere in Europe within the CET ± 2 hours time zones.

Invicti Security

Invicti Security

2 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz