Senior Security Operations Engineer (Europe Remote)
Brak informacji o wynagrodzeniu
SeniorFull-time
#449204·Dodano 3 dni temu·1
Źródło: Invicti SecurityTech Stack / Keywords
JavaScriptPythonDASTOpenGrepSemgrepBurp SuitesqlmapnmapffufYARA
Firma i stanowisko
Invicti Security delivers an application security platform recognized as a leader in Application Security Testing and a DAST innovator. Headquartered in Austin, Texas, the company serves more than 3,600 organizations worldwide with continuous web application and API security solutions.
Wymagania
- 5+ years of offensive security or application security research experience (Bachelor's plus 2 years or equivalent).
- Broad programming language knowledge; JavaScript required, Python is a significant plus.
- Strong understanding of vulnerability classifications, exploitation techniques, and software weakness taxonomies.
- Experience writing detections for DAST scanners, fuzzers, or similar with knowledge of detection logic and false-positive management.
- Hands-on web application penetration testing experience covering OWASP Top 10, authentication, authorization, business logic, and modern APIs (REST, GraphQL).
- Capable of tackling complex problems and algorithms, including parsing with ASTs.
- Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems beneficial.
- Familiarity with offensive security tools like Burp Suite, sqlmap, nmap, ffuf, and HTTP/web protocols.
- Knowledge of cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
- Fluent in English, able to communicate technical details to both technical and non-technical audiences.
- Collaborative across multidisciplinary teams with ability to escalate issues appropriately.
- Hands-on attitude with intellectual curiosity for both traditional AppSec and emerging areas like AI security, LLM vulnerabilities, and agentic systems.
Nice to have:
- Experience with OpenGrep or Semgrep.
- Static analysis experience.
- Experience building production-ready systems.
- Exposure to LLMs and prompt engineering.
- Public security research output (CVEs, advisories, talks, open-source tools) or interest in technical writing.
- Experience with YARA.
Obowiązki
- Build and maintain security checks and detection content with focus on accuracy and low false-positive rates.
- Create new detection rules primarily using OpenGrep to identify malware and vulnerability patterns.
- Research vulnerability classes, exploitation techniques, and emerging attack patterns and translate them into detection content.
- Extend support for new programming languages in the analysis pipeline.
- Triage analysis pipeline packages and validate findings.
- Build attack chain templates combining low-severity findings into higher-impact scenarios.
- Contribute to evaluation harnesses and benchmarks measuring detection effectiveness.
- Build and maintain testing frameworks validating detection quality and exploit reproducibility.
- Maintain detection quality across the platform, including triaging difficult findings.
- Apply and refine internal detection and exploitation standards and methodologies.
- Explore new tools and techniques to detect threats and malware at scale.
- Stay updated on AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, and emerging attack techniques.
- Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
- Work with cloud-native infrastructure and CI/CD pipelines to integrate detection and validation into development lifecycle.
Benefity
- Tailored health, pension, and statutory perks customized to the country of residence.
- Employee Assistance Program offering 24/7 emotional support counseling, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new parent support.
- Remote work options.
- Quarterly Thrive-Wellness Days: one extra vacation day per quarter for company-wide refresh.
- Five days paid volunteerism time off annually.
- Paid birthday off.
- Ongoing employee recognition and rewards.
- Culture emphasizing personal and professional growth.
- Competitive compensation, meaningful benefits, and opportunities for recognition and development aligned globally with regional needs.
Opieka zdrowotna
Elastyczne godziny
Inne informacje
Location requirement: Candidates must reside anywhere in Europe within the CET ± 2 hours time zones.
Invicti Security
2 aktywne oferty