
Senior Security Operations Engineer – Europe
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Romania.
• Develop and uphold security checks and detection content for the Invicti platform.
• Design new OpenGrep detection rules for innovative malware and vulnerability patterns.
• Investigate vulnerability classes, exploitation techniques, and emerging attack vectors.
• Convert research findings into production-ready detections.
• Enhance support for additional programming languages throughout the analysis pipeline.
• Triage analysis-pipeline packages and verify results.
• Create attack-chain templates that integrate low-severity findings into higher-impact detection scenarios.
• Assist in the development of evaluation harnesses and benchmarks to assess false-positive rates, coverage, and accuracy.
• Construct and maintain testing frameworks focused on detection quality, exploit reproducibility, and regression coverage.
• Address challenging or unclear findings while ensuring platform detection quality.
• Improve internal detection and exploitation standards and methodologies.
• Investigate new tools and techniques for large-scale threat and malware detection.
• Leverage current AppSec, offensive security, AI security, LLM vulnerability, AI agent security, MCP security, and emerging attack research in detection engineering.
• Collaborate with teams in engineering, product development, AI/ML, and infrastructure.
• Integrate detection, testing, and validation processes into cloud-native infrastructure and CI/CD pipelines.
• Minimum of 5 years in offensive security or application security research (Bachelor's degree + 2 years, or equivalent experience).
• Extensive knowledge of various programming languages.
• Proficiency in JavaScript is essential.
• Python knowledge is a significant advantage.
• In-depth understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
• Experience in writing detections for DAST scanners, fuzzers, or similar systems, including detection logic, response interpretation, and false-positive management.
• Practical web application pentesting experience covering the OWASP Top 10 and related categories, including authentication, authorization, business logic, REST, and GraphQL.
• Comfortable in researching and solving complex problems and algorithms, such as parsing with ASTs.
• Experience in building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong asset.
• Familiarity with tools like Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and fundamentals of HTTP/web protocols.
• Knowledge of cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
• Proficient in English.
• Ability to communicate technical details to both technical and non-technical audiences.
• Strong collaborative skills across multi-disciplinary teams with an understanding of when to escalate issues.
• Hands-on approach and a strong intellectual curiosity.
• Familiarity with OpenGrep or Semgrep.
• Experience in static analysis.
• Background in building production-ready systems.
• Exposure to LLMs and prompt engineering.
• Public security research contributions, such as CVEs, advisories, presentations, or open-source tools, or an interest in technical writing.
• YARA experience.
• Customized health, pension, and statutory benefits tailored to your country of residence.
• Employee Assistance Program offering 24/7 emotional support counseling.
• Life Coaching services.
• Support for Dependent Care.
• Elder Care assistance.
• Financial & Legal Support services.
• Wellness Coaching programs.
• Support for New Parents.
• Flexible remote work options.
• Quarterly Thrive-Wellness Days: an additional vacation day each quarter.
• Volunteerism Time Off: 5 days of paid time off annually.
• Paid day off for your Birthday.
• Ongoing Employee Recognition, with continuous acknowledgment and rewards.
• Opportunities for personal and professional growth.
• Competitive salary package.
• Valuable benefits and avenues for recognition and development.
OSIbeyond
It4us Cyber Security
CFA Institute
Get handpicked remote jobs straight to your inbox weekly.