
Staff Security Researcher – Europe
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland, +5 more countries.
• Develop new OpenGrep detection rules to address emerging malware and vulnerability patterns.
• Broaden support for additional programming languages within the analysis pipeline.
• Experiment with various tools and techniques to detect threats and malware on a large scale.
• Conduct research on the exploitation and analysis of contemporary web applications and APIs.
• Construct proof-of-concept attacks and translate research findings into practical capabilities.
• Investigate vulnerability categories, exploitation techniques, cloud-native attack vectors, and AI-specific threat modalities.
• Transform research into production-ready detection mechanisms.
• Contribute to the establishment of research standards, policies, and methodologies for attacks.
• Develop attack chain templates that integrate low-severity findings into high-impact exploitation strategies.
• Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems.
• Assess detection effectiveness, exploit reproducibility, false-positive rates, and coverage metrics.
• Contribute to internal research initiatives and influence the public research agenda.
• Write and publish articles on innovative attacks and significant incidents on a large scale.
• Represent Invicti within the security community through CVEs, tool launches, and contributions to conferences.
• Monitor trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attacks.
• Triage analysis-pipeline packages and validate findings.
• Mentor junior and mid-level researchers.
• Collaborate with engineering, product, AI/ML, and infrastructure teams.
• Partner with platform and infrastructure teams to enhance CI/CD and cloud-native security automation.
• Maintain detection quality by addressing complex or ambiguous findings.
• Over 8 years of experience in offensive security or application security research (Bachelor's degree + 5 years, or Master's degree + 3 years).
• Extensive knowledge of programming languages; proficiency in JavaScript is required, while Python is a strong advantage.
• Solid grasp of security principles, standards, and best practices.
• In-depth understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.
• Comprehensive knowledge of detection writing for DAST scanners, fuzzers, or similar systems, including detection logic, response analysis, and false-positive management.
• Experience in designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tools.
• Profound web application penetration testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL.
• Ability to research and address complex issues and algorithms, including parsing with ASTs.
• Proficiency with offensive tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload generation.
• Understanding of HTTP/web protocol fundamentals.
• Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
• Practical experience in researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
• Fluent in English, with strong written and verbal communication abilities.
• Capable of conveying technical concepts to both technical and non-technical audiences.
• Demonstrated ability to collaborate effectively across multidisciplinary teams and make informed decisions regarding issue escalation.
• Hands-on approach, intellectual curiosity, and willingness to explore topics in application security, cloud-native security, and AI security.
• Experience with OpenGrep or Semgrep is a plus.
• Familiarity with static analysis is advantageous.
• Experience in building production-ready systems is a bonus.
• Public security research contributions such as CVEs, advisories, presentations, or open-source tools are a plus.
• YARA experience is a bonus.
• Customized health, pension, and statutory benefits tailored to your country of residence.
• Employee Assistance Program offering 24/7 emotional support counseling.
• Life Coaching services.
• Support for dependent care.
• Assistance for elder care.
• Financial and legal support services.
• Wellness Coaching programs.
• Support for new parents.
• Options for remote work.
• Quarterly Thrive-Wellness Days: an additional vacation day each quarter.
• Volunteerism Time Off: 5 days of paid leave each year.
• Paid day off for your birthday.
• Employee recognition and rewards programs.
• Opportunities for personal and professional growth.
• Competitive salary package.
• Meaningful benefits that enhance employee well-being.
• Opportunities for recognition and professional development.
InPost Group
Grupo Boticário
IPIRANGA
Dental Speed Graph
Get handpicked remote jobs straight to your inbox weekly.