Staff Security Researcher – Europe

Posted 1 day ago

This is a fully remote position, open to applicants in Poland, +5 more countries.

📋 Description

• Develop new OpenGrep detection rules to address emerging malware and vulnerability patterns.

• Broaden support for additional programming languages within the analysis pipeline.

• Experiment with various tools and techniques to detect threats and malware on a large scale.

• Conduct research on the exploitation and analysis of contemporary web applications and APIs.

• Construct proof-of-concept attacks and translate research findings into practical capabilities.

• Investigate vulnerability categories, exploitation techniques, cloud-native attack vectors, and AI-specific threat modalities.

• Transform research into production-ready detection mechanisms.

• Contribute to the establishment of research standards, policies, and methodologies for attacks.

• Develop attack chain templates that integrate low-severity findings into high-impact exploitation strategies.

• Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems.

• Assess detection effectiveness, exploit reproducibility, false-positive rates, and coverage metrics.

• Contribute to internal research initiatives and influence the public research agenda.

• Write and publish articles on innovative attacks and significant incidents on a large scale.

• Represent Invicti within the security community through CVEs, tool launches, and contributions to conferences.

• Monitor trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attacks.

• Triage analysis-pipeline packages and validate findings.

• Mentor junior and mid-level researchers.

• Collaborate with engineering, product, AI/ML, and infrastructure teams.

• Partner with platform and infrastructure teams to enhance CI/CD and cloud-native security automation.

• Maintain detection quality by addressing complex or ambiguous findings.


⛳️ Requirements

• Over 8 years of experience in offensive security or application security research (Bachelor's degree + 5 years, or Master's degree + 3 years).

• Extensive knowledge of programming languages; proficiency in JavaScript is required, while Python is a strong advantage.

• Solid grasp of security principles, standards, and best practices.

• In-depth understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.

• Comprehensive knowledge of detection writing for DAST scanners, fuzzers, or similar systems, including detection logic, response analysis, and false-positive management.

• Experience in designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tools.

• Profound web application penetration testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL.

• Ability to research and address complex issues and algorithms, including parsing with ASTs.

• Proficiency with offensive tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload generation.

• Understanding of HTTP/web protocol fundamentals.

• Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.

• Practical experience in researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.

• Fluent in English, with strong written and verbal communication abilities.

• Capable of conveying technical concepts to both technical and non-technical audiences.

• Demonstrated ability to collaborate effectively across multidisciplinary teams and make informed decisions regarding issue escalation.

• Hands-on approach, intellectual curiosity, and willingness to explore topics in application security, cloud-native security, and AI security.

• Experience with OpenGrep or Semgrep is a plus.

• Familiarity with static analysis is advantageous.

• Experience in building production-ready systems is a bonus.

• Public security research contributions such as CVEs, advisories, presentations, or open-source tools are a plus.

• YARA experience is a bonus.


🏝️ Benefits

• Customized health, pension, and statutory benefits tailored to your country of residence.

• Employee Assistance Program offering 24/7 emotional support counseling.

• Life Coaching services.

• Support for dependent care.

• Assistance for elder care.

• Financial and legal support services.

• Wellness Coaching programs.

• Support for new parents.

• Options for remote work.

• Quarterly Thrive-Wellness Days: an additional vacation day each quarter.

• Volunteerism Time Off: 5 days of paid leave each year.

• Paid day off for your birthday.

• Employee recognition and rewards programs.

• Opportunities for personal and professional growth.

• Competitive salary package.

• Meaningful benefits that enhance employee well-being.

• Opportunities for recognition and professional development.

People also viewed

InPost Group20 hours ago

AI Security Engineer

PL flagPoland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Grupo Boticário20 hours ago

SecOps Manager – Information Security Directorate

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
IPIRANGA20 hours ago

Senior Information Security Governance Analyst

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Dental Speed Graph20 hours ago

Information Security Intern

BR flagBrazil OnlyInternshipCybersecurity / Security Engineer
ApplyView job
ClassLink21 hours ago

IT Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$115k – $125k/year
ApplyView job
Kreative Technologies, LLC21 hours ago

Security Specialist

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer$85.5k – $95k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers