- Create OpenGrep detection rules for novel malware and vulnerability patterns.
- Extend analysis pipeline support for new programming languages.
- Research web applications, APIs, vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors.
- Build proof-of-concept attacks and turn research findings into production-ready detections and product capabilities.
- Build attack-chain templates that combine lower-severity findings into higher-impact exploitation paths.
- Design and maintain evaluation harnesses, testing frameworks, and benchmarks for detection accuracy, exploit reproducibility, false-positive rates, and coverage.
- Triage analysis-pipeline packages and validate difficult or ambiguous findings.
- Publish research through blog posts, CVEs, tool releases, and conference contributions.
- Mentor junior and mid-level researchers on detection writing and exploitation techniques.
- Collaborate with engineering, product, AI/ML, platform, and infrastructure teams to ship research and improve security automation.
PythonJavascript