Senior Security Operations Engineer
New
I
Invicti SecurityApplication security
Open to candidates residing anywhere in Europe, CET ± 2 hoursFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- Fluent in English
- Experience
- 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent).
- Required Skills
- PythonJavascriptCI/CD
Requirements
- Have 5+ years of offensive security or application security research experience, with a bachelor's degree plus 2 years or equivalent.
- Have broad knowledge of programming languages; JavaScript is required and Python is a plus.
- Understand vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
- Have working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management.
- Have hands-on web application penetration-testing experience covering the OWASP Top 10 and related areas, including authentication, authorization, business logic, and REST and GraphQL APIs.
- Be comfortable researching complex problems and algorithms, such as parsing with ASTs.
- Be fluent in English and able to convey technical details to technical and non-technical audiences.
- Be familiar with offensive tools such as Burp Suite, sqlmap, nmap, ffuf, or custom payload generation, and with HTTP and web protocol fundamentals.
- Experience with testing frameworks, evaluation harnesses, or automated validation systems is a plus.
- Familiarity with cloud infrastructure, containerized environments, and CI/CD or DevOps pipelines is a plus.
- OpenGrep or Semgrep, static analysis, YARA, LLMs, and prompt engineering experience are bonuses.
Responsibilities
- Build and maintain security checks and detection content for the Invicti platform, focusing on accuracy, coverage, and low false-positive rates.
- Create detection rules, primarily using OpenGrep, for malware and vulnerability patterns.
- Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate them into production-ready detections.
- Extend support for new programming languages across the analysis pipeline.
- Triage analysis-pipeline packages and validate findings, including difficult or ambiguous findings.
- Build attack-chain templates that combine lower-severity findings into higher-impact detection scenarios.
- Contribute to evaluation harnesses, benchmarks, and testing frameworks for detection effectiveness and quality.
- Integrate detection, testing, and validation into development workflows using cloud-native infrastructure and CI/CD pipelines.
- Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
View Full Description & ApplyYou'll be redirected to the employer's site