Senior Security Operations Engineer

New
I
Invicti SecurityApplication security
Open to candidates residing anywhere in Europe, CET ± 2 hoursFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Languages
Fluent in English
Experience
5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent).
Required Skills
PythonJavascriptCI/CD

Requirements

  • Have 5+ years of offensive security or application security research experience, with a bachelor's degree plus 2 years or equivalent.
  • Have broad knowledge of programming languages; JavaScript is required and Python is a plus.
  • Understand vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
  • Have working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management.
  • Have hands-on web application penetration-testing experience covering the OWASP Top 10 and related areas, including authentication, authorization, business logic, and REST and GraphQL APIs.
  • Be comfortable researching complex problems and algorithms, such as parsing with ASTs.
  • Be fluent in English and able to convey technical details to technical and non-technical audiences.
  • Be familiar with offensive tools such as Burp Suite, sqlmap, nmap, ffuf, or custom payload generation, and with HTTP and web protocol fundamentals.
  • Experience with testing frameworks, evaluation harnesses, or automated validation systems is a plus.
  • Familiarity with cloud infrastructure, containerized environments, and CI/CD or DevOps pipelines is a plus.
  • OpenGrep or Semgrep, static analysis, YARA, LLMs, and prompt engineering experience are bonuses.

Responsibilities

  • Build and maintain security checks and detection content for the Invicti platform, focusing on accuracy, coverage, and low false-positive rates.
  • Create detection rules, primarily using OpenGrep, for malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate them into production-ready detections.
  • Extend support for new programming languages across the analysis pipeline.
  • Triage analysis-pipeline packages and validate findings, including difficult or ambiguous findings.
  • Build attack-chain templates that combine lower-severity findings into higher-impact detection scenarios.
  • Contribute to evaluation harnesses, benchmarks, and testing frameworks for detection effectiveness and quality.
  • Integrate detection, testing, and validation into development workflows using cloud-native infrastructure and CI/CD pipelines.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now