Staff Security Researcher

New
I
Invicti SecurityApplication security
Workable locations: Poland. Romania. Netherlands. Latvia. Estonia. Hungary, CET ± 2 hoursFull-TimeStaff
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Languages
Fluent in English
Experience
8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
Required Skills
PythonJavascript

Requirements

  • Have 8+ years of offensive security or application security research experience, or a Bachelor's degree plus 5 years or a Master's degree plus 3 years.
  • Have broad programming-language knowledge; JavaScript is required and Python is a plus.
  • Understand security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
  • Have complete knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management.
  • Have experience designing testing frameworks, evaluation harnesses, or large-scale security-tool validation systems.
  • Have deep web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL.
  • Be comfortable researching complex problems and algorithms, including parsing with ASTs.
  • Be fluent with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals.
  • Have practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, and MCP security.
  • Be fluent in English, with strong written and verbal communication skills.
  • Cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security experience are highly desirable.
  • OpenGrep or Semgrep, static analysis, production-ready systems, public security research, and YARA experience are bonuses.

Responsibilities

  • Create OpenGrep detection rules for novel malware and vulnerability patterns.
  • Extend analysis pipeline support for new programming languages.
  • Research web applications, APIs, vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors.
  • Build proof-of-concept attacks and turn research findings into production-ready detections and product capabilities.
  • Build attack-chain templates that combine lower-severity findings into higher-impact exploitation paths.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarks for detection accuracy, exploit reproducibility, false-positive rates, and coverage.
  • Triage analysis-pipeline packages and validate difficult or ambiguous findings.
  • Publish research through blog posts, CVEs, tool releases, and conference contributions.
  • Mentor junior and mid-level researchers on detection writing and exploitation techniques.
  • Collaborate with engineering, product, AI/ML, platform, and infrastructure teams to ship research and improve security automation.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now