Staff Security Researcher
New
I
Invicti SecurityApplication security
Workable locations: Poland. Romania. Netherlands. Latvia. Estonia. Hungary, CET ± 2 hoursFull-TimeStaff
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- Fluent in English
- Experience
- 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
- Required Skills
- PythonJavascript
Requirements
- Have 8+ years of offensive security or application security research experience, or a Bachelor's degree plus 5 years or a Master's degree plus 3 years.
- Have broad programming-language knowledge; JavaScript is required and Python is a plus.
- Understand security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
- Have complete knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management.
- Have experience designing testing frameworks, evaluation harnesses, or large-scale security-tool validation systems.
- Have deep web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL.
- Be comfortable researching complex problems and algorithms, including parsing with ASTs.
- Be fluent with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals.
- Have practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, and MCP security.
- Be fluent in English, with strong written and verbal communication skills.
- Cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security experience are highly desirable.
- OpenGrep or Semgrep, static analysis, production-ready systems, public security research, and YARA experience are bonuses.
Responsibilities
- Create OpenGrep detection rules for novel malware and vulnerability patterns.
- Extend analysis pipeline support for new programming languages.
- Research web applications, APIs, vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors.
- Build proof-of-concept attacks and turn research findings into production-ready detections and product capabilities.
- Build attack-chain templates that combine lower-severity findings into higher-impact exploitation paths.
- Design and maintain evaluation harnesses, testing frameworks, and benchmarks for detection accuracy, exploit reproducibility, false-positive rates, and coverage.
- Triage analysis-pipeline packages and validate difficult or ambiguous findings.
- Publish research through blog posts, CVEs, tool releases, and conference contributions.
- Mentor junior and mid-level researchers on detection writing and exploitation techniques.
- Collaborate with engineering, product, AI/ML, platform, and infrastructure teams to ship research and improve security automation.
View Full Description & ApplyYou'll be redirected to the employer's site