Staff Security Researcher
New
J
JobgetherApplication security
Netherlands, CET ±2 hoursFull-TimeStaff
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- Fluent English
- Experience
- 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
- Required Skills
- PythonJavascriptKubernetes
Requirements
- Have 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
- Bring broad programming knowledge, with strong JavaScript skills required and Python experience highly valued.
- Understand security principles, standards, vulnerability classifications, exploitation methodologies, and secure software development.
- Have extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
- Have experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
- Have strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces.
- Be able to solve complex technical and algorithmic problems, including parsing and AST-based analysis.
- Have hands-on experience with Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
- Have a solid understanding of HTTP and web protocol fundamentals.
- Have practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, and MCP security.
- Be fluent in English with strong written and verbal communication skills.
- Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research is a plus.
Responsibilities
- Create and maintain OpenGrep detection rules for novel malware and vulnerability patterns.
- Extend security analysis capabilities to support additional programming languages.
- Research vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, and translate findings into production-ready detections.
- Investigate web applications and APIs, develop proof-of-concept attacks, and turn findings into deployable security capabilities.
- Develop attack-chain templates connecting lower-severity findings into exploitation paths.
- Design and maintain evaluation harnesses, testing frameworks, and benchmarks for security tooling.
- Triage complex findings and packages from the analysis pipeline and validate detection results.
- Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions.
- Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
- Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to deploy and maintain research outputs.
View Full Description & ApplyYou'll be redirected to the employer's site