Senior Security Operations Engineer

Inactive
J
JobgetherApplication security
Workplace type: Remote; based in Germany.Full-TimeSenior
This job is no longer active. We keep the page for reference, but the employer may not accept new applications.
Salary not disclosed
Job closed

Job Details

Languages
Fluent English communication skills
Experience
5+ years of experience in offensive security or application security research, or equivalent experience, with a relevant bachelor's degree plus 2 years of experience.
Required Skills
PythonJavascriptCI/CD

Requirements

  • Have 5+ years of experience in offensive security or application security research, or equivalent experience with a relevant bachelor's degree plus 2 years of experience.
  • Bring broad programming knowledge, with strong JavaScript skills; Python is highly desirable.
  • Understand vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
  • Have experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
  • Have hands-on web application penetration testing experience covering OWASP Top 10 vulnerabilities, authentication, authorization, business logic, REST, and GraphQL.
  • Be able to research complex technical problems and work with algorithms and concepts such as Abstract Syntax Trees (ASTs).
  • Understand HTTP and modern web protocols.
  • Communicate fluently in English and explain technical concepts to technical and non-technical audiences.
  • Collaborate effectively and use good judgment about when to escalate complex or high-impact issues.
  • Be willing to investigate established application security challenges and emerging threats.

Responsibilities

  • Build and maintain production-ready security checks and detection content with a focus on accuracy, broad coverage, and low false-positive rates.
  • Develop detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate findings into production detections.
  • Extend analysis capabilities to support additional programming languages and evolving application technologies.
  • Triage analysis pipeline packages, investigate findings, and validate detection results.
  • Develop attack-chain templates that combine lower-severity findings into higher-impact security scenarios.
  • Create and maintain evaluation harnesses, benchmarks, and testing frameworks for detection coverage, accuracy, false positives, exploit reproducibility, and regression performance.
  • Investigate difficult or ambiguous findings and help maintain consistent detection quality.
  • Experiment with security tools and techniques, and incorporate relevant developments in application security, offensive security, AI security, LLM vulnerabilities, agentic systems, and MCP into detection engineering.
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to develop, test, integrate, and operate detection content in cloud-native and CI/CD environments.
Job closed
View details
Job closed