Staff Security Researcher (Europe Remote)

1 day, 17 hours ago
Full-time
Lead
Cybersecurity
Invicti

Invicti

Invicti (formerly Netsparker) offers cutting-edge web application security solutions for enterprises, providing accurate and automated testing to reduce cyber risks and secure web assets efficiently.

Internet Software & Services
251-1K
Founded 2018
$625M raised

Description

  • Create OpenGrep detection rules for novel malware and vulnerability patterns.
  • Extend analysis support for new programming languages and maintain detection quality.
  • Research web application, API, cloud-native, and AI attack techniques, then develop proof-of-concept exploits and production detections.
  • Build attack-chain templates that combine findings into higher-impact exploitation paths.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarks for coverage, accuracy, reproducibility, and false-positive rates.
  • Triage analysis packages and ambiguous findings, validating detection results.
  • Contribute to internal and public security research through blogs, CVEs, tools, talks, and conference activity.
  • Monitor AppSec, offensive AI, LLM, agent, MCP, and cloud-native security trends and translate them into product priorities.
  • Mentor researchers and collaborate with engineering, product, AI/ML, infrastructure, platform, and CI/CD teams.
  • Help define research standards, attack methodologies, and security automation practices.

Requirements

  • 8+ years of offensive security or application security research experience, or a Bachelor's degree plus 5 years or Master's degree plus 3 years.
  • Broad programming knowledge with strong JavaScript skills; Python is highly desirable.
  • Strong understanding of security principles, standards, best practices, vulnerability classifications, exploitation, and secure development.
  • Expertise writing detections for DAST scanners, fuzzers, or comparable systems, including response interpretation and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale security-tool validation systems.
  • Deep web application penetration-testing experience covering OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL APIs.
  • Ability to solve complex research and algorithmic problems, including AST-based parsing.
  • Proficiency with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is preferred.
  • Experience with LLM applications, AI agents, prompt injection, model abuse, tool invocation risks, MCP security, or emerging AI attacks is preferred; OpenGrep/Semgrep, static analysis, production systems, public research, and YARA experience are additional advantages.
  • Fluent English communication skills, collaborative judgment, intellectual curiosity, and a hands-on approach.

Benefits

  • Remote work available for candidates across Europe within CET ±2 hours.
  • Health, pension, statutory benefits, and other perks tailored to the employee’s country of residence.
  • 24/7 Employee Assistance Program with counseling, coaching, caregiving, financial, legal, wellness, and new-parent support.
  • Quarterly paid wellness days, five annual volunteerism days, and paid birthday leave.
  • Employee recognition and rewards alongside personal and professional growth opportunities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Incident Response Lead

Aspenview Technology Partners Internet Software & Services

AspenView Technology Partners is hiring a US-based Incident Response Lead to direct major incident response and digital forensics for a large consumer lender supported by nearshore security operations teams.

AWS Azure Elasticsearch GCP Linux SIEM Splunk
1 day, 16 hours ago

Director, OT/IoT Security Services- Remote (Anywhere in the U.S.)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Director of OT/IoT Security Services to lead its industrial cybersecurity practice, overseeing its team, service portfolio, delivery quality, client engagements, and financial performance.

Cybersecurity
3 days, 15 hours ago

Technical Consultant - Network Security SASE

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to independently deliver enterprise SASE and SSE deployments, configuring Zero Trust architectures across platforms such as Zscaler, Palo Alto Prisma Access, Cisco Secure Access, and Netskope.

Network Security
1 week, 4 days ago

Senior Penetration Tester

Dark Wolf Solutions 51-250 Internet Software & Services

Dark Wolf is hiring a remote Senior Penetration Tester to assess and improve the security of hardware, software, firmware, embedded systems, networks, and wireless technologies through advanced penetration testing and exploit development.

AWS Azure Cybersecurity GCP Network Security Penetration Testing
1 week, 5 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers