🇳🇱 Netherlands · 1d ago
Staff Security Researcher (Europe Remote)
Invicti
LinkedInseniorEnglish-friendly
Location: Open to candidates residing anywhere in Europe, time zones (CET ± 2 hours)Who we are: Delivering the industry's most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn.Who You Are: You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.RequirementsWhat You'll Be Doing:Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracyExtend support for new programming languages across our analysis pipelineExplore and experiment with cutting-edge tools and techniques to detect threats and malware at scaleResearch novel ways to exploit and analyze modern web applications and APIs — building proof-of-concept attacks and translating findings into shippable capabilitiesResearch new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detectionsDirect the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologiesBuild attack chain templates that combine low-severity findings into high-impact exploitation pathsContribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracyDesign and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverageContribute to internal research and help shape our public research agendaWrite and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributionsStay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilitiesTriage packages from our analysis pipeline and validate findingsMentor junior and mid-level researchers on detection writing and exploitation techniqueCollaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operationalPartner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environmentsHelp maintain detection quality across the platform, including triaging difficult or ambiguous findingsWhat You'll Need:8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)Broad knowledge of programming languages — JavaScript is a must, Python is a huge plusStrong understanding of security principles, standards, and best practicesDeep understanding of vulnerability classifications, exploitation methodologies, and secure software development practicesComplete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive managementExperience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security toolingDeep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL)Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs)Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying HTTP/web protocol fundamentalsExperience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirablePractical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniquesFluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiencesAbility to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issuesA hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP securityBonus Points:OpenGrep (or Semgrep) experienceStatic analysis experienceExperience building production-ready systemsPublic security research output (CVEs, advisories, talks, open-source tools)YARA experienceBenefitsWhy Invicti:Your Health & Wellness Matters:Tailored health, pension, and statutory perks customized to your country of residenceEmployee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and moreWe value Adult/ Life Balance:Excellent working Options: Working remotelyQuarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenateVolunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choicePaid Birthday Off: Take your birthday off to celebrate you!We Value You:Employee Recognition: Ongoing recognition & rewards . A Culture that emphasizes personal and professional growthAt Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyoneSourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.