FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in offensive security and application security research, with a strong focus on vulnerability classification, detection writing, and testing frameworks. Proficient in programming languages such as JavaScript and Python, with the ability to collaborate across multidisciplinary teams and convey technical details effectively.
Highest-signal resume keywords
Offensive Security Research ExperienceJavaScript ProficiencyVulnerability Classification KnowledgeDetection Writing for DAST ScannersWeb Application Penetration Testing
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
OpenGrep Detection RulesVulnerability ResearchDetection LogicTesting FrameworksAutomated Validation SystemsStatic AnalysisProduction-Ready SystemsYARAParsing with ASTsFalse-Positive Management
Soft Skills
CollaborationIntellectual CuriosityProblem-SolvingCommunication
Tools & Technologies
Burp SuiteSqlmapNmapFfufCloud InfrastructureCI/CD PipelinesDevOpsAI Security ToolsHTTP/Web Protocol FundamentalsOpenGrep or Semgrep
Industry Keywords
Application SecurityOffensive SecurityMalware DetectionOWASP Top 10AI SecurityLLM VulnerabilitiesMCP EcosystemsExploit ReproducibilityFalse-Positive RatesEmerging Attack Techniques
Tech Stack
Tools & technologiesCloudGraphQLJavaScriptPython
About the role
Key responsibilities & impact- Build and maintain security checks and detection content for the Invicti platform
- Create OpenGrep detection rules for novel malware and vulnerability patterns
- Research vulnerability classes, exploitation techniques, and emerging attack patterns
- Translate research into production-ready detections
- Extend support for new programming languages across the analysis pipeline
- Triage analysis-pipeline packages and validate findings
- Build attack-chain templates combining low-severity findings into higher-impact scenarios
- Contribute to evaluation harnesses and benchmarks measuring false-positive rates, coverage, and accuracy
- Build and maintain testing frameworks for detection quality, exploit reproducibility, and regression coverage
- Triage difficult or ambiguous findings and maintain detection quality
- Apply and refine detection and exploitation principles, standards, and methodologies
- Explore tools and techniques for detecting threats and malware at scale
- Monitor AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, MCP security, and emerging attack techniques
- Collaborate with engineering, product, AI/ML, and infrastructure teams
- Integrate detection, testing, and validation into cloud-native infrastructure and CI/CD pipelines
Requirements
What you’ll need- 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent)
- Broad knowledge of programming languages
- JavaScript is required; Python is a strong plus
- Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies
- Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
- Hands-on web application penetration testing experience covering the OWASP Top 10 and adjacent classes, including authentication, authorization, business logic, REST, and GraphQL
- Comfortable researching hard problems and algorithms, including parsing with ASTs
- Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus
- Familiarity with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals
- Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus
- Fluent in English, with ability to convey technical details to technical and non-technical audiences
- Ability to collaborate across multidisciplinary teams and know when to escalate issues
- Hands-on attitude and intellectual curiosity
- Willingness to work on AppSec, AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems
- OpenGrep or Semgrep experience is a bonus
- Static analysis experience is a bonus
- Experience building production-ready systems is a bonus
- Exposure to LLMs and prompt engineering is a bonus
- Public security research output, such as CVEs, advisories, talks, or open-source tools, or interest in technical writing, is a bonus
- YARA experience is a bonus
Benefits
Comp & perks- 100% of employee health care and dental premium costs covered
- 100% health care premium and 50% dental premium contribution for dependents
- Free one-time Visual Display Unit testing
- Employee Assistance Program with 24/7 emotional support counseling, life coaching, dependent care, elder care, financial and legal support, wellness coaching, and new parent support
- 16 weeks paid leave for birthing parent recovery
- 4 weeks paid leave for non-birthing/bonding parent
- Hybrid office/home schedule
- Quarterly Thrive-Wellness Days: one extra vacation day per quarter
- 5 days paid Volunteerism Time Off annually
- Paid birthday off
- Mobile allowance benefit
- Employee recognition and rewards
- Personal and professional growth opportunities
- Competitive compensation and regionalized Total Rewards benefits
