FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in offensive security and application security research, with a strong focus on vulnerability detection, analysis, and testing frameworks. Proficient in programming languages such as JavaScript and Python, with hands-on experience in web application pentesting and cloud-native infrastructure integration.
Highest-signal resume keywords
Offensive Security Research ExperienceJavaScript ProficiencyVulnerability Classification KnowledgeDetection Writing for DAST ScannersWeb Application Pentesting Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
OpenGrep Detection RulesVulnerability ResearchDetection LogicTesting FrameworksStatic AnalysisYARAAutomated Validation SystemsFalse-Positive ManagementExploit ReproducibilityCloud Infrastructure
Soft Skills
CollaborationTechnical CommunicationProblem-SolvingIntellectual CuriosityAbility to Escalate Issues
Tools & Technologies
Burp SuiteSqlmapNmapFfufCI/CD PipelinesContainerized EnvironmentsAST ParsingOpenGrepSemgrepHTTP/Web Protocol Fundamentals
Industry Keywords
Application SecurityOffensive SecurityVulnerability PatternsMalware DetectionOWASP Top 10False-Positive RatesDetection QualityEmerging Attack ResearchTechnical WritingPublic Security Research
Tech Stack
Tools & technologiesCloudGraphQLJavaScriptPython
About the role
Key responsibilities & impact- Build and maintain security checks and detection content for the Invicti platform
- Create new OpenGrep detection rules for novel malware and vulnerability patterns
- Research vulnerability classes, exploitation techniques, and emerging attack patterns
- Translate research into production-ready detections
- Extend support for new programming languages across the analysis pipeline
- Triage analysis-pipeline packages and validate findings
- Build attack-chain templates combining low-severity findings into higher-impact detection scenarios
- Contribute to evaluation harnesses and benchmarks measuring false-positive rates, coverage, and accuracy
- Build and maintain testing frameworks for detection quality, exploit reproducibility, and regression coverage
- Triage difficult or ambiguous findings and maintain platform detection quality
- Refine internal detection and exploitation standards and methodologies
- Explore new tools and techniques for detecting threats and malware at scale
- Apply current AppSec, offensive security, AI security, LLM vulnerability, AI agent security, MCP security, and emerging attack research to detection engineering
- Collaborate with engineering, product, AI/ML, and infrastructure teams
- Integrate detection, testing, and validation into cloud-native infrastructure and CI/CD pipelines
Requirements
What you’ll need- 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent)
- Broad knowledge of programming languages
- JavaScript is a must
- Python is a huge plus
- Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies
- Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
- Hands-on web application pentesting experience covering the OWASP Top 10 and adjacent classes, including authentication, authorization, business logic, REST, and GraphQL
- Comfortable researching and tackling hard problems and algorithms, such as parsing with ASTs
- Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus
- Familiarity with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals
- Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus
- Fluent in English
- Ability to convey technical details to technical and non-technical audiences
- Ability to collaborate effectively across multi-disciplinary teams and know when to escalate issues
- Hands-on attitude and intellectual curiosity
- OpenGrep or Semgrep experience
- Static analysis experience
- Experience building production-ready systems
- Exposure to LLMs and prompt engineering
- Public security research output, such as CVEs, advisories, talks, or open-source tools, or an interest in technical writing
- YARA experience
Benefits
Comp & perks- Tailored health, pension, and statutory perks customized to your country of residence
- Employee Assistance Program with 24/7 emotional support counseling
- Life Coaching
- Dependent Care support
- Elder Care support
- Financial & Legal Support
- Wellness Coaching
- New Parent Support
- Working remotely
- Quarterly Thrive-Wellness Days: one extra vacation day per quarter
- Volunteerism Time Off: 5 days of paid time off each year
- Paid Birthday Off
- Employee Recognition, ongoing recognition and rewards
- Personal and professional growth opportunities
- Competitive compensation
- Meaningful benefits and opportunities for recognition and development
