Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Invicti

Staff Security Researcher

Invicti

. Create new detection rules, primarily OpenGrep, for novel malware and vulnerability patterns .

Posted 9/15/2026full-timeBirkirkara • MaltaLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in offensive security and application security research, with a strong focus on detection writing, vulnerability analysis, and secure software development practices. Proficient in collaborating across multidisciplinary teams and contributing to public security research initiatives.

Highest-signal resume keywords
Offensive Security Research ExperienceDetection Writing for DAST ScannersWeb Application Penetration TestingFluency with Offensive ToolingCloud-Native Security Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection WritingVulnerability AnalysisWeb Application Penetration TestingProgramming LanguagesSecurity PrinciplesExploitation MethodologiesTesting Framework DesignCloud SecurityAI Security ResearchStatic Analysis
Soft Skills
Strong Written CommunicationCollaborationIntellectual CuriosityJudgment in EscalationMentoring
Tools & Technologies
OpenGrepBurp SuiteSqlmapNmapFfufKubernetesCI/CDInfrastructure-as-CodeAST ParsingYARA
Industry Keywords
Application SecurityOffensive AICloud-Native Attack TechniquesOWASP Top 10Public Security ResearchCVEsMalware DetectionExploit ReproducibilityFalse-Positive ManagementSecurity Policies

Tech Stack

Tools & technologies
CloudGraphQLJavaScriptKubernetesPython

About the role

Key responsibilities & impact
  • Create new detection rules, primarily OpenGrep, for novel malware and vulnerability patterns
  • Extend support for new programming languages across the analysis pipeline
  • Experiment with tools and techniques to detect threats and malware at scale
  • Research exploitation and analysis techniques for modern web applications and APIs
  • Build proof-of-concept attacks and translate findings into shippable capabilities
  • Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors
  • Convert research into production-ready detections
  • Contribute to security policies, research standards, and attack methodologies
  • Build attack-chain templates combining low-severity findings into high-impact exploitation paths
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems
  • Measure detection accuracy, exploit reproducibility, false-positive rates, and coverage
  • Contribute to internal research and shape the public research agenda
  • Write and publish blog posts on novel attacks and large-scale incidents
  • Represent Invicti in the security community through CVEs, tool releases, and conference contributions
  • Stay current on AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques
  • Triage analysis-pipeline packages and validate findings
  • Mentor junior and mid-level researchers on detection writing and exploitation techniques
  • Collaborate with engineering, product, AI/ML, and infrastructure teams
  • Partner with platform and infrastructure teams to improve security automation across CI/CD and cloud-native environments
  • Maintain detection quality by triaging difficult or ambiguous findings

Requirements

What you’ll need
  • 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)
  • Broad knowledge of programming languages; JavaScript is required and Python is a strong plus
  • Strong understanding of security principles, standards, and best practices
  • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices
  • Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling
  • Deep web application penetration testing experience covering the OWASP Top 10 and adjacent classes, including authentication, authorization, business logic, REST, and GraphQL
  • Comfortable researching hard problems and algorithms, including parsing with ASTs
  • Fluency with offensive tooling including Burp Suite, sqlmap, nmap, ffuf, and custom payload generation
  • Understanding of HTTP and web protocol fundamentals
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques
  • Fluent in English with strong written and verbal communication skills
  • Ability to collaborate across multidisciplinary teams and exercise judgment on when to escalate issues
  • Hands-on attitude, intellectual curiosity, and willingness to research across application security, cloud-native security, and AI security
  • OpenGrep or Semgrep experience is a bonus
  • Static analysis experience is a bonus
  • Experience building production-ready systems is a bonus
  • Public security research output, including CVEs, advisories, talks, or open-source tools, is a bonus
  • YARA experience is a bonus

Benefits

Comp & perks
  • 100% of employee health care and dental premium costs covered
  • 100% of dependent health care premium costs and 50% of dependent dental premium costs contributed
  • Free one-time Visual Display Unit testing
  • Employee Assistance Program with 24/7 emotional support counseling, life coaching, dependent care, elder care, financial and legal support, wellness coaching, and new parent support
  • 16 weeks of paid leave for birthing parent recovery
  • 4 weeks of paid leave for non-birthing/bonding parent
  • Hybrid office/home working schedule
  • Quarterly Thrive-Wellness Days: one extra vacation day per quarter
  • 5 days of paid volunteerism time off annually
  • Paid birthday off
  • Mobile allowance benefit
  • Employee recognition and rewards
  • Personal and professional growth opportunities