Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Invicti

Staff Security Researcher

Invicti

. Create new OpenGrep detection rules for novel malware and vulnerability patterns .

Posted 9/15/2026full-timeAustin • Texas • United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in offensive security and application security research, with a strong focus on vulnerability classification, exploitation methodologies, and detection writing for security tooling. Proficient in collaborating across multidisciplinary teams and effectively communicating complex technical concepts to diverse audiences.

Highest-signal resume keywords
Offensive Security Research ExperienceDetection Writing for DAST ScannersWeb Application PentestingProgramming Languages: JavaScript and PythonCloud-Native Security Automation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability ClassificationExploitation MethodologiesDetection LogicTesting Framework DesignAST ParsingCI/CD SecurityProduction-Ready SystemsStatic AnalysisOpenGrep or SemgrepYARA
Soft Skills
Strong Written and Verbal CommunicationCollaboration Across TeamsJudgment on EscalationIntellectual CuriosityMentoring
Tools & Technologies
Burp SuiteSqlmapNmapFfufHTTP/Web Protocol FundamentalsKubernetesContainersInfrastructure-as-CodeAI Security ToolsCustom Payload Generation
Industry Keywords
Application SecurityMalware DetectionThreat AnalysisOWASP Top 10Cloud-Native Attack PathsAI-Specific Attack VectorsPublic Security ResearchCVEsRed-TeamingOffensive AI

Tech Stack

Tools & technologies
CloudGraphQLJavaScriptKubernetesPython

About the role

Key responsibilities & impact
  • Create new OpenGrep detection rules for novel malware and vulnerability patterns
  • Extend support for new programming languages across the analysis pipeline
  • Experiment with tools and techniques for detecting threats and malware at scale
  • Research exploitation and analysis techniques for modern web applications and APIs
  • Build proof-of-concept attacks and translate findings into shippable capabilities
  • Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors
  • Convert security research into production-ready detections
  • Apply existing detection and exploitation principles and contribute to research standards and attack methodologies
  • Build attack-chain templates combining low-severity findings into high-impact exploitation paths
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems
  • Measure detection accuracy, exploit reproducibility, false-positive rates, and coverage
  • Contribute to internal research and shape the public research agenda
  • Write and publish blog posts on novel attacks and large-scale incidents
  • Represent Invicti in the security community through CVEs, tool releases, and conference contributions
  • Monitor AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack trends
  • Triage analysis-pipeline packages and validate findings
  • Mentor junior and mid-level researchers on detection writing and exploitation techniques
  • Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate research output
  • Partner with platform and infrastructure teams to improve CI/CD and cloud-native security automation
  • Maintain detection quality by triaging difficult or ambiguous findings

Requirements

What you’ll need
  • 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)
  • Broad knowledge of programming languages; JavaScript required and Python strongly advantageous
  • Strong understanding of security principles, standards, and best practices
  • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices
  • Complete knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling
  • Deep web application pentesting experience covering OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL
  • Ability to research and tackle hard problems and algorithms, including AST parsing
  • Fluency with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security highly desirable
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques
  • Fluent in English with strong written and verbal communication skills
  • Ability to convey technical details to technical and non-technical audiences
  • Ability to collaborate across multidisciplinary teams and exercise judgment on escalation
  • Hands-on attitude and intellectual curiosity across application security, cloud-native security, and AI security
  • OpenGrep or Semgrep experience is a bonus
  • Static analysis experience is a bonus
  • Experience building production-ready systems is a bonus
  • Public security research output, including CVEs, advisories, talks, or open-source tools, is a bonus
  • YARA experience is a bonus

Benefits

Comp & perks
  • 100% employee health care, vision, and dental premium costs covered
  • 75% health care premium contribution for dependents
  • 50% vision/dental premium contribution for dependents
  • Coverage effective the first day
  • Employee Assistance Program with 24/7 life coaching, dependent care, elder care, financial and legal support, wellness coaching, and new parent support
  • 16 weeks paid leave for birthing parent recovery
  • 4 weeks paid leave for non-birthing/bonding parent
  • 401(k) savings plan with 50% company match up to 6%, with 100% annual cliff vesting
  • Hybrid/home schedule with twice-weekly work from the Austin office
  • Discretionary time off with flexible vacation schedule
  • Quarterly Thrive-Wellness Days
  • 5 days paid volunteerism time off annually
  • Paid birthday off
  • Employee recognition and rewards
  • Personal and professional growth opportunities