FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in offensive security and application security research, with a strong focus on vulnerability classification, exploitation methodologies, and detection writing for security tooling. Proficient in collaborating across multidisciplinary teams and effectively communicating complex technical concepts to diverse audiences.
Highest-signal resume keywords
Offensive Security Research ExperienceDetection Writing for DAST ScannersWeb Application PentestingProgramming Languages: JavaScript and PythonCloud-Native Security Automation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ClassificationExploitation MethodologiesDetection LogicTesting Framework DesignAST ParsingCI/CD SecurityProduction-Ready SystemsStatic AnalysisOpenGrep or SemgrepYARA
Soft Skills
Strong Written and Verbal CommunicationCollaboration Across TeamsJudgment on EscalationIntellectual CuriosityMentoring
Tools & Technologies
Burp SuiteSqlmapNmapFfufHTTP/Web Protocol FundamentalsKubernetesContainersInfrastructure-as-CodeAI Security ToolsCustom Payload Generation
Industry Keywords
Application SecurityMalware DetectionThreat AnalysisOWASP Top 10Cloud-Native Attack PathsAI-Specific Attack VectorsPublic Security ResearchCVEsRed-TeamingOffensive AI
Tech Stack
Tools & technologiesCloudGraphQLJavaScriptKubernetesPython
About the role
Key responsibilities & impact- Create new OpenGrep detection rules for novel malware and vulnerability patterns
- Extend support for new programming languages across the analysis pipeline
- Experiment with tools and techniques for detecting threats and malware at scale
- Research exploitation and analysis techniques for modern web applications and APIs
- Build proof-of-concept attacks and translate findings into shippable capabilities
- Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors
- Convert security research into production-ready detections
- Apply existing detection and exploitation principles and contribute to research standards and attack methodologies
- Build attack-chain templates combining low-severity findings into high-impact exploitation paths
- Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems
- Measure detection accuracy, exploit reproducibility, false-positive rates, and coverage
- Contribute to internal research and shape the public research agenda
- Write and publish blog posts on novel attacks and large-scale incidents
- Represent Invicti in the security community through CVEs, tool releases, and conference contributions
- Monitor AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack trends
- Triage analysis-pipeline packages and validate findings
- Mentor junior and mid-level researchers on detection writing and exploitation techniques
- Collaborate with engineering, product, AI/ML, and infrastructure teams to ship and operate research output
- Partner with platform and infrastructure teams to improve CI/CD and cloud-native security automation
- Maintain detection quality by triaging difficult or ambiguous findings
Requirements
What you’ll need- 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)
- Broad knowledge of programming languages; JavaScript required and Python strongly advantageous
- Strong understanding of security principles, standards, and best practices
- Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices
- Complete knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
- Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling
- Deep web application pentesting experience covering OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL
- Ability to research and tackle hard problems and algorithms, including AST parsing
- Fluency with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals
- Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security highly desirable
- Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques
- Fluent in English with strong written and verbal communication skills
- Ability to convey technical details to technical and non-technical audiences
- Ability to collaborate across multidisciplinary teams and exercise judgment on escalation
- Hands-on attitude and intellectual curiosity across application security, cloud-native security, and AI security
- OpenGrep or Semgrep experience is a bonus
- Static analysis experience is a bonus
- Experience building production-ready systems is a bonus
- Public security research output, including CVEs, advisories, talks, or open-source tools, is a bonus
- YARA experience is a bonus
Benefits
Comp & perks- 100% employee health care, vision, and dental premium costs covered
- 75% health care premium contribution for dependents
- 50% vision/dental premium contribution for dependents
- Coverage effective the first day
- Employee Assistance Program with 24/7 life coaching, dependent care, elder care, financial and legal support, wellness coaching, and new parent support
- 16 weeks paid leave for birthing parent recovery
- 4 weeks paid leave for non-birthing/bonding parent
- 401(k) savings plan with 50% company match up to 6%, with 100% annual cliff vesting
- Hybrid/home schedule with twice-weekly work from the Austin office
- Discretionary time off with flexible vacation schedule
- Quarterly Thrive-Wellness Days
- 5 days paid volunteerism time off annually
- Paid birthday off
- Employee recognition and rewards
- Personal and professional growth opportunities
