Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Invicti

Staff Security Researcher – Europe

Invicti

. Create new OpenGrep detection rules for novel malware and vulnerability patterns .

Posted 10/2/2026full-timeRemote • Poland, Romania, Netherlands, Latvia, Estonia, HungaryLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in offensive security and application security research, with a strong focus on vulnerability analysis, detection rule creation, and threat modeling. Proficient in programming languages such as JavaScript and Python, with a solid understanding of security principles and methodologies.

Highest-signal resume keywords
Offensive Security Research ExperienceDetection Writing for DAST ScannersWeb Application PentestingFluency with Offensive ToolingCloud-Native Security Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
JavaScriptPythonVulnerability ClassificationsExploitation MethodologiesDetection LogicTesting Framework DesignWeb Application PentestingCloud PlatformsKubernetesInfrastructure-as-Code
Soft Skills
Strong Written CommunicationEffective CollaborationJudgment in EscalationIntellectual Curiosity
Tools & Technologies
Burp SuiteSqlmapNmapFfufOpenGrepSemgrepYARA
Industry Keywords
Application SecurityOffensive AICI/CD SecurityOWASP Top 10False-Positive Management

Tech Stack

Tools & technologies
CloudGraphQLJavaScriptKubernetesPython

About the role

Key responsibilities & impact
  • Create new OpenGrep detection rules for novel malware and vulnerability patterns
  • Extend support for new programming languages across the analysis pipeline
  • Experiment with tools and techniques to detect threats and malware at scale
  • Research exploitation and analysis of modern web applications and APIs
  • Build proof-of-concept attacks and translate findings into shippable capabilities
  • Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors
  • Convert research into production-ready detections
  • Contribute to research standards, policies, and attack methodologies
  • Build attack chain templates combining low-severity findings into high-impact exploitation paths
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems
  • Measure detection effectiveness, exploit reproducibility, false-positive rates, and coverage
  • Contribute to internal research and shape the public research agenda
  • Write and publish blog posts on novel attacks and large-scale incidents
  • Represent Invicti in the security community through CVEs, tool releases, and conference contributions
  • Monitor AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack trends
  • Triage analysis-pipeline packages and validate findings
  • Mentor junior and mid-level researchers
  • Collaborate with engineering, product, AI/ML, and infrastructure teams
  • Partner with platform and infrastructure teams to improve CI/CD and cloud-native security automation
  • Maintain detection quality by triaging difficult or ambiguous findings

Requirements

What you’ll need
  • 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)
  • Broad knowledge of programming languages; JavaScript is required and Python is a strong plus
  • Strong understanding of security principles, standards, and best practices
  • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices
  • Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling
  • Deep web application pentesting experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL
  • Ability to research and tackle hard problems and algorithms, including parsing with ASTs
  • Fluency with offensive tooling including Burp Suite, sqlmap, nmap, ffuf, and custom payload generation
  • Understanding of HTTP/web protocol fundamentals
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques
  • Fluent in English, with strong written and verbal communication skills
  • Ability to convey technical details to technical and non-technical audiences
  • Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues
  • Hands-on attitude, intellectual curiosity, and willingness to research across application security, cloud-native security, and AI security
  • OpenGrep or Semgrep experience is a bonus
  • Static analysis experience is a bonus
  • Experience building production-ready systems is a bonus
  • Public security research output such as CVEs, advisories, talks, or open-source tools is a bonus
  • YARA experience is a bonus

Benefits

Comp & perks
  • Tailored health, pension, and statutory perks customized to your country of residence
  • Employee Assistance Program with 24/7 emotional support counseling
  • Life Coaching
  • Dependent Care support
  • Elder Care support
  • Financial & Legal Support
  • Wellness Coaching
  • New Parent Support
  • Remote working options
  • Quarterly Thrive-Wellness Days: one extra vacation day per quarter
  • Volunteerism Time Off: 5 days of paid time off each year
  • Paid Birthday Off
  • Employee recognition and rewards
  • Personal and professional growth opportunities
  • Competitive compensation
  • Meaningful benefits
  • Opportunities for recognition and development