FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in offensive security and application security research, with a strong focus on vulnerability analysis, detection rule creation, and threat modeling. Proficient in programming languages such as JavaScript and Python, with a solid understanding of security principles and methodologies.
Highest-signal resume keywords
Offensive Security Research ExperienceDetection Writing for DAST ScannersWeb Application PentestingFluency with Offensive ToolingCloud-Native Security Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
JavaScriptPythonVulnerability ClassificationsExploitation MethodologiesDetection LogicTesting Framework DesignWeb Application PentestingCloud PlatformsKubernetesInfrastructure-as-Code
Soft Skills
Strong Written CommunicationEffective CollaborationJudgment in EscalationIntellectual Curiosity
Tools & Technologies
Burp SuiteSqlmapNmapFfufOpenGrepSemgrepYARA
Industry Keywords
Application SecurityOffensive AICI/CD SecurityOWASP Top 10False-Positive Management
Tech Stack
Tools & technologiesCloudGraphQLJavaScriptKubernetesPython
About the role
Key responsibilities & impact- Create new OpenGrep detection rules for novel malware and vulnerability patterns
- Extend support for new programming languages across the analysis pipeline
- Experiment with tools and techniques to detect threats and malware at scale
- Research exploitation and analysis of modern web applications and APIs
- Build proof-of-concept attacks and translate findings into shippable capabilities
- Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors
- Convert research into production-ready detections
- Contribute to research standards, policies, and attack methodologies
- Build attack chain templates combining low-severity findings into high-impact exploitation paths
- Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems
- Measure detection effectiveness, exploit reproducibility, false-positive rates, and coverage
- Contribute to internal research and shape the public research agenda
- Write and publish blog posts on novel attacks and large-scale incidents
- Represent Invicti in the security community through CVEs, tool releases, and conference contributions
- Monitor AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack trends
- Triage analysis-pipeline packages and validate findings
- Mentor junior and mid-level researchers
- Collaborate with engineering, product, AI/ML, and infrastructure teams
- Partner with platform and infrastructure teams to improve CI/CD and cloud-native security automation
- Maintain detection quality by triaging difficult or ambiguous findings
Requirements
What you’ll need- 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years)
- Broad knowledge of programming languages; JavaScript is required and Python is a strong plus
- Strong understanding of security principles, standards, and best practices
- Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices
- Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management
- Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling
- Deep web application pentesting experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL
- Ability to research and tackle hard problems and algorithms, including parsing with ASTs
- Fluency with offensive tooling including Burp Suite, sqlmap, nmap, ffuf, and custom payload generation
- Understanding of HTTP/web protocol fundamentals
- Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable
- Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques
- Fluent in English, with strong written and verbal communication skills
- Ability to convey technical details to technical and non-technical audiences
- Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues
- Hands-on attitude, intellectual curiosity, and willingness to research across application security, cloud-native security, and AI security
- OpenGrep or Semgrep experience is a bonus
- Static analysis experience is a bonus
- Experience building production-ready systems is a bonus
- Public security research output such as CVEs, advisories, talks, or open-source tools is a bonus
- YARA experience is a bonus
Benefits
Comp & perks- Tailored health, pension, and statutory perks customized to your country of residence
- Employee Assistance Program with 24/7 emotional support counseling
- Life Coaching
- Dependent Care support
- Elder Care support
- Financial & Legal Support
- Wellness Coaching
- New Parent Support
- Remote working options
- Quarterly Thrive-Wellness Days: one extra vacation day per quarter
- Volunteerism Time Off: 5 days of paid time off each year
- Paid Birthday Off
- Employee recognition and rewards
- Personal and professional growth opportunities
- Competitive compensation
- Meaningful benefits
- Opportunities for recognition and development
