Senior Security Operations Engineer
Quick Summary
5+ years of experience in offensive security or application security research, or equivalent experience, with a relevant bachelor's degree plus 2 years of experience. Broad programming knowledge,
This role offers the opportunity to turn advanced offensive security research into production-ready detection capabilities for modern application security.
You will build and maintain security checks designed to identify vulnerabilities, malware, and emerging attack patterns with high accuracy and low false-positive rates.
The position combines hands-on security research, detection engineering, testing, and continuous experimentation across evolving threat landscapes.
You will work with technologies including OpenGrep, JavaScript, Python, static analysis, cloud infrastructure, and CI/CD pipelines.
Your work will also extend into emerging areas such as AI security, LLM vulnerabilities, agentic systems, and MCP security.
Collaboration spans engineering, product, AI/ML, and infrastructure teams to ensure detection content is effectively developed, tested, and deployed.
This is a hands-on environment for an experienced security professional who enjoys solving complex problems and improving security capabilities at scale.
- Build and maintain production-ready security checks and detection content with a focus on accuracy, broad coverage, and low false-positive rates.
- Develop new detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns.
- Research vulnerability classes, exploitation techniques, and emerging attack patterns and translate findings into effective production detections.
- Extend analysis capabilities to support additional programming languages and evolving application technologies.
- Triage analysis pipeline packages, investigate findings, and validate detection results.
- Develop attack-chain templates that combine lower-severity findings into higher-impact security scenarios.
- Create and maintain evaluation harnesses, benchmarks, and testing frameworks to measure detection coverage, accuracy, false-positive rates, exploit reproducibility, and regression performance.
- Investigate difficult or ambiguous findings and help maintain consistent detection quality across the platform.
- Apply established detection and exploitation principles while contributing to internal standards and methodologies.
- Experiment with new security tools and techniques for detecting threats and malware at scale.
- Monitor developments in application security, offensive security, AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems and incorporate relevant insights into detection engineering.
- Collaborate with engineering, product, AI/ML, and infrastructure teams to develop, test, integrate, and operate detection content.
- Integrate detection, testing, and validation into cloud-native and CI/CD development environments.
Requirements
~2 min read- 5+ years of experience in offensive security or application security research, or equivalent experience, with a relevant bachelor's degree plus 2 years of experience.
- Broad programming knowledge, with strong JavaScript skills required and Python highly desirable.
- Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies.
- Experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
- Hands-on web application penetration testing experience covering OWASP Top 10 vulnerabilities, authentication, authorization, business logic, REST, GraphQL, and related application security areas.
- Ability to research complex technical problems and work with algorithms and concepts such as Abstract Syntax Trees (ASTs).
- Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is highly valued.
- Familiarity with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
- Understanding of HTTP and modern web protocols.
- Familiarity with cloud infrastructure, containers, CI/CD, and modern DevOps practices is advantageous.
- Fluent English communication skills, with the ability to explain technical concepts to both technical and non-technical audiences.
- Strong collaboration skills and good judgment around when to escalate complex or high-impact issues.
- Hands-on mindset, intellectual curiosity, and willingness to investigate both established application security challenges and emerging threats.
- OpenGrep or Semgrep experience, static analysis expertise, production system development experience, or exposure to LLMs and prompt engineering are advantageous.
- Security research contributions such as CVEs, advisories, technical talks, open-source tools, or technical writing experience are a plus.
- YARA experience is also beneficial.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 2, 2026
- First seen
- October 2, 2026
- Last seen
- October 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 2, 2026
Signal breakdown
Similar Security Operations Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.