Staff Security Researcher
Quick Summary
8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree. Broad programming knowledge,
This role is designed for a hands-on offensive security researcher who can turn advanced vulnerability and malware research into production-ready detection capabilities. You will investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems, translating discoveries into accurate security checks with low false-positive rates. The position combines deep technical research with practical engineering, from exploit proof-of-concepts to detection rules, evaluation frameworks, and attack-chain methodologies. You will also contribute to research standards, security tooling, and the broader application security community through publications and technical contributions. Working across engineering, product, AI/ML, and infrastructure teams, you will help ensure research moves efficiently from discovery to production. The role offers a high degree of ownership in a fast-evolving security environment where technical curiosity and measurable detection quality are highly valued.
- Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy.
- Extend security analysis capabilities to support additional programming languages across the analysis pipeline.
- Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections.
- Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities.
- Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths.
- Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates.
- Triage complex findings and packages from the analysis pipeline and validate detection results.
- Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies.
- Explore emerging tools and techniques for detecting threats and malware at scale.
- Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
- Contribute to internal research initiatives and help shape future security research priorities.
- Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions where appropriate.
- Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
- Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained.
- Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality.
Requirements
~2 min read- 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
- Broad programming knowledge, with strong JavaScript skills required and Python experience highly valued.
- Deep understanding of security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
- Extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
- Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
- Strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces.
- Ability to tackle complex technical and algorithmic problems, including parsing and AST-based analysis.
- Strong hands-on experience with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
- Solid understanding of HTTP and web protocol fundamentals.
- Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
- Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
- Fluent English with strong written and verbal communication skills and the ability to explain complex technical topics to both technical and non-technical audiences.
- Strong collaboration skills and sound judgment when determining when issues require escalation.
- Hands-on mindset, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and rapidly evolving AI security domains.
- Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research such as CVEs, advisories, talks, or open-source tools is a plus.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 2, 2026
- First seen
- October 2, 2026
- Last seen
- October 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 1
- Trust Level
- 62%
- Scored at
- October 2, 2026
Signal breakdown
Similar Security Researcher jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.