Staff Security Researcher

Invicti
United States
Workplace: HybridFull timeFunction: Research & Scientific (R&D)Experience: 8+ yearsSkills: ["Hands-on","Intellectual curiosity","Strong written communication","Strong verbal communication","Cross-functional collaboration"]

Create and maintain detection rules to catch novel malware and vulnerability patterns, primarily using OpenGrep. Extend the analysis pipeline to support new programming languages, research modern web/API exploitation and emerging AI attack vectors, and turn findings into production-ready detections. Build evaluation harnesses to measure false-positive rates, coverage, and accuracy, triage pipeline outputs, and collaborate cross-functionally to keep security checks operational. Mentor researchers and contribute public research via blogs, CVEs, and conference work.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Invicti
Invicti
2 days ago

Staff Security Researcher

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live
Reposted: similar role first listed 2 days ago

Job Summary

Create and maintain detection rules to catch novel malware and vulnerability patterns, primarily using OpenGrep. Extend the analysis pipeline to support new programming languages, research modern web/API exploitation and emerging AI attack vectors, and turn findings into production-ready detections. Build evaluation harnesses to measure false-positive rates, coverage, and accuracy, triage pipeline outputs, and collaborate cross-functionally to keep security checks operational. Mentor researchers and contribute public research via blogs, CVEs, and conference work.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Create new detection rules (primarily OpenGrep) to detect novel malware and vulnerability patterns and improve detection accuracy.
  • •Research and translate exploitation findings (including web apps, APIs, cloud-native paths, and AI-specific attack vectors) into production-ready detections.
  • •Build and maintain evaluation harnesses and benchmarking systems to measure detection effectiveness, exploit reproducibility, false-positive rates, and coverage.
  • •Triaging analysis pipeline packages and validating findings; help maintain detection quality across the platform.
  • •Mentor junior and mid-level researchers; collaborate with engineering, product, AI/ML, and infrastructure to keep research outputs shippable and operational.

Pay and Benefits

Perks:Health InsuranceVisionDental401kParental LeaveEmployee Assistance

Key Requirements

  • •8+ years of offensive security or application security research experience (Bachelor's +5 years, or Master's +3 years).
  • •Broad programming knowledge with JavaScript required and strong preference for Python.
  • •Expertise in vulnerability classifications, exploitation methodologies, and secure software development practices.
  • •Complete understanding of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic and false-positive management.
  • •Experience designing testing frameworks/evaluation harnesses and deep web application pentesting across OWASP Top 10 and related API classes (REST, GraphQL).
Experience:8+ yearsApplication securityOffensive securityDASTPentestingAPI securityCloud securityLLM securityAI red-teaming
Skills:Hands-onIntellectual curiosityStrong written communicationStrong verbal communicationCross-functional collaboration
Languages:English
Tech Stack:OpenGrepSemgrepJavaScriptPythonBurp SuiteSqlmapNmapFfufYARAOWASP Top 10RESTGraphQLASTKubernetesContainersInfrastructure-as-codeCI/CDLLM vulnerabilitiesPrompt injectionAgent security

Company Brief

Invicti
Provides dynamic application security testing (DAST) and web application/API security solutions, formed by combining Netsparker and Acunetix to help organizations detect, prioritize, and fix web-app vulnerabilities at scale.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: USD 500M to 1B
Funding: Private Equity Backed
Headquarters: Austin, United States
Founded: 2018
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor