Staff Security Researcher

Invicti
Malta
Workplace: HybridFull timeFunction: Research & Scientific (R&D)Experience: 8+ yearsSkills: ["Communication","Collaboration","Quality-focused","Ownership","Intellectual curiosity"]

Build and ship offensive security research that becomes high-quality detection content. Create new detection rules (primarily OpenGrep) for novel malware and vulnerability patterns, extend language coverage across the analysis pipeline, and develop evaluation harnesses to track accuracy, false positives, and coverage. Research exploitation and modern web/API attack paths, contribute public research, and mentor researchers while partnering across engineering and AI/ML teams to keep detections operational.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Invicti
Invicti
3 days ago

Staff Security Researcher

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Build and ship offensive security research that becomes high-quality detection content. Create new detection rules (primarily OpenGrep) for novel malware and vulnerability patterns, extend language coverage across the analysis pipeline, and develop evaluation harnesses to track accuracy, false positives, and coverage. Research exploitation and modern web/API attack paths, contribute public research, and mentor researchers while partnering across engineering and AI/ML teams to keep detections operational.
Location: Malta
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)

Key Responsibilities

  • •Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and improve detection accuracy.
  • •Extend support for new programming languages across the analysis pipeline.
  • •Research and translate exploitation findings into production-ready detections, including cloud-native and AI/LLM-specific attack vectors.
  • •Build and maintain evaluation harnesses, testing frameworks, and benchmarking systems to measure accuracy, false-positive rates, coverage, and exploit reproducibility.
  • •Mentor junior and mid-level researchers, triage pipeline outputs, and collaborate with engineering, product, AI/ML, and infrastructure teams to ensure research ships and stays operational.

Pay and Benefits

Perks:Health InsuranceDentalPaid LeaveMobile AllowanceEmployee Assistance

Key Requirements

  • •8+ years of offensive security or application security research experience, with a bachelor’s +5 years or master’s +3 years.
  • •Strong knowledge of programming languages (JavaScript required; Python a plus) and security principles, standards, and best practices.
  • •Deep expertise in vulnerability classifications, exploitation methodologies, and detection writing for DAST scanners/fuzzers including false-positive management.
  • •Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • •Deep web application pentesting experience (OWASP Top 10 and adjacent classes) including authentication, authorization, business logic, and modern REST/GraphQL API surfaces.
Experience:8+ yearsApplication securityOffensive securityDASTWeb application pentesting
Skills:CommunicationCollaborationQuality-focusedOwnershipIntellectual curiosity
Languages:English
Tech Stack:OpenGrepSemgrepJavaScriptPythonBurp SuiteSqlmapNmapFfufYARAASTsOWASP Top 10RESTGraphQLKubernetesContainersCI/CDLLMPrompt injectionAgent securityMCP security

Company Brief

Invicti
Provides dynamic application security testing (DAST) and web application/API security solutions, formed by combining Netsparker and Acunetix to help organizations detect, prioritize, and fix web-app vulnerabilities at scale.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: USD 500M to 1B
Funding: Private Equity Backed
Headquarters: Austin, United States
Founded: 2018
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor