657,068open jobs
38,176companies
92,947added this week
Browse all
Salary
$97k – $230k per year (Estimated)
Location
In office (Birkirkara)
Seniority
Staff
Employment
Full-Time
Overview
Company
Impact
Profile match

Who we are:

Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as aleader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visitInvicti.com or follow us onLinkedIn.

Who You Are:

You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.

Requirements

What You'll Be Doing:

  • Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracy.
  • Extend support for new programming languages across our analysis pipeline.
  • Explore and experiment with cutting-edge tools and techniques to detect threats and malware at scale.
  • Research novel ways to exploit and analyze modern web applications and APIs - building proof-of-concept attacks and translating findings into shippable capabilities.
  • Research new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detections.
  • Direct the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologies.
  • Build attack chain templates that combine low-severity findings into high-impact exploitation paths.
  • Contribute to evaluation harnesses and benchmarks that measure detection effectiveness - false-positive rates, coverage, and accuracy.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverage.
  • Contribute to internal research and help shape our public research agenda.
  • Write and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributions.
  • Stay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilities.
  • Triage packages from our analysis pipeline and validate findings.
  • Mentor junior and mid-level researchers on detection writing and exploitation technique.
  • Collaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operational.
  • Partner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environments.
  • Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.

What You'll Need:

  • 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
  • Broad knowledge of programming languages - JavaScript is a must, Python is a huge plus.
  • Strong understanding of security principles, standards, and best practices.
  • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.
  • Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems - including detection logic, response interpretation, and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes - authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
  • Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
  • Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying HTTP/web protocol fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
  • Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences.
  • Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues.
  • A hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security.

Bonus Points:

  • OpenGrep (or Semgrep) experience.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Public security research output (CVEs, advisories, talks, open-source tools).
  • YARA experience.

Benefits

Why Invicti:

Why Invicti?

Your Health & Wellness Matters:

Health Insurance : Taking care of our team goes beyond the office. We cover 100% of employee health care and dental premium costs. For dependents, we contribute 100% of the health care and 50% dental premium costVDU testing: Upon joining us, we will provide for free a one time Visual Display Unit testing to ensure you can work as comfortable as possible

Employee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more

Family Leave: 16 week paid leave for birthing parent recovery. 4 week paid leave for non-birthing/bonding parent

We value Adult/ Life Balance:

Excellent working Options: Our teams operate in a hybrid office/home schedule

Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate

Volunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choice

Paid Birthday Off: Take your birthday off to celebrate you!

Mobile Allowance Benefit: This allowance will be provided to ensure you have support for work-related communication and tasks

We Value You:

Employee Recognition: Ongoing recognition & rewards . A Culture that emphasizes personal and professional growth

At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.

As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth

"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
657,068 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Birkirkara
$57k – $161k per year (Estimated) • In office • Full-Time • 2+ years exp • Singapore
Python
Go
JavaScript
TypeScript
Databases
MySQL
PostgreSQL
AI/ML
Copilot
Cursor
Claude
Model Context Protocol
Prompt Engineering
AI Agents
LLM
OpenAI
Anthropic
OpenAI Agents SDK
Agno
Frontend
Tailwind CSS
Next.js
React.js
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Apply
Fullstack Engineer 1 day ago
$29k – $66k per year (Estimated) • In office • 5+ years exp • Bengaluru
JavaScript
Java
TypeScript
Java
Spring Framework
Databases
MySQL
PostgreSQL
Frontend
React.js
DevOps
Datadog
Prometheus
Azure
CI/CD
AWS
Grafana
Apply
$85k – $142k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Chicago
Python
SQL
Apply
Mgr Pricing 1 day ago
$109k – $181k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chicago
Python
SQL
Apply
$94k – $175k per year (Estimated) • In office • Full-Time • Switzerland
Kotlin
Kotlin
Ktor
Mobile
Kotlin Multiplatform
DevOps
CI/CD
Apply
$136k – $278k per year (Estimated) • Remote/Hybrid • Full-Time • Austin
Python
JavaScript
YARA
AI/ML
Model Context Protocol
AI Agents
LLM
LLM Evaluation
Frontend
GraphQL
DevOps
CI/CD
Kubernetes
Cybersecurity
Burp Suite
Nmap
SQLmap
Semgrep
YARA
OWASP Top 10
Invicti
Apply
$86k – $193k per year (Estimated) • In office • Full-Time • Birkirkara
Python
JavaScript
YARA
AI/ML
Model Context Protocol
Prompt Engineering
AI Agents
LLM
LLM Evaluation
Frontend
GraphQL
DevOps
CI/CD
Cybersecurity
Burp Suite
Nmap
SQLmap
Semgrep
YARA
OWASP Top 10
Invicti
Apply
Remote/Hybrid • Full-Time
Cybersecurity
Invicti
Marketing
Salesforce
Apply
Remote • Full-Time • Austin
Cybersecurity
Invicti
Marketing
Salesforce
LinkedIn
Apply
$96k – $194k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree
Cybersecurity
Invicti
Marketing
LinkedIn
Apply
Logistics Clerk 19 days ago
In office • Full-Time • Birkirkara
Apply
Facilities Technician 29 days ago
$33k – $82k per year (Estimated) • In office • Full-Time • 2+ years exp • Birkirkara
Analytics
Microsoft Excel
Apply
Motorcycle Assembler 2 months ago
$29k – $70k per year (Estimated) • In office • Full-Time • Birkirkara
Apply
Compliance Analyst 2 months ago
In office • Full-Time • Birkirkara
Apply
In office • Full-Time • Birkirkara
Apply
See all jobs
This is one of many
657,068 more open roles from verified company boards, updated every day.