Jobgether

Staff Security Researcher

Jobgether

Remote · Full Time

Be the first to apply

Experience
8+ yrs
Salary
—
Openings
1
Posted
3 seconds ago
Work mode
Work from home
Education
Bachelor's or Master's degree
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Overview

This role is for a proactive offensive security researcher based in Ireland, who specializes in converting sophisticated vulnerability and malware investigations into robust, production-level detection solutions. The researcher will explore emerging threats spanning web applications, APIs, cloud-native infrastructures, and AI-powered systems, crafting precise and low false-positive security checks. The position blends in-depth technical research with practical engineering efforts, including exploit proof-of-concepts, detection rule creation, evaluation frameworks, and attack-chain development. Additionally, the role involves contributing to security research standards, tooling, and participating in the application security community through published works and technical contributions. Collaboration with engineering, product, AI/ML, and infrastructure teams ensures smooth delivery from discovery to deployment. This position offers extensive autonomy in a dynamic security environment that values strong technical curiosity and measurable detection efficacy.

Responsibilities

  • Develop and maintain detection rules, mainly leveraging OpenGrep, to identify new malware and vulnerability trends while enhancing detection precision.
  • Broaden security analysis tools to encompass more programming languages within the pipeline.
  • Research novel vulnerabilities, exploitation methods, cloud-native attack vectors, and AI-related threats, converting results into actionable detection capabilities.
  • Analyze modern web applications and APIs, design exploit proof-of-concepts, and translate these findings into deployable security defenses.
  • Create templates that map out attack chains by linking less severe issues to significant exploitation routes.
  • Build and upkeep testing frameworks, evaluation harnesses, and benchmark suites to assess coverage, accuracy, reproducibility, and false-positive rates.
  • Analyze complex pipeline findings and verify detection accuracy.
  • Adopt existing detection and exploitation standards while aiding in the development of new research policies and attack methodologies.
  • Investigate innovative tools and techniques for large-scale threat and malware detection.
  • Study security aspects related to AppSec, AI red teaming, offensive AI, large language model vulnerabilities, AI agents, MCP security, and cloud-native attacks.
  • Contribute to internal research projects and influence future security research directions.
  • Publish technical research via blogs, CVEs, advisories, tool launches, and conference presentations as suitable.
  • Guide and mentor junior and mid-level researchers on detection writing and exploitation strategies.
  • Collaborate cross-functionally with engineering, product, AI/ML, infrastructure, platform, and security teams to deliver and sustain research outputs.
  • Enhance security automation throughout CI/CD and cloud-native environments, emphasizing high detection quality.

Requirements

  • A minimum of 8 years of experience in offensive or application security research or an equivalent combination of experience and Bachelor’s or Master’s degree.
  • Comprehensive programming skills with strong expertise in JavaScript and valued experience in Python.
  • In-depth knowledge of security principles, standards, best practices, vulnerability types, exploitation techniques, and secure development.
  • Proven experience authoring detection logic for DAST scanners, fuzzers, or similar security platforms, including managing false positives.
  • Background in building testing frameworks, evaluation systems, or large-scale validation setups for security tools.
  • Extensive hands-on web application penetration testing expertise addressing OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and current API technologies.
  • Capability to solve intricate technical and algorithmic challenges, including parsing and AST-related analysis.
  • Strong practical knowledge of offensive tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload creation.
  • Well-rounded understanding of HTTP protocols and web technologies.
  • Preferred experience with cloud environments, Kubernetes, containers, infrastructure-as-code, and CI/CD security implementations.
  • Practical background in researching or securing applications powered by large language models, AI agents, and AI-assisted workflows, covering prompt injections, model misuse, tool invocation risks, MCP security, and emergent AI attack vectors.
  • Fluent English communication skills, both written and verbal, able to articulate complex technical information to diverse audiences.
  • Excellent teamwork abilities alongside sound judgment on issue escalation.
  • A hands-on approach, intellectual curiosity, and willingness to explore traditional application security, cloud-native security, and emerging AI security fields.
  • Experience with OpenGrep or Semgrep, static analysis, production-grade security tools, YARA, or public security research contributions (CVEs, advisories, talks, open-source software) is advantageous.

Benefits

  • Fully remote position for candidates based within CET time zone ±2 hours in Europe.
  • Country-specific health, pension, and statutory benefits.
  • Around-the-clock Employee Assistance Program providing emotional support, life coaching, dependent and elder care, financial and legal advice, wellness coaching, and new-parent resources.
  • Quarterly wellness days granting an extra day off every quarter for relaxation and rejuvenation.
  • Five paid volunteer days annually to support charitable or community service activities.
  • Paid day off on birthdays.
  • Employee recognition and rewards initiatives.
  • A culture prioritizing personal and professional growth.
  • Flexible remote working designed to promote a healthy work-life balance.
  • Competitive salary and comprehensive total rewards tailored to the region.
  • Opportunities to impact significant security research and develop expertise in application, cloud, and AI security domains.

Additional Information

This role is listed via a partner company that handles all applications and subsequent hiring steps. The selection process uses AI-powered matching to fairly evaluate candidates, with final decisions made by the hiring organization. Candidates must be located in or able to work remotely within the CET ±2 hour time frame to qualify.

Minimum education

Master's Degree

Tools & software

Nmap required Burp Suite required SQLMap required FFUF required

How they work

Communication Teamwork & Collaboration Decision Making Learning Agility
🤖
Online · instant AI help
Broxer