- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 seconds ago
- Work mode
- Work from home
- Education
- Bachelor's or Master's degree
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
This role is for a proactive offensive security researcher based in Ireland, who specializes in converting sophisticated vulnerability and malware investigations into robust, production-level detection solutions. The researcher will explore emerging threats spanning web applications, APIs, cloud-native infrastructures, and AI-powered systems, crafting precise and low false-positive security checks. The position blends in-depth technical research with practical engineering efforts, including exploit proof-of-concepts, detection rule creation, evaluation frameworks, and attack-chain development. Additionally, the role involves contributing to security research standards, tooling, and participating in the application security community through published works and technical contributions. Collaboration with engineering, product, AI/ML, and infrastructure teams ensures smooth delivery from discovery to deployment. This position offers extensive autonomy in a dynamic security environment that values strong technical curiosity and measurable detection efficacy.
Responsibilities
- Develop and maintain detection rules, mainly leveraging OpenGrep, to identify new malware and vulnerability trends while enhancing detection precision.
- Broaden security analysis tools to encompass more programming languages within the pipeline.
- Research novel vulnerabilities, exploitation methods, cloud-native attack vectors, and AI-related threats, converting results into actionable detection capabilities.
- Analyze modern web applications and APIs, design exploit proof-of-concepts, and translate these findings into deployable security defenses.
- Create templates that map out attack chains by linking less severe issues to significant exploitation routes.
- Build and upkeep testing frameworks, evaluation harnesses, and benchmark suites to assess coverage, accuracy, reproducibility, and false-positive rates.
- Analyze complex pipeline findings and verify detection accuracy.
- Adopt existing detection and exploitation standards while aiding in the development of new research policies and attack methodologies.
- Investigate innovative tools and techniques for large-scale threat and malware detection.
- Study security aspects related to AppSec, AI red teaming, offensive AI, large language model vulnerabilities, AI agents, MCP security, and cloud-native attacks.
- Contribute to internal research projects and influence future security research directions.
- Publish technical research via blogs, CVEs, advisories, tool launches, and conference presentations as suitable.
- Guide and mentor junior and mid-level researchers on detection writing and exploitation strategies.
- Collaborate cross-functionally with engineering, product, AI/ML, infrastructure, platform, and security teams to deliver and sustain research outputs.
- Enhance security automation throughout CI/CD and cloud-native environments, emphasizing high detection quality.
Requirements
- A minimum of 8 years of experience in offensive or application security research or an equivalent combination of experience and Bachelor’s or Master’s degree.
- Comprehensive programming skills with strong expertise in JavaScript and valued experience in Python.
- In-depth knowledge of security principles, standards, best practices, vulnerability types, exploitation techniques, and secure development.
- Proven experience authoring detection logic for DAST scanners, fuzzers, or similar security platforms, including managing false positives.
- Background in building testing frameworks, evaluation systems, or large-scale validation setups for security tools.
- Extensive hands-on web application penetration testing expertise addressing OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and current API technologies.
- Capability to solve intricate technical and algorithmic challenges, including parsing and AST-related analysis.
- Strong practical knowledge of offensive tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload creation.
- Well-rounded understanding of HTTP protocols and web technologies.
- Preferred experience with cloud environments, Kubernetes, containers, infrastructure-as-code, and CI/CD security implementations.
- Practical background in researching or securing applications powered by large language models, AI agents, and AI-assisted workflows, covering prompt injections, model misuse, tool invocation risks, MCP security, and emergent AI attack vectors.
- Fluent English communication skills, both written and verbal, able to articulate complex technical information to diverse audiences.
- Excellent teamwork abilities alongside sound judgment on issue escalation.
- A hands-on approach, intellectual curiosity, and willingness to explore traditional application security, cloud-native security, and emerging AI security fields.
- Experience with OpenGrep or Semgrep, static analysis, production-grade security tools, YARA, or public security research contributions (CVEs, advisories, talks, open-source software) is advantageous.
Benefits
- Fully remote position for candidates based within CET time zone ±2 hours in Europe.
- Country-specific health, pension, and statutory benefits.
- Around-the-clock Employee Assistance Program providing emotional support, life coaching, dependent and elder care, financial and legal advice, wellness coaching, and new-parent resources.
- Quarterly wellness days granting an extra day off every quarter for relaxation and rejuvenation.
- Five paid volunteer days annually to support charitable or community service activities.
- Paid day off on birthdays.
- Employee recognition and rewards initiatives.
- A culture prioritizing personal and professional growth.
- Flexible remote working designed to promote a healthy work-life balance.
- Competitive salary and comprehensive total rewards tailored to the region.
- Opportunities to impact significant security research and develop expertise in application, cloud, and AI security domains.
Additional Information
This role is listed via a partner company that handles all applications and subsequent hiring steps. The selection process uses AI-powered matching to fairly evaluate candidates, with final decisions made by the hiring organization. Candidates must be located in or able to work remotely within the CET ±2 hour time frame to qualify.
Minimum education
Master's Degree