Назад
Company hidden
2 месяца назад

Senior Security Research Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Research Engineer (Vulnerability Research & Exploit Validation): Researching vulnerabilities across operating systems, databases, cloud services, containers, enterprise applications, and network devices with an accent on exploitability analysis, safe validation, and detection content. Focus on building attacker-behavior emulation, improving research automation with AI and LLMs, and leading complex projects while mentoring security engineers.

Location: Pune, India

Company

hirify.global provides cloud security and vulnerability management solutions, including vulnerability research and detection content for real-world threats.

What you will do

  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research newly disclosed, zero-day, and actively exploited vulnerabilities, prioritizing work by real-world risk.
  • Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
  • Build safe, controlled exploit-validation techniques that emulate attacker behavior without affecting production systems.
  • Develop validation logic for WAF, firewall, EDR, IPS, and compensating controls, and establish quality standards for detection content.
  • Improve automation, tooling, testing, release workflows, and the use of AI and LLMs in security research.

Requirements

  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong knowledge of vulnerability analysis, exploit development, modern attack techniques, operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Proficiency with Python and Bash, plus experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10 and current threat actor tactics.
  • Experience leading projects, mentoring technical teammates, and communicating clearly in written, verbal, and technical formats.

Nice to have

  • Experience applying AI or LLMs to security research or detection engineering.
  • Contributions to CVEs, security advisories, open-source security tooling, or published research.
  • OSCP, OSCE, OSED, GXPN, or similar certifications.
  • Experience building detection content or signatures for IPS, WAF, or EDR platforms.

Culture & Benefits

  • Hands-on senior individual-contributor role with ownership of complex research projects.
  • Opportunity to choose research topics and develop deep expertise in selected areas.
  • Collaboration with Engineering and Product teams.
  • Mentoring responsibilities and opportunities for career growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →