2 месяца назад
Senior Security Research Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Research Engineer (Vulnerability Research & Exploit Validation): Researching vulnerabilities across operating systems, databases, cloud services, containers, enterprise applications, and network devices with an accent on exploitability analysis, safe validation, and detection content. Focus on building attacker-behavior emulation, improving research automation with AI and LLMs, and leading complex projects while mentoring security engineers.
Location: Pune, India
Company
provides cloud security and vulnerability management solutions, including vulnerability research and detection content for real-world threats.
What you will do
- Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research newly disclosed, zero-day, and actively exploited vulnerabilities, prioritizing work by real-world risk.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
- Build safe, controlled exploit-validation techniques that emulate attacker behavior without affecting production systems.
- Develop validation logic for WAF, firewall, EDR, IPS, and compensating controls, and establish quality standards for detection content.
- Improve automation, tooling, testing, release workflows, and the use of AI and LLMs in security research.
Requirements
- 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Strong knowledge of vulnerability analysis, exploit development, modern attack techniques, operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Proficiency with Python and Bash, plus experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Working knowledge of the OWASP Top 10 and current threat actor tactics.
- Experience leading projects, mentoring technical teammates, and communicating clearly in written, verbal, and technical formats.
Nice to have
- Experience applying AI or LLMs to security research or detection engineering.
- Contributions to CVEs, security advisories, open-source security tooling, or published research.
- OSCP, OSCE, OSED, GXPN, or similar certifications.
- Experience building detection content or signatures for IPS, WAF, or EDR platforms.
Culture & Benefits
- Hands-on senior individual-contributor role with ownership of complex research projects.
- Opportunity to choose research topics and develop deep expertise in selected areas.
- Collaboration with Engineering and Product teams.
- Mentoring responsibilities and opportunities for career growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →