Staff Security Researcher

Lever, Inc.

France

À distance

EUR 90 000 - 140 000

Plein temps

Il y a 4 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Avantages offerts par ce poste

Fully remote Europe
Health & pension
Wellness days
Volunteer days

Résumé du poste

Lever, Inc. is seeking a Staff Security Researcher in France to lead hands-on offensive security research across web apps, APIs, cloud-native environments, and AI-powered systems. You will transform research into production-ready detections, build PoCs, and contribute to security tooling.

Collaboration with engineering, product, AI/ML, and infrastructure teams is essential. The role emphasizes ownership, low false-positive detections, and evolving security research standards while publishing

Qualifications

  • 8+ years in offensive security or application security research
  • Broad programming knowledge with strong JavaScript and Python
  • Experience writing detection logic for security tooling
  • Web API security and OWASP Top 10
  • Experience with cloud-native security and CI/CD security

Responsabilités

  • Create and maintain detection rules for malware and vulnerabilities
  • Extend analysis capabilities to new languages
  • Research vulnerabilities, exploitation techniques, and AI threats
  • Develop PoCs and deployable security detections
  • Design evaluation harnesses and benchmarks
  • Triage complex findings and validate results
  • Publish technical research and contribute to security community
  • Mentor junior researchers and collaborate across teams

Connaissances

JavaScript
Python
Offensive security
Web app pentesting
Burp Suite
sqlmap
nmap
ffuf
OpenGrep
Semgrep
Threat research

Formation

Bachelor's or Master's in CS/Security

Outils

OpenGrep
Semgrep
Burp Suite
YARA
CVEs/Advisories

Description du poste

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Researcher based in France.

This role is designed for a hands-on offensive security researcher who can turn advanced vulnerability and malware research into production-ready detection capabilities. You will investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems, translating discoveries into accurate security checks with low false-positive rates. The position combines deep technical research with practical engineering, from exploit proof-of-concepts to detection rules, evaluation frameworks, and attack-chain methodologies. You will also contribute to research standards, security tooling, and the broader application security community through publications and technical contributions. Working across engineering, product, AI/ML, and infrastructure teams, you will help ensure research moves efficiently from discovery to production. The role offers a high degree of ownership in a fast-evolving security environment where technical curiosity and measurable detection quality are highly valued.

Accountabilities:
  • Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy.
  • Extend security analysis capabilities to support additional programming languages across the analysis pipeline.
  • Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections.
  • Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities.
  • Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates.
  • Triage complex findings and packages from the analysis pipeline and validate detection results.
  • Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies.
  • Explore emerging tools and techniques for detecting threats and malware at scale.
  • Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
  • Contribute to internal research initiatives and help shape future security research priorities.
  • Publish technical research through blog posts, CVEs, advisories, tool releases and conference contributions where appropriate.
  • Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
  • Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained.
  • Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality.

Requirements:

  • 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
  • Broad programming knowledge, with strong JavaScript skills required and Python experience highly valued.
  • Deep understanding of security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
  • Extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • Strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces.
  • Ability to tackle complex technical and algorithmic problems, including parsing and AST-based analysis.
  • Strong hands-on experience with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
  • Solid understanding of HTTP and web protocol fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
  • Fluent English with strong written and verbal communication skills and the ability to explain complex technical topics to both technical and non-technical audiences.
  • Strong collaboration skills and sound judgment when determining when issues require escalation.
  • Hands-on mindset, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and rapidly evolving AI security domains.
  • Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research such as CVEs, advisories, talks, or open-source tools is a plus.

Benefits:

  • Fully remote work from Europe, with the role open to candidates working within CET ±2 hours.
  • Health, pension, and statutory benefits tailored to your country of residence.
  • 24/7 Employee Assistance Program offering emotional support, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new-parent support.
  • Quarterly wellness days providing an additional day off each quarter for rest and rejuvenation.
  • 5 paid volunteer days per year to support charitable or community activities of your choice.
  • Paid birthday day off.
  • Employee recognition and rewards programs.
  • A culture focused on personal and professional development.
  • Flexible, remote working environment designed to support work-life balance.
  • Competitive compensation and a broader total-rewards approach adapted to regional needs.
  • Opportunities to contribute to meaningful security research and develop expertise across application security, cloud, and AI security.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security Operations Engineer
Senior Security Operations Engineer

Lever, Inc. • France

À distance
EUR 70 000 - 110 000
Fully remote
Health benefits
Pension plan
+8
Security Engineer - Paris / Lyon / Cracow
Security Engineer - Paris / Lyon / Cracow

Atlas Metrics • Tassin-la-Demi-Lune

Sur place
EUR 60 000 - 90 000
Hybrid work model
RTT days
Meal vouchers (SWILE)
+2
Senior Backend Engineer | Cybersecurity AI AppSec
Senior Backend Engineer | Cybersecurity AI AppSec

United States Digital Space LLC • Paris

Sur place
EUR 90 000 - 130 000
Significant equity
Top-tier health insurance
Meal vouchers
+5
Security Risk Management Specialist
Security Risk Management Specialist

Lever, Inc. • France

Sur place
EUR 70 000 - 110 000
Remote-first working environment
In-person team sprints (twice yearly)
Learning & development budget (USD 2,0
+5
CyberSecurity Engineer, Offensive Security
CyberSecurity Engineer, Offensive Security

Mistral • Paris

Sur place
EUR 70 000 - 90 000
Competitive salary and equity
Health insurance
Transportation allowance
+5
Cyber Security Engineer
Cyber Security Engineer

Leap29 • France

Sur place
EUR 70 000 - 100 000
Remote work in France
On-call rotation pay
Lead Security Researcher
Lead Security Researcher

Escape • Paris

Sur place
EUR 75 000 - 95 000
Significant equity
Top-tier health insurance
Meal vouchers
+5
Staff Engineer (Core & MLOps)
Staff Engineer (Core & MLOps)

Lever, Inc. • France

À distance
EUR 120 000 - 170 000
Fully remote
Flexible hours
Global collaboration
Senior Security Engineer
Senior Security Engineer

DataDome • France

Sur place
EUR 70 000 - 90 000
500€ stipend for workspace setup
Generous health benefits
Annual allowance for leisure activities
+2
AI Research Engineer (Prototyping, AI & Research) – France
AI Research Engineer (Prototyping, AI & Research) – France

Hornetsecurity GmbH • France

Sur place
EUR 60 000 - 100 000
Meal vouchers €10 per voucher (Hornet)
Public transport costs fully covered
Health insurance
+3