Staff Security Researcher

Lever, Inc.

Ireland

Remote

EUR 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Fully remote in Europe
Health insurance
Pension plan
Wellness days
Volunteer days
Birthday day off
Employee recognition
Professional development

Job summary

Lever, Inc. is seeking a Staff Security Researcher based in Ireland to turn vulnerability and malware research into production-ready detections.

You will investigate threats across web apps, APIs, cloud-native environments, and AI-powered systems and translate findings into accurate security checks with low false positives. The role partners with engineering, product, and AI/ML teams, offering ownership in a fast-evolving security landscape.

Qualifications

  • 8+ years in offensive security or application security research or equivalent with degree.
  • Strong JavaScript and Python skills with production-grade security tooling experience.
  • Extensive experience writing detection logic for DAST/fuzzing/security systems, including handling FP rate management.
  • Experience designing testing frameworks and evaluation harnesses for security tooling.
  • Web application pentesting across OWASP Top 10, REST/GraphQL, and modern APIs.

Responsibilities

  • Create and maintain detection rules using OpenGrep to identify malware patterns.
  • Extend analysis to support more languages in the pipeline.
  • Research vulnerabilities, exploitation techniques, and AI threats to production-ready detections.
  • Develop PoCs for web apps and APIs, converting findings into deployable capabilities.
  • Create attack-chain templates linking findings to exploit paths.
  • Design evaluation harnesses and benchmarks to measure coverage and FP rates.
  • Triaged complex findings and validated detection results.
  • Collaborate with multiple teams to deploy research outputs.
  • Improve security automation across CI/CD and cloud-native environments.

Skills

JavaScript
Python
DAST
Fuzzers
Testing frameworks
Web pentesting
Algorithms
AST analysis
Burp Suite
SQLMap
Nmap
FFUF
HTTP/Web protocols
Cloud/Kubernetes
AI security
English communication
Collaboration
Hands-on research
OpenGrep/Semgrep
YARA

Education

Bachelor's degree in a relevant field
Master's degree (preferred)

Tools

Burp Suite
SQLMap
Nmap
FFUF
OpenGrep
Semgrep
YARA

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Researcher based in Ireland.

This role is designed for a hands-on offensive security researcher who can turn advanced vulnerability and malware research into production-ready detection capabilities. You will investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems, translating discoveries into accurate security checks with low false-positive rates. The position combines deep technical research with practical engineering, from exploit proof-of-concepts to detection rules, evaluation frameworks, and attack-chain methodologies. You will also contribute to research standards, security tooling, and the broader application security community through publications and technical contributions. Working across engineering, product, AI/ML, and infrastructure teams, you will help ensure research moves efficiently from discovery to production. The role offers a high degree of ownership in a fast-evolving security environment where technical curiosity and measurable detection quality are highly valued.

Accountabilities
  • Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy.
  • Extend security analysis capabilities to support additional programming languages across the analysis pipeline.
  • Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections.
  • Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities.
  • Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates.
  • Triage complex findings and packages from the analysis pipeline and validate detection results.
  • Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies.
  • Explore emerging tools and techniques for detecting threats and malware at scale.
  • Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
  • Contribute to internal research initiatives and help shape future security research priorities.
  • Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions where appropriate.
  • Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
  • Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained.
  • Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality.
Requirements
  • 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
  • Broad programming knowledge, with strong JavaScript skills required and Python experience highly valued.
  • Deep understanding of security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
  • Extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • Strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces.
  • Ability to tackle complex technical and algorithmic problems, including parsing and AST-based analysis.
  • Strong hands-on experience with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
  • Solid understanding of HTTP and web protocol fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
  • Fluent English with strong written and verbal communication skills and the ability to explain complex technical topics to both technical and non-technical audiences.
  • Strong collaboration skills and sound judgment when determining when issues require escalation.
  • Hands-on mindset, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and rapidly evolving AI security domains.
  • Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research such as CVEs, advisories, talks, or open-source tools is a plus.
Benefits
  • Fully remote work from Europe, with the role open to candidates working within CET ±2 hours.
  • Health, pension, and statutory benefits tailored to your country of residence.
  • 24/7 Employee Assistance Program offering emotional support, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new-parent support.
  • Quarterly wellness days providing an additional day off each quarter for rest and rejuvenation.
  • 5 paid volunteer days per year to support charitable or community activities of your choice.
  • Paid birthday day off.
  • Employee recognition and rewards programs.
  • A culture focused on personal and professional development.
  • Flexible, remote working environment designed to support work-life balance.
  • Competitive compensation and a broader total-rewards approach adapted to regional needs.
  • Opportunities to contribute to meaningful security research and develop expertise across application security, cloud, and AI security.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Offensive Security
Senior Security Engineer, Offensive Security

Jobgether • Ireland

On-site
EUR 119,000 - 170,000
Fully remote
EU compensation
Equity
+1
Offensive Security Engineer
Offensive Security Engineer

Lever, Inc. • Ireland

Remote
EUR 120,000 - 180,000
Equity
Remote-first work
Career development
+2
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • Ireland

On-site
EUR 120,000 - 180,000
Annual learning & development budget:
Remote-first work environment
In-person team sprints
+4
Lead Vulnerability Intelligence Analyst
Lead Vulnerability Intelligence Analyst

Lever, Inc. • Ireland

Remote
EUR 120,000 - 160,000
Remote-friendly culture
Wellness programs
Professional development
+2
Senior Security Researcher AI, Cloud & AppSec (Remote)
Senior Security Researcher AI, Cloud & AppSec (Remote)

Lever, Inc. • Ireland

Remote
EUR 120,000 - 180,000
Fully remote in Europe
Health insurance
Pension plan
+5
Senior Security Researcher
Senior Security Researcher

Vectra • Ireland

On-site
EUR 120,000 - 180,000
Senior AI Security Engineer (R-19324)
Senior AI Security Engineer (R-19324)

Dnb • Dublin

On-site
EUR 140,000 - 190,000
25 days annual leave
Holiday buy & sell (up to 5 days)
Flexible working - hybrid model
+7
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Realtime Recruitment • Dublin

On-site
EUR 70,000 - 110,000
Security Operations Analyst- Ireland
Security Operations Analyst- Ireland

Huntress • Ireland

Remote
EUR 70,000 - 90,000
Remote work environment
Home office stipend
Pension
+2
MDR Associate Analyst (Night Shift) - Hybrid Cork, Ireland
MDR Associate Analyst (Night Shift) - Hybrid Cork, Ireland

Malwarebytes • Cork

On-site
EUR 50,000 - 61,000
Medical Insurance
Referral Bonus
Wellness Programs
+1