Security Researcher II (WAF)

Lever, Inc.

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Safe is seeking a Threat Research Engineer in Bengaluru to join our AI-driven cyber risk platform. You will work with the Threat Research team focusing on vulnerability analysis of web apps, and build automations to monitor policies and CVEs.

You should have hands-on WAF experience, strong HTTP knowledge, and Python plus REST API skills; experience with LLMs for automation is a plus. The role offers ownership and high-impact work.

Qualifications

  • Hands-on experience with WAF products (implementation, tuning, automation).
  • Strong understanding of HTTP protocol and web traffic.
  • Proficient in Python and REST APIs; able to build automations.
  • Experience using LLMs for automation engineering and research.
  • Open source contributions or published research are a plus.
  • Ability to clearly document technical findings for teams and customers.
  • Ability to work independently with minimal supervision.
  • Excellent communication and interpersonal skills.

Responsibilities

  • Primary role is to work with the Threat Research team focusing on vulnerability research to analyze affected products and trigger conditions for newly released vulnerabilities.
  • Utilize vulnerability and exploit intel feeds to identify applicable compensating controls and policies to prevent exploitation of CVEs.
  • Research various WAF products to identify APIs that provide details about attack surface protected, policies applied and enforcement status.
  • Build automation that continuously monitor changes in these policies and APIs of these WAF solutions.
  • Setup a lab to apply compensating controls and policies to validate whether that can prevent exploitation of the CVE.
  • Map and review auto generated mapping of CVEs to compensating controls and policies which feeds back to our CTEM product.

Skills

WAF experience
HTTP protocol
Python & REST APIs
LLMs for automation
Open source contributions
Documentation
Independent work
Communication

Education

M.Tech/B.Tech/B.E./BCA in CS/IT

Job description

Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we providecertainty.

We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud toserve 10% of the Fortune 500, protecting global icons such asApple, Netflix, AT&T, Verizon, and Victoria’s Secret.

As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.

The Culture Memo: Our Operating System

Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.

  • Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.

  • The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.

  • Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.

  • Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.

  • The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.

The Perks & Ownership:

We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.

  • Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.

  • Unlimited Leaves: We don’t believe in clock-watching. We offerunlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.

  • Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.

  • Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.

Location: Bangalore

Experience: 2 to 4 years

Core Responsibilities:

  • Primary role is to work with the Threat Research team focussing on vulnerability research to analyze affected products and trigger conditions for newly released vulnerabilities

  • Utilize vulnerability and exploit intel feeds to identify applicable compensating controls and policies to prevent successful exploitation of these CVEs

  • Research various WAF products to identify APIs that provides details about attack surface protected, policies applied and the enforcement status of these policies

  • Build automation that continuously monitor changes in these policies and APIs of these WAF solutions

  • Setup a lab to apply compensating controls and policies to validate whether that can prevent the exploitation of the CVE in question

  • Map and review auto generated mapping of CVEs to compensating controls and policies which feeds back to our CTEM product


Essential Skills, Experience and Qualifications:
  • M.Tech or B.Tech / B.E. / BCA in Computer Science or Information Technology

  • Must have hands-on experience in working with WAF products (implementation, fine tuning and building automations)

  • Strong understanding of HTTP protocol

  • Proficiency in Python (or a similar language) and experience working with REST APIs.

  • Must have experience in effectively utilizing LLMs for automation engineering and research such as using LLMs to parse advisories, generate mappings, or build agentic workflows

  • Contributions to open source tools or published research is nice-to-have

  • Able to clearly document technical findings for both research team and customer success team

  • Able to work independently with minimum supervision

  • Effective communication, and interpersonal skills

Any of the following certifications would be preferred:

  • Vendor WAF Certification

If you’re passionate about cyber risk, thrive in a fast-paced environment, and want to be part of a team that’s redefining security, we want to hear from you!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Researcher II (WAF)
Security Researcher II (WAF)

Balbix, Inc. • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Vulnerability Researcher II
Vulnerability Researcher II

Balbix, Inc. • New Delhi

On-site
INR 2,500,000 - 4,000,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Vulnerability Researcher II
Vulnerability Researcher II

Safe Security • Delhi

On-site
INR 2,500,000 - 5,000,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II (AEV)
Threat Researcher II (AEV)

Lever, Inc. • New Delhi

On-site
INR 1,800,000 - 2,400,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Vulnerability Researcher II
Vulnerability Researcher II

Safe • New Delhi

On-site
INR 1,800,000 - 3,000,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II
Threat Researcher II

Balbix, Inc. • New Delhi

On-site
INR 1,500,000 - 3,500,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II
Threat Researcher II

Safe Security • Delhi

On-site
INR 1,500,000 - 2,100,000
Threat Researcher II AEV
Threat Researcher II AEV

Safe Security • India

On-site
INR 1,200,000 - 1,800,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II (AEV)
Threat Researcher II (AEV)

Balbix, Inc. • New Delhi

On-site
INR 1,400,000 - 2,200,000
Meaningful Equity
Unlimited Leaves
Comprehensive Benefits
+1
Threat Researcher II (AEV)
Threat Researcher II (AEV)

Safe Security • Delhi

On-site
INR 1,200,000 - 2,400,000