Enable job alerts via email!

Security Research Engineer for Wallarm

Hire5

United States

Remote

USD 80,000 - 140,000

Full time

25 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Security Research Engineer, where you'll drive innovation in API security. This exciting role involves researching and developing advanced testing capabilities while collaborating with engineering teams to tackle emerging threats. You'll be at the forefront of the industry, translating complex vulnerabilities into actionable solutions. Enjoy the flexibility of fully remote work, competitive salary, and opportunities for professional growth while contributing to a product that enhances Internet security. If you have a passion for security research and technical expertise, this role is perfect for you.

Benefits

Flexible working hours
Competitive salary
Performance-based bonuses
Paid time off
Medical insurance
Working equipment
Professional development opportunities

Qualifications

  • Proven experience in security roles, with a focus on API security and vulnerability management.
  • Strong understanding of API protocols and application security concepts.

Responsibilities

  • Investigate API threats and enhance security testing capabilities.
  • Design and implement automated vulnerability scanning features.
  • Analyze industry trends and collaborate with teams for security best practices.

Skills

Security Engineering
API Security
Vulnerability Management
Automation for Security Testing
Communication Skills
API Protocols
OWASP Top 10

Tools

CI/CD Pipelines
SAST/DAST Tools
Programming Languages (Python, Go, Ruby)

Job description

Security Research Engineer (Security Testing Product) for Wallarm - a San Francisco-based API security platform (remote)

Wallarm is an API security platform that focuses on protecting AI-driven innovation, modern applications, and cloud infrastructures. APIs, being the primary attack vector for cybercriminals, often face vulnerabilities that existing tools can't address effectively. Many API security solutions today only offer observability without the ability to prevent attacks, requiring complex deployments and significant human involvement.

Wallarm stands out by offering the fastest, easiest, and most effective way to stop API attacks. The platform provides a comprehensive inventory of APIs, patented AI/ML-based abuse detection, real-time blocking, and an API Security Operations Center (SOC)-as-a-service. Unlike traditional solutions that simply alert on suspicious behavior, Wallarm proactively works to fix API security issues, not just identify them. The platform can be easily deployed inline to block attacks, and its expert API SOC team ensures continuous protection 24/7/365.

Headquartered in San Francisco, California, Wallarm is supported by investors like Toba Capital, Y Combinator, Partech, and others.

More short facts about Wallarm:

  • Global remote-first team of 100+ people on 4 continents and in 10+ countries.
  • They have been protecting clients since 2014.
  • The company has raised over $10M in investments.
  • More than 200 customers around the world, including Fortune 500, Nasdaq, and high-growth startups choose Wallarm to protect their API and web applications.
  • The company passed Y Combinator, the most prestigious incubator in Silicon Valley, from which Dropbox, Stripe, Docker, etc. came out.

About the role:

As a Security Research Engineer for our Security Testing Product, you will drive innovation in API security by researching, designing, and developing advanced testing capabilities. You will collaborate with engineering teams to identify and address emerging threats, ensuring our solutions remain at the forefront of the industry. This role requires deep technical expertise, a passion for security research, and the ability to translate complex vulnerabilities into actionable solutions.

Key Responsibilities:

  • Security Research: Investigate emerging API threats, vulnerabilities, and attack vectors (e.g., OWASP API Top 10) to enhance our security testing capabilities.
  • Feature Development: Design and implement new testing features, such as automated vulnerability scanning and API-specific threat detection, in collaboration with developers.
  • Technical Leadership: Define technical requirements for complex security features and guide their implementation.
  • Threat Analysis: Analyze industry trends, competitor offerings, and real-world attack patterns to inform product enhancements.
  • Collaboration: Work closely with engineering, product, and customer success teams to integrate security best practices (e.g., OWASP API Top 10) into our solutions.
  • Innovation: Propose and prototype cutting-edge testing methodologies, including AI-driven or MLOps-based approaches to threat detection.

Job Requirements:

Must-Have Skills:

  • Proven experience as a Security Engineer, Security Researcher, or similar role in the security domain (e.g., SAST/DAST, Vulnerability Management, or API security).
  • Strong understanding of API protocols such as JSON-API, GraphQL, XML-RPC, JSON-RPC, OData, gRPC, WebSocket, SOAP, and others.
  • Expertise in application security concepts (e.g., OWASP Top 10, OWASP API Top 10) and vulnerability exploitation techniques.
  • Past experience in automation for security testing tools and pentets.
  • Knowledge of Secure Software Development Lifecycle (SSDLC) and integrating security solutions into CI/CD pipelines.
  • Excellent communication skills to articulate complex security concepts to technical and non-technical stakeholders.

Nice-to-Have Skills:

  • Expertise in API-specific attacks or participation in vulnerability assessments (e.g., bug bounty programs).
  • Proficiency in programming languages like Python, Go, or Ruby for scripting and tool development.
  • Familiarity with MLOps practices or AI-driven approaches to threat detection.

What we offer:

  • The opportunity to work on a product that enhances Internet security.
  • Fully remote work with flexible working hours.
  • Competitive salary and performance-based bonuses.
  • Paid time off.
  • Medical insurance.
  • Working equipment.
  • Professional development and career growth opportunities.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.