Senior Security Operations Engineer (Europe Remote)

Invicti Security

Austin (TX)

Remote

USD 101,000 - 135,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote-friendly
Thrive-Wellness Days
Volunteer time off
Birthday off

Job summary

Invicti Security is seeking a hands-on offensive security researcher to build detection content for the platform, focusing on accuracy and coverage. You will craft rule sets, translate vulnerability research into detections, and extend language support across the analysis pipeline.

Contribute to evaluation harnesses, benchmarks, and testing frameworks while collaborating with engineering, product, and AI/ML teams to ship scalable detection content.

Qualifications

  • 5+ years in offensive security or app security research.
  • Proficient in JavaScript; Python is a plus.
  • Strong knowledge of vulnerability classes and exploitation techniques.
  • Experience with DAST scanners, fuzzers, or similar detection systems.
  • Hands-on web app pentesting covering OWASP Top 10 and modern APIs.

Responsibilities

  • Develop and maintain detection content with focus on accuracy and low false positives.
  • Create new detection rules (OpenGrep) for malware and patterns.
  • Research attack vectors and translate findings into production detections.
  • Extend analysis pipeline support for new languages and frameworks.
  • Collaborate across teams to ship and operate detections in CI/CD.

Skills

JavaScript
Python
OpenGrep
Web app pentesting
OWASP Top 10

Education

Bachelor's degree or equivalent

Tools

Burp Suite
sqlmap
nmap
ffuf
OpenGrep

Job description

Location: Open to candidates residing anywhere in Europe, time zones (CET ± 2 hours)

Who We Are:

Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn.

Who you Are:

You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.

What You'll Be Doing:
  • Build and maintain security checks and detection content that ship as part of the Invicti platform, with a focus on accuracy, coverage, and low false-positive rates.
  • Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and improve detection accuracy.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate them into production-ready detections.
  • Extend support for new programming languages across our analysis pipeline.
  • Triage packages from our analysis pipeline and validate findings.
  • Build attack chain templates that combine low-severity findings into higher-impact detection scenarios.
  • Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy.
  • Build and maintain testing frameworks that validate detection quality, exploit reproducibility, and regression coverage.
  • Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.
  • Apply established detection and exploitation principles, and help refine our internal standards and methodologies.
  • Explore and experiment with new tools and techniques to detect threats and malware at scale.
  • Stay current on AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, MCP security, and emerging attack techniques, and apply those insights to detection engineering.
  • Collaborate across engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
  • Work with cloud-native infrastructure and CI/CD pipelines to integrate detection, testing, and validation into the development lifecycle.
What You'll Need:
  • 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent).
  • Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomi
  • Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management.
  • Hands-on web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
  • Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus.
  • Familiarity with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and HTTP/web protocol fundamentals.
  • Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
  • Fluent in English, with the ability to convey technical details to both technical and non-technical audiences.
  • Ability to collaborate effectively across multi-disciplinary teams and know when to escape issues.
  • A hands-on attitude and intellectual curiosity, with a willingness to dig into both classic AppSec problems and emerging areas including AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems.
  • Bonus Points
  • OpenGrep (or Semgrep) experience.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Exposure to LLMs and prompt engineering.
  • Public security research output (CVEs, advisories, talks, open-source tools) or an interest in technical writing.
  • YARA experience.
Why Invicti?
Your Health & Wellness Matters:

Tailored health, pension, and statutory perks customized to your country of residence

Employee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more

We value Adult/ Life Balance:

Excellent working Options: Working remotely

Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate

Volunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choice

Paid Birthday Off: Take your birthday off to celebrate you!

We Value You:

Employee Recognition: Ongoing recognition & rewards . A Culture that emphasizes personal and professional growth

At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.

As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth

"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer (Europe Remote)
Senior Security Operations Engineer (Europe Remote)

Invicti • Austin (TX), Northern (KY)

Hybrid
USD 140,000 - 200,000
Health & pension benefits
Remote-friendly policy
Wellness days
+3
Staff Security Researcher (Europe Remote)
Staff Security Researcher (Europe Remote)

Invicti • Austin (TX), Northern (KY)

Hybrid
USD 150,000 - 190,000
Remote work options
Volunteer time off
Wellness days
+1
Staff Security Researcher (Europe Remote)
Staff Security Researcher (Europe Remote)

Invicti Security • Austin (TX)

Remote
USD 101,000 - 146,000
Remote work options
Wellness days
Volunteer time off
+2
Staff Security Researcher
Staff Security Researcher

Invicti Security • United States

Hybrid
USD 130,000 - 190,000
Health Insurance
401(k) Plan
Hybrid work schedule
+2
Staff Security Researcher
Staff Security Researcher

Invicti • Austin (TX)

Hybrid
USD 140,000 - 210,000
Health insurance
Hybrid work schedule
Discretionary Time Off
+1
Staff Security Researcher
Staff Security Researcher

Invicti Security • Austin (TX)

On-site
USD 140,000 - 210,000
Health insurance
Hybrid work in Austin
401(k) match
+1
Staff Security Researcher
Staff Security Researcher

Invicti • United States

Hybrid
USD 140,000 - 200,000
Health Insurance
401(k) Savings Plan
Parental Leave
+1
Senior Product Marketing Manager
Senior Product Marketing Manager

Invicti • Austin (TX)

On-site
USD 120,000 - 160,000
Health Insurance
401(k) Plan
Parental Leave
+1
Senior Product Marketing Manager
Senior Product Marketing Manager

Invicti Security • Austin (TX)

On-site
USD 120,000 - 170,000
Health Insurance
Employee Assistance Program
Parental Leave
+6
Principal Product Manager
Principal Product Manager

Invicti Security • Austin (TX)

On-site
USD 180,000 - 240,000
Health Insurance
401(k) Savings Plan
Parental Leave
+3