Staff Security Researcher

Invicti

Austin (TX)

Hybrid

USD 140,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Hybrid work schedule
Discretionary Time Off
401(k) match

Job summary

Invicti, based in Austin, TX, seeks a senior security researcher to build detection rules, extend language support, and innovate at scale. You will explore novel malware patterns, analyze complex web apps, and translate findings into production-ready detections that advance our security platform.

You will collaborate across engineering, AI/ML, and infrastructure teams, mentor peers, and contribute to Invicti’s research agenda while staying current on appsec and cloud-native security trends.

Qualifications

  • 5+ years in offensive or application security research.
  • Deep understanding of vulnerability classifications and exploit methods.
  • Experience with detection writing for security tooling and DAST scanners.

Responsibilities

  • Create and extend detection rules for malware and vulnerabilities.
  • Research new vulnerability classes and AI-related attack vectors.
  • Collaborate with engineering and security teams to ship detections.
  • Write and publish research blog posts and CVEs.
  • Mentor junior researchers on detection writing and exploits.
  • Improve security automation across CI/CD and cloud-native environments.

Skills

Offensive security
Application security
OWASP Top 10
DAST/Fuzzers
Cloud security

Education

Bachelor's degree in CS/Math/Engineering
5+ years relevant experience

Tools

Burp Suite
sqlmap
nmap
ffuf

Job description

Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn.

What You'll Be Doing:

  • Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracy.
  • Extend support for new programming languages across our analysis pipeline.
  • Explore and experiment with cutting-edge tools and techniques to detect threats and malware at scale.
  • Research novel ways to exploit and analyze modern web applications and APIs — building proof-of-concept attacks and translating findings into shippable capabilities.
  • Research new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detections.
  • Direct the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologies.
  • Build attack chain templates that combine low-severity findings into high-impact exploitation paths.
  • Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverage.
  • Contribute to internal research and help shape our public research agenda.
  • Write and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributions.
  • Stay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilities.
  • Triage packages from our analysis pipeline and validate findings.
  • Mentor junior and mid-level researchers on detection writing and exploitation technique.
  • Collaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operational.
  • Partner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environments.
  • Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.

What You'll Need:

  • 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
  • Strong understanding of security principles, standards, and best practices.
  • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.
  • Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
  • Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
  • Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying HTTP/web protocol fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
  • Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences.
  • Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to elevate issues.
  • A hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security.

Bonus Points:

  • OpenGrep (or Semgrep) experience.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Public security research output (CVEs, advisories, talks, open-source tools).
  • YARA experience.

Why Invicti:

Your Health & Wellness Matters:

Health Insurance: Taking care of our team goes beyond the office. We cover 100% of employee health care, vision and dental premium costs. For dependents, we contribute 75% of the health care and 50% vision/dental premium cost, so you can be sure that you and your family are in the best possible health. Coverage is effective your first day.

Employee Assistance Program: Emotional Support Counseling services - 24/7 Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more

Parental Leave16 week paid leave for birthing parent recovery. 4 week paid leave for non-birthing/bonding parent

401(k) Savings Plan: 50% up to 6% company match with 100% annual cliff vesting

We Value Adult/Life Balance:

Hybrid: Twice a week from our Austin office, hybrid/home schedule

Discretionary Time Off: Enjoy a flexible vacation schedule where you do not have to wait to use time off until it is accrued

Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate

Volunteerism Time Off : 5 days of paid time off each year to participate in the volunteer activities of your choice

Paid Birthday Off: Take your birthday off to celebrate you!

We Value You:

Employee Recognition: Ongoing recognition & rewards. A Culture that emphasizes personal and professional growth

At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.

As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth

"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone feels valued and included. So come as you are and join us in shaping the future of our industry."

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Researcher
Staff Security Researcher

Invicti Security • United States

Hybrid
USD 130,000 - 190,000
Health Insurance
401(k) Plan
Hybrid work schedule
+2
Staff Security Researcher
Staff Security Researcher

Invicti Security • Austin (TX)

On-site
USD 140,000 - 210,000
Health insurance
Hybrid work in Austin
401(k) match
+1
Staff Security Researcher
Staff Security Researcher

Invicti • United States

Hybrid
USD 140,000 - 200,000
Health Insurance
401(k) Savings Plan
Parental Leave
+1
Senior Product Marketing Manager
Senior Product Marketing Manager

Invicti Security • United States

Hybrid
USD 140,000 - 190,000
Health Insurance
Parental Leave
401(k) Savings Plan
Senior Product Marketing Manager
Senior Product Marketing Manager

Invicti • Austin (TX)

Hybrid
USD 120,000 - 160,000
Health Insurance
401(k) Plan
Parental Leave
+1
Senior Product Marketing Manager
Senior Product Marketing Manager

Invicti Security • Austin (TX)

On-site
USD 120,000 - 170,000
Health Insurance
Employee Assistance Program
Parental Leave
+6
Principal Product Manager
Principal Product Manager

Invicti Security • Austin (TX)

On-site
USD 180,000 - 240,000
Health Insurance
401(k) Savings Plan
Parental Leave
+3
Senior Software Engineer, Agentic AI
Senior Software Engineer, Agentic AI

Invicti Security Corp • Austin (TX)

On-site
USD 150,000 - 190,000
Health Insurance
401k Plan
Parental Leave
+1
Solutions Engineer
Solutions Engineer

Invicti Security • Austin (TX)

On-site
USD 110,000 - 140,000
Health Insurance
EAP (Employee Assistance Program)
Parental Leave
+6
Principal Product Manager
Principal Product Manager

Invicti • Austin (TX)

On-site
USD 160,000 - 210,000
Health Insurance
Employee Assistance Program
Parental Leave
+5