Senior Security Operations Engineer @Invicti Security
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted Today

[Hiring] Senior Security Operations Engineer @Invicti Security

Today - Invicti Security is hiring a remote Senior Security Operations Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Europe

Role Description

You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.

What You'll Be Doing

  • Build and maintain security checks and detection content that ship as part of the Invicti platform, with a focus on accuracy, coverage, and low false-positive rates.
  • Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and improve detection accuracy.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate them into production-ready detections.
  • Extend support for new programming languages across our analysis pipeline.
  • Triage packages from our analysis pipeline and validate findings.
  • Build attack chain templates that combine low-severity findings into higher-impact detection scenarios.
  • Contribute to evaluation harnesses and benchmarks that measure detection effectiveness β€” false-positive rates, coverage, and accuracy.
  • Build and maintain testing frameworks that validate detection quality, exploit reproducibility, and regression coverage.
  • Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.
  • Apply established detection and exploitation principles, and help refine our internal standards and methodologies.
  • Explore and experiment with new tools and techniques to detect threats and malware at scale.
  • Stay current on AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, MCP security, and emerging attack techniques, and apply those insights to detection engineering.
  • Collaborate across engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
  • Work with cloud-native infrastructure and CI/CD pipelines to integrate detection, testing, and validation into the development lifecycle.

Qualifications

  • 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent).
  • Broad knowledge of programming languages β€” JavaScript is a must, Python is a huge plus.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomy.
  • Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems β€” including detection logic, response interpretation, and false-positive management.
  • Hands-on web application pentesting experience covering the OWASP Top 10 and adjacent classes β€” authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
  • Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus.
  • Familiarity with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and HTTP/web protocol fundamentals.
  • Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
  • Fluent in English, with the ability to convey technical details to both technical and non-technical audiences.
  • Ability to collaborate effectively across multi-disciplinary teams and know when to escalate issues.
  • A hands-on attitude and intellectual curiosity, with a willingness to dig into both classic AppSec problems and emerging areas including AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems.

Bonus Points

  • OpenGrep (or Semgrep) experience.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Exposure to LLMs and prompt engineering.
  • Public security research output (CVEs, advisories, talks, open-source tools) or an interest in technical writing.
  • YARA experience.

Benefits

  • Tailored health, pension, and statutory perks customized to your country of residence.
  • Employee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more.
  • Excellent working Options: Working remotely.
  • Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate.
  • Volunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choice.
  • Paid Birthday Off: Take your birthday off to celebrate you!
  • Ongoing recognition & rewards. A Culture that emphasizes personal and professional growth.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Operations Engineer @Invicti Security
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 128,142+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later