Staff Security Researcher (Europe Remote)
Invicti
- Remote job
Location: Open to candidates residing anywhere in Europe, time zones (CET ± 2 hours) Who we are: Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn. Who You Are: You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base. What You'll Be Doing: Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracy. Extend support for new programming languages across our analysis pipeline. Explore and experiment with cutting-edge tools and techniques to detect threats and malware at scale. Research novel ways to exploit and analyze modern web applications and APIs — building proof-of-concept attacks and translating findings into shippable capabilities. Research new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detections. Direct the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologies. Build attack chain templates that combine low-severity findings into high-impact exploitation paths. Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy. Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverage. Contribute to internal research and help shape our public research agenda. Write and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributions. Stay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilities. Triage packages from our analysis pipeline and validate findings. Mentor junior and mid-level researchers on detection writing and exploitation technique. Collaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operational. Partner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environments. Help maintain detection quality across the platform, including triaging difficult or ambiguous findings. What You'll Need: 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years). Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus. Strong understanding of security principles, standards, and best practices. Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices. Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management. Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling. Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL). Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs). Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying protocol fundamentals. Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable. Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques. Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences. Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to elevate issues. A hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security. Bonus Points: OpenGrep (or Semgrep) experience. Static analysis experience. Experience building production-ready systems. Public security research output (CVEs, advisories, talks, open-source tools). YARA experience. Why Invicti: Tailored health, pension, and statutory perks customized to your country of residence Employee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more Your Health & Wellness Matters: Excellent working Options: Working remotely Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate Volunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choice Paid Birthday Off: Take your birthday off to celebrate you! We value Adult/ Life Balance: Employee Recognition: Ongoing recognition & rewards . A Culture that emphasizes personal and professional growth At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being. We Value You: As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth "At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone #J-18808-Ljbffr Invicti
$122.5k - $175k
...customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange️ platform protects... ...era? Join us at Zscaler.RoleWe are looking for a Staff Threat Researcher to join our team. This is a remote role, reporting to the Manager Threat Research in...Remote workFull timeWork at officeLocal area$122.5k - $175k
...customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange platform protects... ...? Join us at Zscaler. Role We are looking for a Staff Threat Researcher to join our team. This is a remote role, reporting to the Manager Threat Research in...Remote workFull timeWork at officeLocal area- ...customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform... ...era? Join us at Zscaler. Role We are looking for a Staff Threat Researcher to join our team. This is a remote role, reporting to the Manager Threat Research in...Remote workFull time
- This a Full Remote job, the offer is available from: EMEA, United States, Europe, European Union, Massachusetts (USA), Ireland, California... ...Intelligence, it empowers security teams to rapidly prioritize,... ...Overview Vectra AI’s Security Research Team represents the core...Remote workWorldwide
- ...across 8 offices, spanning North America, Europe, and Asia, and representing over 20... ...cities worldwide. Your Mission: As a Staff User Researcher, you'll set and own the research agenda... ...Manager of User Research. This is a remote position, with a preference for candidates...Remote workWork at officeLocal areaImmediate startWork from homeWorldwideFlexible hours
$145k - $215.05k
...moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately... ....Job Summary:We’re looking for a curious and empathetic Staff Experience Researcher who is passionate about understanding user needs. Joining...Full timeWork at officeLocal areaImmediate startFlexible hours$139.6k - $225.78k
...precision that drives great outcomes.Job SummaryJob SummaryWe are seeking a passionate and self-driven Sr. Staff Researcher to join our Cloud-Delivered Security Services team. In this role, you will be pivotal in developing and refining the security content that powers...Full timeWork experience placementWork at officeVisa sponsorshipWork visa$127.08k - $277.2k
...PENN STATE EMPLOYEE (faculty, staff, technical service, or... ...external applicants.Approval of remote and hybrid work is not guaranteed... ...self-motivated Vulnerability Researcher to join our Cyberspace... ...system evaluation and provide security hardening support to various...Remote workFull timeFor contractorsWork experience placementWork from home- ...apply now.We are currently seeking a AI Researcher - Support & Innovation to join our team... ...capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and... ...client’s needs. While many positions offer remote or hybrid work options, these arrangements...Remote workTemporary workWork at officeFlexible hours
$380k
About the TeamThe Safety Training research team aims to fundamentally advance our capabilities... ...bad actors, how to address privacy and security risks, and how to make the model... ...380K - $500KLocationSan Francisco; US - Remote; Washington, DCEmployment TypeFull timeDepartmentSafety...Remote workWork at officeLocal areaFlexible hours$145.46k - $193.94k
...expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and... ..., join us today.The RoleBlack Lotus Labs is seeking a remote Threat Intelligence Researcher on the Research & Analysis team focused on tracking advanced...Remote workTemporary work$104.9k - $182.13k
...now.We are currently seeking a Applied AI Researcher to join our team in Jersey City, New... ...including latency, cost, observability, security, and AWS/cloud deployment considerations... ...client’s needs. While many positions offer remote or hybrid work options, these...Remote workFull timeTemporary workWork at officeFlexible hours$110k - $140k
...when others can’t. We conduct research and development, manage... ...mathematics to develop unique embedded security solutions for government and... ...work 60% in-office and 40% remote, with Monday and Tuesday as... ...local law. Our goal is for each staff member to have the...Remote workWork experience placementWork at officeLocal areaFlexible hours- ...As the first Security Researcher in a full-time hybrid role, the successful candidate will identify and exploit vulnerabilities in AI agent security, manage the research agenda from discovery to publication, and produce impactful findings that enhance customer protections...Remote workFull time
$175k - $225k
...Role: Cybersecurity Researcher Location: South Bay Area (On-site or Remote flexibility) Compensation: $175K - $225K + ~0.1% equity Visa: Sponsorship... ...-tier investors, the startup is building advanced security solutions at the intersection of applied research...Remote workVisa sponsorshipFlexible hours$127.08k - $277.2k
...PENN STATE EMPLOYEE (faculty, staff, technical service, or... ...applicants.### **Approval of remote and hybrid work is not guaranteed... ...self-motivated Vulnerability Researcher to join our Cyberspace Operations... ...evaluation and provide security hardening support to various...Remote workFull timeFor contractorsWork experience placementWork from homeFlexible hours$127.08k - $277.2k
...PENN STATE EMPLOYEE (faculty, staff, technical service, or... ...applicants. Approval of remote and hybrid work is not guaranteed... ...self-motivated Vulnerability Researcher to join our Cyberspace Operations... ...evaluation and provide security hardening support to various...Remote workFull timeFor contractorsWork experience placementWork from home- Cybersecurity Researcher (Remote / SF Bay Area) Are you the kind of person who breaks things to understand them—then builds stronger defenses... ...of AI, agentic systems, and your own deep curiosity for security. About Us We’re a well‑funded AI startup ($25M seed round...Remote workFull timeWork at office
$179.3k - $318.4k
...at the forefront of national security, providing advanced solutions... ...oriented SME CNO Vulnerability Researcher to join our team in Columbia,... ...Collaborative (IIC) staff. Minimum Qualifications:... ...role, geographic location (For Remote Opportunities), education and...Remote workHourly payContract workTemporary workWork experience placementWork at officeLocal area$110.8k - $179.23k
..., we invite you to join us!This role is remote, but distance is no barrier to impact. Our... ...and findings.Collaborate with multiple research and development groups.Contribute to... ...and techniques, as well as networking and security fundamentals.Experience investigating targeted...Remote workFull timeVisa sponsorshipWork visa- ...our nation’s most demanding space-related security challenges backed by validated analysis,... ...national defense strategy. What will you do?Our staff are skilled scientists and engineers with... ...develop and execute strategies to solve research questions. Guide and integrate the work...
- Senior UX Researcher Design (Remote - Europe) We are seeking a seasoned UX Researcher to help shape the future of health, nutrition, and wellness products within a globally distributed, remote-first environment. In this role, you will conduct strategic and generative research...Remote jobFull timeContract workFlexible hoursShift work
- ...their best work together.What’s the role?We’re looking for a Staff UX Researcher to help define and raise the quality of experiences across... ...proximity, we ask team members to come in once or twice per week. Remote candidates outside commutable distance may be considered on...Remote workFull timeWork at officeLocal areaVisa sponsorship
$145.75k - $300.07k
...in our recruiting process here.Pinterest is looking for a Staff Qualitative researcher to play a crucial role in the Pinterest monetization team... ...therefore can be situated anywhere in the country. #LI-REMOTE#LI-JD3At Pinterest we believe the workplace should be equitable...Remote workWork at officeLocal areaImmediate startRelocationRelocation package- ...As a full-time remote Staff User Researcher, the successful candidate will set and own the research agenda across multiple product areas, identifying key questions and opportunities while translating findings into actionable insights for leadership and mentoring other...Remote workFull time
- GitLab seeks a Staff Security Research Engineer to advance AI-powered DevSecOps security. You will conduct cutting-edge security research, develop novel testing methodologies for AI agents, and perform hands-on penetration testing to identify and remediate vulnerabilities...Remote job
- SigIntZero is expanding its security research team with a remote Security Researcher who will investigate emerging attack vectors in Web3, develop internal tooling, and contribute to public security advisories. You will operate at the frontier of Web3 security, analyzing...Remote jobFor contractors
- CrowdStrike is seeking a security researcher to analyze in-the-wild exploits and document exploitation techniques. The role sits in the Technical... ...across teams to inform mitigations and products. This remote role may require travel and demands strong writing and communication...Remote job
- CrowdStrike is seeking a security researcher to analyze exploits in-the-wild, support adversary tracking, and build automated tooling for exploit... ...a proven ability to communicate complex findings clearly. Remote work with occasional travel is supported, with competitive...Remote job
- CrowdStrike is seeking a Security Researcher to join the Intelligence team, focusing on analyzing in-the-wild exploits and documenting vulnerability... ...communicate complex findings to technical and non-technical audiences. Remote work with travel可能. #J-18808-Ljbffr CrowdStrikeRemote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Researcher (Europe Remote). Be the first to apply!
- criminal researcher New York, NY
- security researcher New York, NY
- court researcher New York, NY
- field researcher New York, NY
- human factors researcher New York, NY
- academic researcher New York, NY
- independent researcher New York, NY
- survey researcher New York, NY
- qualitative researcher New York, NY
- researcher New York, NY


