Staff Security Researcher
Socket.dev
Who we are: Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn. Who You Are: You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base. What You'll Be Doing: Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracy. Extend support for new programming languages across our analysis pipeline. Explore and experiment with cutting-edge tools and techniques to detect threats and malware at scale. Research novel ways to exploit and analyze modern web applications and APIs — building proof-of-concept attacks and translating findings into shippable capabilities. Research new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detections. Direct the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologies. Build attack chain templates that combine low-severity findings into high-impact exploitation paths. Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy. Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverage. Contribute to internal research and help shape our public research agenda. Write and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributions. Stay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilities. Triage packages from our analysis pipeline and validate findings. Mentor junior and mid-level researchers on detection writing and exploitation technique. Collaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operational. Partner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environments. Help maintain detection quality across the platform, including triaging difficult or ambiguous findings. What You'll Need: 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years). Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus. Strong understanding of security principles, standards, and best practices. Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices. Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management. Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling. Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL). Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs). Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying protocol fundamentals. Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable. Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques. Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences. Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalation issues. A hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security. Bonus Points: OpenGrep (or Semgrep) experience. Static analysis experience. Experience building production-ready systems. Public security research output (CVEs, advisories, talks, open-source tools). YARA experience. Why Invicti: Your Health & Wellness Matters: Health Insurance: Taking care of our team goes beyond the office. We cover 100% of employee health care, vision and dental premium costs. For dependents, we contribute 75% of the health care and 50% vision/dental premium cost, so you can be sure that you and your family are in the best possible health. Coverage is effective your first day. Employee Assistance Program: Emotional Support Counseling services - 24/7 Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more Parental Leave16 week paid leave for birthing parent recovery. 4 week paid leave for non-birthing/bonding parent 401(k) Savings Plan: 50% up to 6% company match with 100% annual cliff vesting We Value Adult/Life Balance: Hybrid: Twice a week from our Austin office, hybrid/home schedule Discretionary Time Off: Enjoy a flexible vacation schedule where you do not have to wait to use time off until it is accrued Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate Volunteerism Time Off : 5 days of paid time off each year to participate in the volunteer activities of your choice Paid Birthday Off: Take your birthday off to celebrate you! We Value You: Employee Recognition: Ongoing recognition & rewards. A Culture that emphasizes personal and professional growth At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being. As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth “At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone feels valued and included. So come as you are and join us in shaping the future of our industry.” #J-18808-Ljbffr Socket.dev
- CrowdStrike is seeking a self-starting Security Researcher to join our Counter Adversary Operations Team. The role focuses on LatAm-language eCrime actors, OSINT collection, and producing insight for intelligence products used by customers. The candidate will track actors...Suggested
- Invicti Security in Austin is seeking a senior offensive security researcher to develop detection rules for malware and vulnerabilities, extend the analysis pipeline, and translate findings into scalable protections for web apps and APIs. You will lead research on threat...Suggested
$70k - $95k
...changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on... ...self-starting, action-oriented, and highly motivated Security Researcher to join our Counter Adversary Operations Team. This position...SuggestedWork experience placementWork at officeLocal area$105k - $130k
...the DoD community, as well as Homeland Security, advanced technologies, environmental, and... ...offer you! Position Biotechnology Researcher for Microbial Genetic/Synthetic Biology... ...personnel shall present the information to staff, universities, private corporations,...SuggestedFor contractorsFlexible hours$110.8k - $179.23k
...industry by sharing knowledge and findings.Collaborate with multiple research and development groups.Contribute to making the world a safer... ...tools, tactics, and techniques, as well as networking and security fundamentals.Experience investigating targeted, sophisticated,...SuggestedFull timeRemote workVisa sponsorshipWork visa$198.1k - $268k
...applications—from ultra-efficient IoT endpoints to ground breaking server-class SoCs. Our silicon-proven portfolio spans interconnects, security IP, system controllers, debug and trace, and IP tooling, all purpose-built and optimized for Arm Cortex processors and Arm Mali...Work at officeLocal areaWorldwide$127k - $249k
MongoDB, Inc. is seeking an experienced Senior or Staff Engineer for their SRE, InfraSec team, responsible for guiding the security of cloud-based infrastructure. The role involves hands-on technical work and mentorship of a small team while collaborating with engineering...Remote workFlexible hours- ...set of AI-assisted and agentic creation tools.We are hiring a Staff Security Architect to be a senior technical authority on how security... ...developer-facing platforms.Contributions to AI security standards, research, tooling, or open source.Base Salary Range: We determine the...Full timeWork at officeRemote workWorldwide
- ...Job Posting Title: Postdoctoral Researcher ---- Hiring Department: Department of Psychology ---- Position Open To:... ...law under Title IX and the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery Act). If this position...For contractorsWork at office
- ...like the idea of working diverse events? If so, then an event staff job could be a great opportunity for you! Your Day... ...operating concession stands, serving as ushers, ticket-takers, or security personnel. Cleaning or setting work areas, tables, or counters...Weekend workAfternoon shiftEarly shift
- ...will maintain a clean vehicle, follow safety policies, report incidents promptly, and present a professional image while supporting Houseman and security duties as needed. This is a guest-facing, full- or part-time role. #J-18808-Ljbffr TEXAS WESTERN MANAGEMENT PARTNERSFull timePart timeLocal area
$15 - $18.5 per hour
Civitech in Austin, Texas is looking for a Researcher to support civic participation by researching various elections and candidate details. You’ll play a crucial role in providing accurate data and engaging with team initiatives aimed at progressive causes. This contractor...Remote jobFor contractorsFlexible hours- The University of Texas at Austin, Cockrell School of Engineering, invites applications for a Post-Doctoral Researcher in the Hildebrand Department. The role focuses on computational and experimental studies of electromagnetic properties of rocks, with emphasis on interpretation...
$68k
...Geothermal Conformance and Flow Control Researcher Hiring Department Bureau of Economic Geology... ...interest Employment Eligibility Regular staff who have been employed in their current... ...the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery...For contractorsWork at officeLocal areaImmediate startAfternoon shift- Serverless Ventures ( is hiring an AI Researcher Intern to explore the cutting edge of AI at the intersection of Edge AI , Vertical AI , and large-scale software and content generation. We're looking for someone who thinks rigorously, ships fast, and brings genuine intellectual...InternshipLocal areaRemote work
$15 - $18.5 per hour
...Civitech’s tools to reach tens of millions of voters to help create a more equitable and progressive democracy. Responsibilities Researchers, who can be based anywhere in the U.S., are responsible for researching a wide range of topics, including elections at all levels...Full timeContract workPart timeFor contractorsWork at officeLocal area- Job Description The Research department at Dimensional is integral both in the successful day-to-day functioning of the firm and in developing Dimensional’s long-term strategy. The team produces high-quality, thought-leadership research on investments and financial markets...
$15 - $18.5 per hour
A civic technology organization seeks a Researcher to explore election topics and candidate qualifications. Responsibilities include researching various election-related topics across the U.S., mentoring new researchers, and contributing to data collection processes. Candidates...Hourly payContract workRemote work- VulnCheck, The Exploit Intelligence Company, is seeking a Senior Vulnerability Researcher for its Initial Access Intelligence group. You will drive original vulnerability research, reverse engineer firmware, and develop weaponized exploits across various OSes and devices...Remote job
$127.68k - $175.56k
...Job Description Job Description We're looking for a Staff Business Systems Analyst – Workday Security & ITGC Lead to join Procore's Enterprise Technology and Business Platforms team. In this hands-on technical role, you will be the system administrator and technical...Local areaImmediate start$68k
...Geothermal Conformance and Flow Control Researcher Job Posting Title Geothermal Conformance... ...Employment Eligibility Regular staff who have been employed in their current... ...and the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery Act...For contractorsWork at officeImmediate startAfternoon shift- Applied Research Laboratories at UT Austin invites a Research Associate to advance GNSS signals and software research on the Pickle Research Campus. You will contribute to designs, implement algorithms in C++ and Python, and publish findings for sponsor reviews and scientific...Immediate start
- SentiLink seeks a Quantitative Researcher to build core products: models that detect fraud and advance risk analytics. This role suits new PhD graduates or early-career researchers applying ML to real‑world fraud. You will develop and ship ML models in production, gain...Remote job
$53.46k
A prestigious research institution in Austin seeks a Post-Doctoral Researcher in the Department of Petroleum and Geosystems Engineering. Responsibilities include conducting research on electromagnetic properties of rocks and publishing findings. Candidates must have a...$68k
...Geothermal Conformance and Flow Control Researcher -- Hiring Department: Bureau of Economic... ...above. Employment Eligibility: Regular staff who have been employed in their current... ...and the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery Act...For contractorsWork at officeImmediate startAfternoon shift- Wireless Systems Researcher Apple is seeking a Wireless Systems Researcher to apply RF technology expertise to user-centered research that informs the design and development of Apple's wireless products. This role investigates how real-world usage—such as body-worn interference...
- A public benefit corporation is seeking skilled researchers to investigate topics surrounding elections and civic engagement. The role calls for strong attention to detail, effective communication skills, and the ability to manage time efficiently. Additionally, researchers...For contractors
- Google is offering Student Researcher internships in the United States. Eligible students are pursuing a Bachelor’s or Master’s degree in Computer Science or related fields, with opportunities across Google research and engineering teams. Start dates typically August through...Remote jobInternshipFlexible hours
- All Options is seeking Graduate Quantitative Researchers in Austin, TX, offering a six-month training program blending options theory with market making. You will join a cohort and move to active research under mentorship, coaching, and performance feedback. Cohort start...
- Optiver seeks a Graduate Quantitative Researcher to tackle challenging quantitative problems in global financial markets. You’ll work with researchers, engineers, and traders to analyze large datasets, develop predictive models, and apply statistical and machine learning...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Researcher. Be the first to apply!
- field researcher Austin, TX
- human factors researcher Austin, TX
- data collection researcher Austin, TX
- product researcher Austin, TX
- security researcher Austin, TX
- researcher Austin, TX
- music researcher Austin, TX
- remote researcher Austin, TX
- design researcher Austin, TX
- machine learning researcher Austin, TX



