Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Staff Security Researcher role.
Rezi rewrites your resume against Invicti Security's job description. Free.

Tailor your resume to this Staff Security Researcher role.
Rezi rewrites your resume against Invicti Security's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Staff Security Researcher posting at Invicti Security — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Staff Security Researcher posting at Invicti Security — free, in seconds.
About the Role
Invicti Security is seeking a hands-on offensive security researcher to create detection content that ships. You will own the security checks you build, write accurate detection rules, and focus on quality and low false-positive rates. Apply research principles to ensure security checks deliver solid results for customers.
Responsibilities
- Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and boost detection accuracy.
- Extend support for new programming languages across our analysis pipeline.
- Explore and experiment with cutting-edge tools and techniques to detect threats and malware at scale.
- Research novel ways to exploit and analyze modern web applications and APIs — building proof-of-concept attacks and translating findings into shippable capabilities.
- Research new vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors, and convert research into production-ready detections.
- Direct the application of existing detection and exploitation principles while contributing to new policies, research standards, and attack methodologies.
- Build attack chain templates that combine low-severity findings into high-impact exploitation paths.
- Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy.
- Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems that continuously measure detection accuracy, exploit reproducibility, false-positive rates, and coverage.
- Contribute to internal research and help shape our public research agenda.
- Write and publish blog posts on novel attacks and large-scale incidents, and represent Invicti in the security community through CVEs, tool releases, and conference contributions.
- Stay current on industry trends in AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques, and translate those insights into research priorities and product capabilities.
- Triage packages from our analysis pipeline and validate findings.
- Mentor junior and mid-level researchers on detection writing and exploitation technique.
- Collaborate across engineering, product, AI/ML, and infrastructure teams to ensure research output ships and stays operational.
- Partner with platform and infrastructure teams to improve security automation across CI/CD pipelines and cloud-native environments.
- Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.
Requirements
- 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
- Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus.
- Strong understanding of security principles, standards, and best practices.
- Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.
- Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management.
- Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
- Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
- Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
- Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying HTTP/web protocol fundamentals.
- Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
- Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
- Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences.
- Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues.
- A hands-on attitude, intellectual curiosity and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security.
Skills
- JavaScript
- Python
- OpenGrep
- Semgrep
- Static analysis
- YARA
- Burp Suite
- sqlmap
- nmap
- ffuf
- HTTP/web protocol fundamentals
- Cloud platforms
- Kubernetes
- Containers
- Infrastructure-as-code
- CI/CD security
- LLM vulnerabilities
- Agent security
- MCP security
- Cloud-native attack techniques
- AI red-teaming
- Offensive AI
- Prompt injection
- Model abuse
- Tool invocation risks
- Emerging AI attack techniques
Location
- Austin, Texas
Work Type
- Hybrid
Experience Level
- 8+ years of offensive security or application security research experience
- Bachelor's + 5 years experience
- Master's + 3 years experience
Education Level
- Bachelor's degree
- Master's degree
Benefits
- 100% employee health, vision, and dental premium coverage
- 75% dependent health premium contribution
- 50% dependent vision/dental premium contribution
- 24/7 Employee Assistance Program with Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, and New Parent Support
- 16 weeks paid parental leave for birthing parents
- 4 weeks paid parental leave for non-birthing/bonding parents
- 401(k) Savings Plan with 50% company match up to 6%
- Discretionary Time Off
- Quarterly Thrive-Wellness Days
- 5 days of paid Volunteerism Time Off
- Paid Birthday Off
- Ongoing recognition & rewards
About the Company
- Invicti Security delivers the industry’s most accurate application security platform, transforming how web applications are secured for nearly 20 years.
- Recognized as a leader in Application Security Testing and a DAST Innovator by Latio.
- Enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation.
- Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide.
- Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development.
- Operates in a dynamic, fast-paced industry.
Equal Opportunity
- At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone feels valued and included. So come as you are and join us in shaping the future of our industry.