Senior Security Operations Engineer – Europe

🔥 19 minutes ago

🇷🇴 Romania – Remote

⏰ Full Time

🟠 Senior

🛡️ Security Operations

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Invicti

Invicti

201 - 500 employees

Founded 2018

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Cybersecurity • SaaS • Enterprise

Invicti is a cybersecurity company that provides a DAST-first, proof-based application security platform for organizations to discover, validate, prioritize, and remediate web, API, and container vulnerabilities. The platform combines dynamic application security testing (DAST) with ASPM, SCA, SAST integrations, and AI-powered automation to reduce false positives, speed remediation, and integrate security into CI/CD workflows. Invicti serves enterprise and highly regulated customers across sectors, offering scalable, compliance-ready deployments and broad integrations with developer and security tooling.

📋 Description

• Build and maintain security checks and detection content for the Invicti platform • Create new OpenGrep detection rules for novel malware and vulnerability patterns • Research vulnerability classes, exploitation techniques, and emerging attack patterns • Translate research into production-ready detections • Extend support for new programming languages across the analysis pipeline • Triage analysis-pipeline packages and validate findings • Build attack-chain templates combining low-severity findings into higher-impact detection scenarios • Contribute to evaluation harnesses and benchmarks measuring false-positive rates, coverage, and accuracy • Build and maintain testing frameworks for detection quality, exploit reproducibility, and regression coverage • Triage difficult or ambiguous findings and maintain platform detection quality • Refine internal detection and exploitation standards and methodologies • Explore new tools and techniques for detecting threats and malware at scale • Apply current AppSec, offensive security, AI security, LLM vulnerability, AI agent security, MCP security, and emerging attack research to detection engineering • Collaborate with engineering, product, AI/ML, and infrastructure teams • Integrate detection, testing, and validation into cloud-native infrastructure and CI/CD pipelines

🎯 Requirements

• 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent) • Broad knowledge of programming languages • JavaScript is a must • Python is a huge plus • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomies • Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management • Hands-on web application pentesting experience covering the OWASP Top 10 and adjacent classes, including authentication, authorization, business logic, REST, and GraphQL • Comfortable researching and tackling hard problems and algorithms, such as parsing with ASTs • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus • Familiarity with Burp Suite, sqlmap, nmap, ffuf, custom payload generation, and HTTP/web protocol fundamentals • Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus • Fluent in English • Ability to convey technical details to technical and non-technical audiences • Ability to collaborate effectively across multi-disciplinary teams and know when to escalate issues • Hands-on attitude and intellectual curiosity • OpenGrep or Semgrep experience • Static analysis experience • Experience building production-ready systems • Exposure to LLMs and prompt engineering • Public security research output, such as CVEs, advisories, talks, or open-source tools, or an interest in technical writing • YARA experience

🏖️ Benefits

• Tailored health, pension, and statutory perks customized to your country of residence • Employee Assistance Program with 24/7 emotional support counseling • Life Coaching • Dependent Care support • Elder Care support • Financial & Legal Support • Wellness Coaching • New Parent Support • Working remotely • Quarterly Thrive-Wellness Days: one extra vacation day per quarter • Volunteerism Time Off: 5 days of paid time off each year • Paid Birthday Off • Employee Recognition, ongoing recognition and rewards • Personal and professional growth opportunities • Competitive compensation • Meaningful benefits and opportunities for recognition and development

Apply Now

Similar Jobs

🕒 2 days ago

Talan

1001 - 5000

💼 Consulting

🏢 Enterprise

☁️ SaaS

Senior Cybersecurity Analyst protecting Talan’s global clients through 24x7 SOC monitoring and incident response. Investigating threats across SIEM, EDR, cloud, Windows and Linux environments.