
201 - 500 employees
Founded 2018
🔒 Cybersecurity
☁️ SaaS
🏢 Enterprise
Cybersecurity • SaaS • Enterprise
Invicti is a cybersecurity company that provides a DAST-first, proof-based application security platform for organizations to discover, validate, prioritize, and remediate web, API, and container vulnerabilities. The platform combines dynamic application security testing (DAST) with ASPM, SCA, SAST integrations, and AI-powered automation to reduce false positives, speed remediation, and integrate security into CI/CD workflows. Invicti serves enterprise and highly regulated customers across sectors, offering scalable, compliance-ready deployments and broad integrations with developer and security tooling.
🔥 19 minutes ago
🌐 Poland, Romania, +4 more countries – Remote
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 2018
🔒 Cybersecurity
☁️ SaaS
🏢 Enterprise
Cybersecurity • SaaS • Enterprise
Invicti is a cybersecurity company that provides a DAST-first, proof-based application security platform for organizations to discover, validate, prioritize, and remediate web, API, and container vulnerabilities. The platform combines dynamic application security testing (DAST) with ASPM, SCA, SAST integrations, and AI-powered automation to reduce false positives, speed remediation, and integrate security into CI/CD workflows. Invicti serves enterprise and highly regulated customers across sectors, offering scalable, compliance-ready deployments and broad integrations with developer and security tooling.
• Create new OpenGrep detection rules for novel malware and vulnerability patterns • Extend support for new programming languages across the analysis pipeline • Experiment with tools and techniques to detect threats and malware at scale • Research exploitation and analysis of modern web applications and APIs • Build proof-of-concept attacks and translate findings into shippable capabilities • Research vulnerability classes, exploitation techniques, cloud-native attack paths, and AI-specific attack vectors • Convert research into production-ready detections • Contribute to research standards, policies, and attack methodologies • Build attack chain templates combining low-severity findings into high-impact exploitation paths • Design and maintain evaluation harnesses, testing frameworks, and benchmarking systems • Measure detection effectiveness, exploit reproducibility, false-positive rates, and coverage • Contribute to internal research and shape the public research agenda • Write and publish blog posts on novel attacks and large-scale incidents • Represent Invicti in the security community through CVEs, tool releases, and conference contributions • Monitor AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack trends • Triage analysis-pipeline packages and validate findings • Mentor junior and mid-level researchers • Collaborate with engineering, product, AI/ML, and infrastructure teams • Partner with platform and infrastructure teams to improve CI/CD and cloud-native security automation • Maintain detection quality by triaging difficult or ambiguous findings
• 8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years) • Broad knowledge of programming languages; JavaScript is required and Python is a strong plus • Strong understanding of security principles, standards, and best practices • Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices • Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems, including detection logic, response interpretation, and false-positive management • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling • Deep web application pentesting experience covering the OWASP Top 10, authentication, authorization, business logic, REST, and GraphQL • Ability to research and tackle hard problems and algorithms, including parsing with ASTs • Fluency with offensive tooling including Burp Suite, sqlmap, nmap, ffuf, and custom payload generation • Understanding of HTTP/web protocol fundamentals • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques • Fluent in English, with strong written and verbal communication skills • Ability to convey technical details to technical and non-technical audiences • Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues • Hands-on attitude, intellectual curiosity, and willingness to research across application security, cloud-native security, and AI security • OpenGrep or Semgrep experience is a bonus • Static analysis experience is a bonus • Experience building production-ready systems is a bonus • Public security research output such as CVEs, advisories, talks, or open-source tools is a bonus • YARA experience is a bonus
• Tailored health, pension, and statutory perks customized to your country of residence • Employee Assistance Program with 24/7 emotional support counseling • Life Coaching • Dependent Care support • Elder Care support • Financial & Legal Support • Wellness Coaching • New Parent Support • Remote working options • Quarterly Thrive-Wellness Days: one extra vacation day per quarter • Volunteerism Time Off: 5 days of paid time off each year • Paid Birthday Off • Employee recognition and rewards • Personal and professional growth opportunities • Competitive compensation • Meaningful benefits • Opportunities for recognition and development
Apply Now🕒 September 4
Staff Security Engineer securing RTB House’s Deep Learning-powered DSP, infrastructure, and software development practices. Designing organization-wide controls and standards across engineering and security operations.
🇵🇱 Poland – Remote
💰 Private Equity Round on 2019-01
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🗣️🇵🇱 Polish Required
Cloud
Distributed Systems
Java
Kubernetes
Linux
Python
C++
Go
🕒 September 4
Security engineer building Imunify360’s Node.js runtime protection product from scratch. Designing attack detection and launching transparent, real-time defenses for hosting environments.
JavaScript
Linux
Node.js
🕒 August 10
Security Architect designing enterprise security across Azure, identity, infrastructure, and SaaS. Shaping secure technology strategy for Unit4’s cloud ERP software and global customers.
Azure
Cloud
Cyber Security
Kubernetes
Python
Terraform
🕒 August 4
Security Architect shaping Azure, identity, and multi-cloud security for Unit4, an enterprise ERP software company. Embedding Zero Trust, DevSecOps, and secure architecture across global technology platforms.
Azure
Cloud
Cyber Security
Kubernetes
Python
Terraform
🕒 July 27
Director of IT & Security at Ajaia overseeing IT operations, security, and compliance across a multi-cloud environment while leveraging AI tools for automation.
Azure
Cloud
Cyber Security
Google Cloud Platform
Terraform