J

Staff Security Researcher (Offensive Security, Web Applications, Cloud, AI)

Jobgether • France
Remote
Apply Now

Seeking a Staff Security Researcher in France to conduct advanced offensive security research across web applications, APIs, cloud, and AI systems. This role involves translating research into production-ready detection capabilities, developing exploit proof-of-concepts, and contributing to security standards. Requires 8+ years of offensive security experience, strong programming skills (JavaScript required, Python valued), and deep understanding of security principles and exploitation methodologies.

Key Highlights
Hands-on offensive security research with a focus on turning advanced vulnerability and malware research into production-ready detection capabilities.
Investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems.
Develop and maintain detection rules, evaluation frameworks, and attack-chain methodologies, contributing to research standards and the broader security community.
Key Responsibilities
Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy.
Extend security analysis capabilities to support additional programming languages across the analysis pipeline.
Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections.
Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities.
Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths.
Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates.
Triage complex findings and packages from the analysis pipeline and validate detection results.
Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies.
Explore emerging tools and techniques for detecting threats and malware at scale.
Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
Contribute to internal research initiatives and help shape future security research priorities.
Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions where appropriate.
Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained.
Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality.
Technical Skills Required
Offensive Security JavaScript Python
Benefits & Perks
Fully remote work from Europe (CET ±2 hours)
Health, pension, and statutory benefits tailored to country of residence
24/7 Employee Assistance Program
Quarterly wellness days
5 paid volunteer days per year
Paid birthday day off
Employee recognition and rewards programs
Culture focused on personal and professional development
Flexible, remote working environment
Competitive compensation and total-rewards approach
Nice to Have
Experience with OpenGrep or Semgrep
Static analysis
Production-ready security systems
YARA
Public security research such as CVEs, advisories, talks, or open-source tools

Job Description

This role is designed for a hands-on offensive security researcher who can turn advanced vulnerability and malware research into production-ready detection capabilities. You will investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems, translating discoveries into accurate security checks with low false-positive rates. The position combines deep technical research with practical engineering, from exploit proof-of-concepts to detection rules, evaluation frameworks, and attack-chain methodologies. You will also contribute to research standards, security tooling, and the broader application security community through publications and technical contributions. Working across engineering, product, AI/ML, and infrastructure teams, you will help ensure research moves efficiently from discovery to production. The role offers a high degree of ownership in a fast-evolving security environment where technical curiosity and measurable detection quality are highly valued.
Want the full job description? Read the complete details on LinkedIn, the original posting.
Continue on LinkedIn

This is a short excerpt. All rights to the full description belong to its original publisher.

See Jaabz jobs first on Google 1 tap · free · in AI Overviews Jaabz is on your Google Manage Preferred Sources

Similar Jobs

Explore other opportunities that match your interests

Security Research Engineer

Cyber Security
•
2w ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Opus Recruitment Solutions

France
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

wooclap

France
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

noris network AG

Germany

Subscribe our newsletter

New Things Will Always Update Regularly