Senior Security Operations Engineer
Core
Build and maintain security checks and detection content for an application security testing platform, focusing on accuracy, coverage, and low false-positive rates.
Role type
Senior offensive security researcher (detection engineering)
Builds
Production-ready detection rules, attack chain templates, and testing frameworks for a DAST platform
Domain
Application Security / Offensive Security / Malware Detection
Deliverable
production ML models | product features
Required skills
Offensive security research, vulnerability classification, exploitation techniques, web application pentesting, detection rule writing, programming (JavaScript, Python), HTTP/web protocols, AST parsing, CI/CD integration
Preferred skills
OpenGrep/Semgrep, static analysis, production system building, LLM/prompt engineering, YARA, public security research output
Technologies
OpenGrep, Semgrep, Burp Suite, sqlmap, nmap, ffuf, JavaScript, Python, REST, GraphQL
Responsibilities
Create new detection rules to catch novel malware and vulnerability patterns; Research vulnerability classes and emerging attack patterns; Extend support for new programming languages; Build attack chain templates; Contribute to evaluation harnesses and benchmarks; Build and maintain testing frameworks; Collaborate across engineering and product teams; Stay current on AppSec, AI security, and emerging attack techniques
Seniority
Senior, hands-on IC