ApplySarthi

Staff Security Researcher

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

280 open researcher roles across 87 companies are on ApplySarthi right now, most of them in Bengaluru (11), Mumbai (2), Delhi NCR (2).

What researcher roles keep asking for: Python (41%), Machine learning (25%), C++ (22%), LLMs (12%) — counted across their open postings here.

Remote Security Researcher jobs · CI/CD jobs · GraphQL jobs · JavaScript jobs · Kubernetes jobs

Jobgether has 4,273 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for researcher roles keep coming back to Python, Machine learning, C++, LLMs. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with CI/CD? Tell me one thing you learned the hard way.
  3. How would you cut the cloud bill of a system without hurting it?
  4. How do you keep secrets and access safe in your infrastructure?
  5. Walk me through how code gets from a commit to production where you work.

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Staff Security Researcher at Jobgether interview free →

Accountabilities:: Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy. Extend security analysis capabilities to support additional programming languages across the analysis pipeline. Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections. Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities. Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths. Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates. Triage complex findings and packages from the analysis pipeline and validate detection results. Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies. Explore emerging tools and techniques for detecting threats and malware at scale. Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques. Contribute to internal research initiatives and help shape future security research priorities. Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions where appropriate. Mentor junior and mid-level security researchers on detection writing and exploitation techniques. Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained. Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality. Requirements: 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree. Broad programming knowledge, with strong JavaScript skills required and Python experience highly valued. Deep understanding of security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development. Extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management. Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling. Strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces. Ability to tackle complex technical and algorithmic problems, including parsing and AST-based analysis. Strong hands-on experience with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques. Solid understanding of HTTP and web protocol fundamentals. Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable. Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques. Fluent English with strong written and verbal communication skills and the ability to explain complex technical topics to both technical and non-technical audiences. Strong collaboration skills and sound judgment when determining when issues require escalation. Hands-on mindset, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and rapidly evolving AI security domains. Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research such as CVEs, advisories, talks, or open-source tools is a plus. Benefits: Fully remote work from Europe, with the role open to candidates working within CET ±2 hours. Health, pension, and statutory benefits tailored to your country of residence. 24/7 Employee Assistance Program offering emotional support, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new-parent support. Quarterly wellness days providing an additional day off each quarter for rest and rejuvenation. 5 paid volunteer days per year to support charitable or community activities of your choice. Paid birthday day off. Employee recognition and rewards programs. A culture focused on personal and professional development. Flexible, remote working environment designed to support work-life balance. Competitive compensation and a broader total-rewards approach adapted to regional needs. Opportunities to contribute to meaningful security research and develop expertise across application security, cloud, and AI security.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-02. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.