Senior Security Researcher
CommIT · Ukraine
Skills in this posting
Benefits
The posting
Description
The company is the pioneer of Active ASPM, purpose-built to secure the modern software supply chain in the age of AI. While traditional tools overwhelm teams with endless alerts, company cuts through the noise to identify the critical 5% of risks — those that are truly reachable and exploitable. From GenAI-generated code to cloud runtime, the company gives developers and security teams the visibility and automation needed to ship secure software, faster.
We're looking for a highly skilled, driven Security Researcher to join our research group to analyze supply chain attacks, dissect malware, and build open-source tools. This is a high-impact role: you'll work with cross-functional teams to scan and protect users and organizations worldwide from the hottest cyber threats, playing a key part in shaping the future of company.
Must-Have Skills
5+ years of experience as a Cybersecurity Researcher (supply-chain attacks, malware analysis)
Familiarity with open-source registry ecosystems (npm, PyPI, Maven) and their respective attack surfaces
Proven ability to ship software in a production environment
Strong understanding of the SDLC and modern CI/CD pipelines
Comfortable leveraging AI tools to optimize research and development processes
Proactive and independent mindset, with the ability to take full ownership of projects
Nice to Have
Active contributions to open-source security tools or research projects
Hands-on experience with decompilers, debuggers, and network traffic analysis
Advanced malware analysis experience (obfuscation, encryption, anti-analysis, and sandbox-evasion techniques)
Web application penetration testing experience
Published CVEs, coordinated disclosures, writeups, blogs, or research papers
Experience public speaking at major industry conferences (e.g., Black Hat, DEFCON, RSAC)
A genuine passion for cybersecurity, open-source communities, and solving complex ecosystem threats
Originally posted on Himalayas
The PivotHop read
- What a penetration tester actually earnsmedian, seniority, by country
- Careers a penetration tester can move intoevery measured route out
- Security Engineer → Penetration Tester69% readiness
- All open penetration tester rolesthe full board
Where these skills also reach
- 336 open security engineer roles48% readiness from penetration tester
- 72 open network engineer roles33% readiness from penetration tester
- 553 open it support specialist roles25% readiness from penetration tester
- 565 open solutions architect roles24% readiness from penetration tester
More penetration tester roles
Offensive Security Lead at NebiusEurope · Remote5d agoApply
Penetration Tester (Only for GR Residents) at AI2CYBERGreece · Remote6d agoApply
Offensive Security Engineer at PalantirWashington, D.C.1w agoApply
Junior Offensive Security Engineer at SatispayMilan, Italy · Remote1w agoApply
AI Security Research & Red Team Engineer at CloudflareHybrid$166k–$208k1w agoApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.