C

Senior Security Researcher

CommIT · Ukraine

RemoteWorkplace
3d agoPosted · Aug 19
HimalayasSource
$130kpenetration tester median
Apply now Opens the original posting at CommIT. PivotHop does not host applications.
Experience5+ years

Skills in this posting

Benefits

The posting

Description

The company is the pioneer of Active ASPM, purpose-built to secure the modern software supply chain in the age of AI. While traditional tools overwhelm teams with endless alerts, company cuts through the noise to identify the critical 5% of risks — those that are truly reachable and exploitable. From GenAI-generated code to cloud runtime, the company gives developers and security teams the visibility and automation needed to ship secure software, faster.

We're looking for a highly skilled, driven Security Researcher to join our research group to analyze supply chain attacks, dissect malware, and build open-source tools. This is a high-impact role: you'll work with cross-functional teams to scan and protect users and organizations worldwide from the hottest cyber threats, playing a key part in shaping the future of company.

Must-Have Skills

5+ years of experience as a Cybersecurity Researcher (supply-chain attacks, malware analysis)

Familiarity with open-source registry ecosystems (npm, PyPI, Maven) and their respective attack surfaces

Proven ability to ship software in a production environment

Strong understanding of the SDLC and modern CI/CD pipelines

Comfortable leveraging AI tools to optimize research and development processes

Proactive and independent mindset, with the ability to take full ownership of projects

Nice to Have

Active contributions to open-source security tools or research projects

Hands-on experience with decompilers, debuggers, and network traffic analysis

Advanced malware analysis experience (obfuscation, encryption, anti-analysis, and sandbox-evasion techniques)

Web application penetration testing experience

Published CVEs, coordinated disclosures, writeups, blogs, or research papers

Experience public speaking at major industry conferences (e.g., Black Hat, DEFCON, RSAC)

A genuine passion for cybersecurity, open-source communities, and solving complex ecosystem threats

Originally posted on Himalayas

The PivotHop read

Where these skills also reach

More penetration tester roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves