Vulnerability Researcher
SearchlightFull Time
Job description
About the role
As a , you will play a crucial role in identifying and analyzing security vulnerabilities within various software applications and systems. Your expertise will contribute to enhancing the security posture of our products and services, ensuring that we remain a trusted partner for our clients. This position offers the opportunity to work with a talented team of professionals in a collaborative environment, where your insights will directly impact our security strategies and initiatives.
Key facts
What you'll do
- Conduct thorough research to identify potential vulnerabilities in software applications, systems, and networks, utilizing both automated tools and manual testing techniques.
- Collaborate with cross-functional teams, including developers and product managers, to communicate findings and recommend actionable remediation strategies.
- Develop and maintain a comprehensive vulnerability database to track identified issues and their resolution status.
- Create detailed reports outlining vulnerabilities, their potential impact, and suggested mitigation measures for internal stakeholders and clients.
- Stay up-to-date with the latest security trends, vulnerabilities, and threat intelligence to inform your research and recommendations.
- Participate in security assessments and penetration testing exercises to evaluate the effectiveness of existing security measures.
- Assist in the development and implementation of security policies and best practices across the organization.
- Provide training and guidance to team members on secure coding practices and vulnerability management.
- Engage with the security community by attending conferences, contributing to open-source projects, and sharing knowledge through blogs or presentations.
- Work closely with incident response teams to analyze security incidents and provide insights for future prevention strategies.
- Mentor junior researchers and interns, fostering a culture of learning and growth within the team.
- Contribute to the continuous improvement of the vulnerability management process, ensuring it aligns with industry standards and best practices.
Requirements
- A minimum of 3 years of experience in vulnerability research, penetration testing, or a related field.
- Strong understanding of common vulnerabilities and exposure (CVE) databases and frameworks, such as OWASP Top Ten.
- Proficiency in programming languages such as Python, Java, or C++, with the ability to write scripts for automation and testing purposes.
- Familiarity with security tools and technologies, including static and dynamic analysis tools, vulnerability scanners, and exploitation frameworks.
- Experience with network protocols and security concepts, including firewalls, intrusion detection systems, and encryption methods.
- Excellent analytical and problem-solving skills, with a keen attention to detail and the ability to think critically about security challenges.
Nice to have
- Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or Certified Information Systems Security Professional (CISSP).
- Experience with cloud security and understanding of cloud service models (IaaS, PaaS, SaaS).
- Knowledge of secure software development lifecycle (SDLC) practices and methodologies.
- Familiarity with regulatory compliance frameworks such as GDPR, HIPAA, or PCI-DSS.
- Previous experience in a fast-paced startup environment, demonstrating adaptability and initiative.
Skills & tools
- Proficient in using vulnerability assessment tools like Nessus, Burp Suite, or Qualys.
- Familiarity with version control systems, particularly Git, for collaborative development.
- Strong written and verbal communication skills, enabling effective collaboration with technical and non-technical stakeholders.
- Ability to work independently and manage multiple projects simultaneously in a remote work environment.
Practical notes
- The position is fully remote, allowing for flexibility in your work environment.
- Candidates should be prepared for occasional travel to attend conferences or team meetings, as necessary.
- The salary for this role is competitive and will be determined based on your experience and qualifications.
- Searchlight is committed to fostering a diverse and inclusive workplace, encouraging applicants from all backgrounds to apply.
META
Company: Searchlight
Title: Vulnerability Researcher
Listed
location: Unknown
Job type: Full-time
Apply URL: https://searchlight.bamboohr.com/careers/239