Skip to content

Open nowPosted 10 hours agoWe saw it 16 min after it went up

Staff Security Researcher

Jobgether4,394 open roles

Where
Switzerland
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security ResearcherJobgether · Switzerland
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 10 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Researcher based in Switzerland.

This role is designed for a hands-on offensive security researcher who can turn advanced vulnerability and malware research into production-ready detection capabilities. You will investigate emerging threats across web applications, APIs, cloud-native environments, and AI-powered systems, translating discoveries into accurate security checks with low false-positive rates. The position combines deep technical research with practical engineering, from exploit proof-of-concepts to detection rules, evaluation frameworks, and attack-chain methodologies. You will also contribute to research standards, security tooling, and the broader application security community through publications and technical contributions. Working across engineering, product, AI/ML, and infrastructure teams, you will help ensure research moves efficiently from discovery to production. The role offers a high degree of ownership in a fast-evolving security environment where technical curiosity and measurable detection quality are highly valued.

Accountabilities:

  • Create and maintain detection rules, primarily using OpenGrep, to identify novel malware and vulnerability patterns and improve detection accuracy.
  • Extend security analysis capabilities to support additional programming languages across the analysis pipeline.
  • Research emerging vulnerabilities, exploitation techniques, cloud-native attack paths, and AI-specific threats, translating findings into production-ready detections.
  • Investigate modern web applications and APIs, develop proof-of-concept attacks, and convert research findings into deployable security capabilities.
  • Develop attack-chain templates that connect lower-severity findings into meaningful exploitation paths.
  • Design and maintain evaluation harnesses, testing frameworks, and benchmarks to measure coverage, accuracy, exploit reproducibility, and false-positive rates.
  • Triage complex findings and packages from the analysis pipeline and validate detection results.
  • Apply established detection and exploitation principles while contributing to new research standards, policies, and attack methodologies.
  • Explore emerging tools and techniques for detecting threats and malware at scale.
  • Research security topics across AppSec, AI red-teaming, offensive AI, LLM vulnerabilities, agent security, MCP security, and cloud-native attack techniques.
  • Contribute to internal research initiatives and help shape future security research priorities.
  • Publish technical research through blog posts, CVEs, advisories, tool releases, and conference contributions where appropriate.
  • Mentor junior and mid-level security researchers on detection writing and exploitation techniques.
  • Collaborate with engineering, product, AI/ML, infrastructure, platform, and security teams to ensure research outputs are successfully deployed and maintained.
  • Help improve security automation across CI/CD and cloud-native environments while maintaining high detection quality.
  • 8+ years of experience in offensive security or application security research, or equivalent experience supported by a relevant Bachelor's or Master's degree.
  • Broad programming knowledge, with strong JavaScript skills required and Python experience highly valued.
  • Deep understanding of security principles, standards, best practices, vulnerability classifications, exploitation methodologies, and secure software development.
  • Extensive experience writing detection logic for DAST scanners, fuzzers, or comparable security systems, including response interpretation and false-positive management.
  • Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
  • Strong web application penetration-testing experience covering the OWASP Top 10, authentication, authorization, business logic, REST, GraphQL, and modern API surfaces.
  • Ability to tackle complex technical and algorithmic problems, including parsing and AST-based analysis.
  • Strong hands-on experience with offensive security tools such as Burp Suite, sqlmap, nmap, ffuf, and custom payload-generation techniques.
  • Solid understanding of HTTP and web protocol fundamentals.
  • Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
  • Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
  • Fluent English with strong written and verbal communication skills and the ability to explain complex technical topics to both technical and non-technical audiences.
  • Strong collaboration skills and sound judgment when determining when issues require escalation.
  • Hands-on mindset, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and rapidly evolving AI security domains.
  • Experience with OpenGrep or Semgrep, static analysis, production-ready security systems, YARA, or public security research such as CVEs, advisories, talks, or open-source tools is a plus.
  • Fully remote work from Europe, with the role open to candidates working within CET ±2 hours.
  • Health, pension, and statutory benefits tailored to your country of residence.
  • 24/7 Employee Assistance Program offering emotional support, life coaching, dependent and elder care, financial and legal support, wellness coaching, and new-parent support.
  • Quarterly wellness days providing an additional day off each quarter for rest and rejuvenation.
  • 5 paid volunteer days per year to support charitable or community activities of your choice.
  • Paid birthday day off.
  • Employee recognition and rewards programs.
  • A culture focused on personal and professional development.
  • Flexible, remote working environment designed to support work-life balance.
  • Competitive compensation and a broader total-rewards approach adapted to regional needs.
  • Opportunities to contribute to meaningful security research and develop expertise across application security, cloud, and AI security.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.