Skip to content

Open nowPosted 20 days ago

Senior Security Operations Engineer

Workable (global search)107,990 open roles

Where
Birkirkara, Eastern Region, Malta
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Operations EngineerWorkable (global search) · Birkirkara, Eastern Region, Malta
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 6 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 20 days ago

Workable (global search) median: 6 days open

The posting

Who We Are:

Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide. Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn.

Requirements

Location: Candidates need to be based in Malta

Who You Are:

You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.

What You'll Be Doing:

  • Build and maintain security checks and detection content that ship as part of the Invicti platform, with a focus on accuracy, coverage, and low false-positive rates.
  • Create new detection rules (primarily OpenGrep) to catch novel malware and vulnerability patterns and improve detection accuracy.
  • Research vulnerability classes, exploitation techniques, and emerging attack patterns, and translate them into production-ready detections.
  • Extend support for new programming languages across our analysis pipeline.
  • Triage packages from our analysis pipeline and validate findings.
  • Build attack chain templates that combine low-severity findings into higher-impact detection scenarios.
  • Contribute to evaluation harnesses and benchmarks that measure detection effectiveness — false-positive rates, coverage, and accuracy.
  • Build and maintain testing frameworks that validate detection quality, exploit reproducibility, and regression coverage.
  • Help maintain detection quality across the platform, including triaging difficult or ambiguous findings.
  • Apply established detection and exploitation principles, and help refine our internal standards and methodologies.
  • Explore and experiment with new tools and techniques to detect threats and malware at scale.
  • Stay current on AppSec, offensive security, AI security, LLM vulnerabilities, AI agent security, MCP security, and emerging attack techniques, and apply those insights to detection engineering.
  • Collaborate across engineering, product, AI/ML, and infrastructure teams to ship and operate detection content.
  • Work with cloud-native infrastructure and CI/CD pipelines to integrate detection, testing, and validation into the development lifecycle.

What You'll Need:

  • 5+ years of offensive security or application security research experience (Bachelor's + 2 years, or equivalent).
  • Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus.
  • Strong understanding of vulnerability classifications, exploitation techniques, and common software weakness taxonomi
  • Working knowledge of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management.
  • Hands-on web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
  • Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
  • Experience building or maintaining testing frameworks, evaluation harnesses, or automated validation systems is a strong plus.
  • Familiarity with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and HTTP/web protocol fundamentals.
  • Familiarity with cloud infrastructure, containerized environments, and modern CI/CD or DevOps pipelines is a plus.
  • Fluent in English, with the ability to convey technical details to both technical and non-technical audiences.
  • Ability to collaborate effectively across multi-disciplinary teams and know when to escalate issues.
  • A hands-on attitude and intellectual curiosity, with a willingness to dig into both classic AppSec problems and emerging areas including AI security, LLM vulnerabilities, agentic systems, and MCP ecosystems.
  • Bonus Points
  • OpenGrep (or Semgrep) experience.
  • Static analysis experience.
  • Experience building production-ready systems.
  • Exposure to LLMs and prompt engineering.
  • Public security research output (CVEs, advisories, talks, open-source tools) or an interest in technical writing.
  • YARA experience.

Benefits

Why Invicti?

Your Health & Wellness Matters:

Health Insurance : Taking care of our team goes beyond the office. We cover 100% of employee health care and dental premium costs. For dependents, we contribute 100% of the health care and 50% dental premium cost

VDU testing: Upon joining us, we will provide for free a one time Visual Display Unit testing to ensure you can work as comfortable as possible

Employee Assistance Program: Emotional Support Counseling services 24/7. Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more

Family Leave: 16 week paid leave for birthing parent recovery. 4 week paid leave for non-birthing/bonding parent

We value Adult/ Life Balance:

Excellent working Options: Our teams operate in a hybrid office/home schedule

Quarterly Thrive-Wellness Days: One extra vacation day per quarter where the entire company takes a break from normal, daily activities to refresh and rejuvenate

Volunteerism Time Off: 5 days of paid time off each year to participate in the volunteer activities of your choice

Paid Birthday Off: Take your birthday off to celebrate you!

Mobile Allowance Benefit: This allowance will be provided to ensure you have support for work-related communication and tasks

We Value You:

Employee Recognition: Ongoing recognition & rewards . A Culture that emphasizes personal and professional growth

At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.

As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth

"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.