Logo for Commit

Security Researcher

Key Facts

Category:  Security Analyst
Full time
Senior (5-10 years)
English

Other Skills

  • β€’
    Public Speaking
  • β€’
    Proactivity

Roles & Responsibilities

  • 5+ years of experience as a Cybersecurity Researcher
  • Familiarity with open-source registry ecosystems
  • Proven ability to ship software in a production environment
  • Strong understanding of the SDLC and modern CI/CD pipelines

Requirements:

  • Analyze supply chain attacks and dissect malware
  • Build open-source tools
  • Work with cross-functional teams to scan and protect users and organizations
  • Shape the future of cybersecurity regarding modern threats

Job description

Description

Company is the pioneer of Active ASPM, purpose-built to secure the modern software supply chain in the age of AI. While traditional tools overwhelm teams with endless alerts, cuts through the noise to identify the critical 5% of risks β€” those that are truly reachable and exploitable. From GenAI-generated code to cloud runtime, company gives developers and security teams the visibility and automation needed to ship secure software, faster.

We're looking for a highly skilled, driven Security Researcher to join our research group to analyze supply chain attacks, dissect malware, and build open-source tools. This is a high-impact role: you'll work with cross-functional teams to scan and protect users and organizations worldwide from the hottest cyber threats, playing a key part in shaping the future.


Requirements

Must-Have Skills:

  • 5+ years of experience as a Cybersecurity Researcher (supply-chain attacks, malware analysis)
  • Familiarity with open-source registry ecosystems (npm, PyPI, Maven) and their respective attack surfaces
  • Proven ability to ship software in a production environment
  • Strong understanding of the SDLC and modern CI/CD pipelines
  • Comfortable leveraging AI tools to optimize research and development processes
  • Proactive and independent mindset, with the ability to take full ownership of projects

Nice to Have:

  • Active contributions to open-source security tools or research projects
  • Hands-on experience with decompilers, debuggers, and network traffic analysis
  • Advanced malware analysis experience (obfuscation, encryption, anti-analysis, and sandbox-evasion techniques)
  • Web application penetration testing experience
  • Published CVEs, coordinated disclosures, writeups, blogs, or research papers
  • Experience public speaking at major industry conferences (e.g., Black Hat, DEFCON, RSAC)
  • A genuine passion for cybersecurity, open-source communities, and solving complex ecosystem threats



Security Analyst Related jobs

Other jobs at Commit

We help you get seen. Not ignored.

We help you get seen faster β€” by the right people.

πŸš€

Auto-Apply

We apply for you β€” automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

✨

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.