CO

Senior Security Researcher

COMMIT

ДистанційноunknownPosted Aug 17, 2026
Posting intelligenceActively listed

Skills

cicd

About the role

The company is the pioneer of Active ASPM, purpose-built to secure the modern software supply chain in the age of AI. While traditional tools overwhelm teams with endless alerts, company cuts through the noise to identify the critical 5% of risks - those that are truly reachable and exploitable. From GenAI-generated code to cloud runtime, the company gives developers and security teams the visibility and automation needed to ship secure software, faster.

We're looking for a highly skilled, driven Security Researcher to join our research group to analyze supply chain attacks, dissect malware, and build open-source tools. This is a high-impact role: you'll work with cross-functional teams to scan and protect users and organizations worldwide from the hottest cyber threats, playing a key part in shaping the future of company.

Requirements:

Must-Have Skills:

5+ years of experience as a Cybersecurity Researcher (supply-chain attacks, malware analysis)

Familiarity with open-source registry ecosystems (npm, PyPI, Maven) and their respective attack surfaces

Proven ability to ship software in a production environment

Strong understanding of the SDLC and modern CI/CD pipelines

Comfortable leveraging AI tools to optimize research and development processes

Proactive and independent mindset, with the ability to take full ownership of projects

Nice to Have:

Active contributions to open-source security tools or research projects

Hands-on experience with decompilers, debuggers, and network traffic analysis

Advanced malware analysis experience (obfuscation, encryption, anti-analysis, and sandbox-evasion techniques)

Web application penetration testing experience

Published CVEs, coordinated disclosures, writeups, blogs, or research papers

Experience public speaking at major industry conferences (e.g., Black Hat, DEFCON, RSAC)

A genuine passion for cybersecurity, open-source communities, and solving complex ecosystem threats

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on COMMIT's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation varies by seniority, employer size, and location. When this listing publishes a salary band you'll see it in the badge row above the description.

You never touch the form - the application is filled and submitted for you on COMMIT's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.