layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Invicti Security
Austin, TX, US
Source: Invicti Security careers · View original posting
From Invicti Security's posting. “We” and “our” refer to the employer.
Delivering the industry’s most accurate application security platform, Invicti Security has been transforming the way web applications are secured for nearly 20 years. Recognized as a leader in Application Security Testing and a DAST Innovator by Latio, Invicti enables organizations to continuously scan and secure their web apps and APIs with the rigor of runtime testing and the speed of constant innovation. Headquartered in Austin, Texas, Invicti serves more than 3,600 organizations worldwide.
Invicti serves more than 3,600 organizations worldwide. To learn more, visit Invicti.com or follow us on LinkedIn.
You are a hands-on offensive security researcher who enjoys turning vulnerability and malware knowledge into detection content that ships. You take ownership of the security checks you build, write clean and accurate detection rules, and care deeply about quality and low false-positive rates. You have strong opinions that are loosely held, apply established research principles in your day-to-day work, and help ensure our security checks deliver solid results for our customer base.
8+ years of offensive security or application security research experience (Bachelor's + 5 years, or Master's + 3 years).
Broad knowledge of programming languages — JavaScript is a must, Python is a huge plus.
Strong understanding of security principles, standards, and best practices.
Deep understanding of vulnerability classifications, exploitation methodologies, and secure software development practices.
Complete knowledge and full understanding of detection writing for DAST scanners, fuzzers, or comparable systems — including detection logic, response interpretation, and false-positive management.
Experience designing testing frameworks, evaluation harnesses, or large-scale validation systems for security tooling.
Deep web application pentesting experience covering the OWASP Top 10 and adjacent classes — authentication, authorization, business logic, modern API surfaces (REST, GraphQL).
Comfortable researching and tackling hard problems and algorithms (e.g., parsing with ASTs).
Fluency with offensive tooling (Burp Suite, sqlmap, nmap, ffuf, custom payload generation) and the underlying HTTP/web protocol fundamentals.
Experience with cloud platforms, Kubernetes, containers, infrastructure-as-code, and CI/CD security is highly desirable.
Practical experience researching or securing LLM-powered applications, AI agents, or AI-assisted development workflows, including prompt injection, model abuse, tool invocation risks, MCP security, and emerging AI attack techniques.
Fluent in English, with strong written and verbal communication skills and the ability to convey technical details to both technical and non-technical audiences.
Ability to collaborate effectively across multi-disciplinary teams and exercise judgment on when to escalate issues.
A hands-on attitude, intellectual curiosity, and willingness to research across traditional application security, cloud-native security, and the rapidly evolving AI ecosystem, including LLM vulnerabilities, agent security, and MCP security.
OpenGrep (or Semgrep) experience.
Static analysis experience.
Experience building production-ready systems.
Public security research output (CVEs, advisories, talks, open-source tools).
YARA experience.
Health Insurance: Taking care of our team goes beyond the office. We cover 100% of employee health care, vision and dental premium costs. For dependents, we contribute 75% of the health care and 50% vision/dental premium cost, so you can be sure that you and your family are in the best possible health. Coverage is effective your first day.
Employee Assistance Program: Emotional Support Counseling services - 24/7 Life Coaching, Dependent Care, Elder Care, Financial & Legal Support, Wellness Coaching, New Parent Support and more
Parental Leave16 week paid leave for birthing parent recovery. 4 week paid leave for non-birthing/bonding parent
401(k) Savings Plan: 50% up to 6% company match with 100% annual cliff vesting
Paid Birthday Off: Take your birthday off to celebrate you!
Employee Recognition: Ongoing recognition & rewards. A Culture that emphasizes personal and professional growth
At Invicti, we believe our people are at the core of our success. Our Total Rewards approach is designed to attract, support, and grow exceptional talent by offering a balanced mix of competitive compensation, meaningful benefits, and opportunities for recognition and development. We take a global, flexible approach that aligns with our business goals and values while adapting to regional needs. Above all, we are committed to transparency and ensuring our employees understand how we invest in their success and well-being.
As we operate in a dynamic, fast-paced industry, this role evolves with the business. While core responsibilities are outlined above, duties may adapt over time to meet operational needs and support both team success and your professional growth
"At Invicti, we embrace diversity and individuality in all forms. Discrimination has no place here - regardless of race, religion, gender, age, ability, sexual orientation, or any other aspect that makes you unique. We're all about creating a space where everyone feels valued and included. So come as you are and join us in shaping the future of our industry."
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: