Integrity & Excellence
Web Security Researcher
Location
United States
Posted
16 hours ago
Salary
0
Seniority
Senior
Job Description
Web Security Researcher
Dataflow Security
• Help develop and carry out the Web team research strategy by conducting vulnerability research and exploit development on Web Applications. • Provide unbiased insights and ideas to the web research team. • Develop proof-of-concept code and exploits. • Remain on top of various developments related to Web Technologies such as security mitigations, new features, exploitation techniques, etc.
Job Requirements
- Track record of finding impactful server-side vulnerabilities (e.g. Auth Bypass, RCE, User to Admin PE) in Web Applications.
- An understanding of web protocols and web architectures.
- Ability to manually detect and exploit common web vulnerabilities.
- Ability to conduct long-term and widely scoped security research projects as part of a broader team effort.
- Stay up to date with emerging trends of web app security and research methods.
- Exploitation experience is a plus, but not required.
Benefits
- Highly competitive compensation package with an additional monetary bonus system based on exploitable vulnerability findings.
- Further your career by joining a team of established and experienced security researchers.
- Fully remote with flexible work schedule.
- We allow researchers, at their discretion, to spend up to 15% of their time conducting research on other topics.
- We offer a prime wellness program designed to promote a healthy lifestyle, which includes, but not limited to access to gyms around the world, health coaching, and more.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Help develop and carry out the Browser team research strategy by doing vulnerability research, reverse engineering and exploit development on Web Browsers. • Provide unbiased insights and ideas to the research team. • Develop proof-of-concept code and exploits to the quality standard of DFSEC. • Remain on top of various developments related to Web Browsers such as security mitigations, new features, etc.
Director of Security
Togal.AIThe AI-powered pre-construction takeoff software built BY estimators, FOR estimators
• Own Togal's SOC 2 Type II program end-to-end — evidence collection, audit management, and control ownership in Vanta — so it's audit-ready year-round, not just before an audit. • Turn around customer security questionnaires and vendor security reviews quickly and accurately. • Be Togal's front-line security contact for customers and prospects, including calls with customer-side CISOs and security teams during deal cycles and MSA negotiations. • Design a written incident-response and notification policy — clear triggers, timelines, escalation paths, and roles — that's actually followed, replacing today's ad hoc handling by the CTO and CEO. • Lead incident response when something does happen: containment, investigation, and coordinating any outside help needed (e.g., an MDR/IR retainer for surge capacity) — this is "own it when it happens," not the day-to-day center of the role. • Evaluate whether to buy, outsource, or build additional security monitoring — assess managed detection/SIEM options against what we actually need before committing engineering time to standing anything up ourselves. • Assess and tighten cloud security posture (IAM, configuration, logging) alongside the CTO and engineering team. • Partner with Legal and the CEO on breach determination and external communication, as a defined process rather than a one-off scramble.
• Perform vulnerability assessments on technology infrastructures; • Identify, prioritize and track vulnerabilities according to their risk level; • Manage remediation plans and follow up on security patches; • Participate in monitoring the security posture of technology environments; • Implement and maintain security dashboards and indicators; • Produce reports for various stakeholders; • Participate in automation activities related to vulnerability management; • Collaborate with operations, infrastructure and cybersecurity teams; • Conduct technology and security monitoring to stay up to date; • Contribute to the continuous improvement of security processes and practices.
• Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning. • Partner with client security, DLP, SOC, and data governance teams • Triage findings surfaced through data security tooling • Drive remediation actions to closure • Coordinate with the SOC and response teams during findings • Document remediation decisions and closure evidence • Provide technical input into the remediation roadmap



