Security researcher
San Francisco, CA, United States
Wallarm Inc. Wallarm automates real-time application protection and security testing for APIs, apps, and microservices and APIs across multi-cloud and K8s environments. View company page
We are a global remote-first team of 100+ people on 4 continents and in 10+ countries.
We have been protecting our clients since 2014.
The company has raised over $10M in investments.
More than 200 customers around the world, including Fortune 500, Nasdaq, and high-growth startups choose Wallarm to protect their API and web applications.
The company passed Y Combinator, the most prestigious incubator in Silicon Valley, from which Dropbox, Stripe, Docker, etc. came out.
Our product:
Wallarm API security solutions provide proven performance to support innovative companies serving millions of users and billions of API requests per month. Hundreds of Security and DevOps teams globally use Wallarm daily to:
Discover . See every asset across your entire attack surface—from cloud environments to every API endpoint with auto-discovery capabilities.
Protect . A single suite that goes beyond OWASP Top 10 for full coverage for API specific threats, account takeover, malicious bots, L7 DDoS, and more.
Respond . Streamline incident response with complete visibility, smart triggers, and active threat verification.
Test . Automate security testing of your APIs and web assets. Prioritize remediation for every asset, in every environment.
In this role you will:
Improve detection capabilities of Wallarm WAF/WAAP products;
Analyze and research new vulnerabilities, WEB/API attack techniques and reproduce them;
Develop new detection mechanisms, rules and attack attribution filters;
Continuously evaluate (manually and automated) the product’s posture;
Identify detecting gaps in WAAP products;
Research new methods and techniques for identifying API threats (API vulnerabilities, API leaks, etc.);
Generate and push ideas for improving the product;
Occasionally triage security events and investigate security incidents;
Support and improve the infrastructure and processes of the team.
Requirements In this role you’ll need:
Solid understanding of web protocol stack (TCP, HTTP, TLS), HTTP request/response structure, HTTP headers, and web server principles;
Experience in web application security assessment;
Deep knowledge of all types of attacks on web applications (CWE, OWASP Top 10, OWASP API Top 10);
Experience with Linux, Docker containers, and version control systems (GIT);
Proficient in one of the programming languages (e.g. Python/Ruby);
Analytical mindset;
Nice to have:
Practical offensive security certifications (BSCP, OSCP, OSWE, ASCP, etc.);
Participation experience in bug bounty, CTFs;
Experience and skills in bypassing Web Application firewalls;
Professional publications and/or speaker experience at specialized conferences;
Experience and/or desire to write security blog posts.
What we offer:
Ability to work on a product that makes the Internet safer;
Completely remote work and flexible working hours;
Professional development and career growth.
Explore more InfoSec / Cybersecurity career opportunities Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
#J-18808-Ljbffr