Senior Security Researcher

Senior Security Researcher

Full-Time 70000 - 90000 € / year (est.) No home office possible
D

At a Glance

  • Tasks: Lead the detection pipeline for software supply chain security and combat malicious packages.
  • Company: Join Devtech, a digital innovation leader empowering businesses globally.
  • Benefits: Enjoy private health insurance, 25 days vacation, and flexible work options.
  • Other info: Collaborative environment with opportunities for professional growth and development.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
  • Qualifications: Proven track record in vulnerability detection and strong programming skills required.

The predicted salary is between 70000 - 90000 € per year.

About Us

Devtech provides digital innovation services that help Fortune 1000 and emerging companies transform, scale and disrupt. We partner with our clients to envision and develop next-gen digital and cloud solutions that drive impactful business outcomes through people and technology. Our mission is to empower every innovative business in the world to do what they do best, even better. Founded in 2012, Devtech successfully bootstrapped the business for many years before securing institutional growth capital in 2022 and 2024 to fuel our next stages of growth. We are a team of over 300 professionals across Europe and North America, and our continued growth is a testament to the quality of work our teams produce. At Devtech, we’re fostering an environment of autonomy, mastery, and purpose, where our team members can grow and thrive. As we continue to scale globally, we're excited to welcome new team members who share our curiosity and growth mindset, and are ready to make an impact!

What You Will Do

We're building a platform in the software supply chain security space. Our mission is to catch malicious packages, compromised CI/CD pipelines, and supply chain attacks before they reach our customers' production systems, servers, or developer desktops. We're looking for a Senior Security Researcher to own the detection pipeline end-to-end, which includes the systems that ingest packages, surface malicious findings, identify suspicious behavior, triage findings, and publish the research that both protects our customers and establishes our voice in the community. This is a hands‑on role. You'll be designing detection pipelines, reviewing flagged packages, writing code, hunting threats, disclosing vulnerabilities, and publishing your work.

  • Design the systems that scan open-source packages (npm, PyPI, RubyGems, Maven, crates.io, Go modules, GitHub Actions, container images, and more) for malicious behavior at scale
  • Tune signals, reduce false positives, and add new detection techniques as attackers evolve
  • Actively find novel malicious packages, typosquats, dependency confusion attempts, compromised maintainers, and CI/CD abuse patterns
  • Coordinate with maintainers, foundations, and registries, file CVEs, work with GitHub Security Advisories, the OSV schema, and platform security teams
  • Turn every significant finding into a blog post that's fast, clear, and technically rigorous that gets shared in security newsletters and lands on places like Hacker News
  • Build internal tooling that uses static analysis and AI models to triage findings, summarize package diffs, and cluster related campaigns
  • Your findings feed directly into what we build. Expect to sit in on roadmap discussions and push back when detection logic in the product doesn't match what you see in the wild
  • Stay up-to-date with the latest sandbox evasion and detection measures and create countermeasures and red‑teaming exercises
  • Keeping a tight line between false positives and false negatives in our detection pipeline to ensure a well‑curated and trusted set of threat intelligence

What you will need

  • A track record of finding real vulnerabilities - published CVEs, GHSAs, or equivalent advisories with your name on them
  • Deep familiarity with multiple vulnerability classes like malicious packages, RCE, prototype pollution, deserialization, SSRF, auth bypasses, CI/CD‑specific attack paths and memory corruption
  • Experience designing and operating a detection, scanning, or analysis pipeline at scale that run continuously and produce signal
  • Strong programming skills in at least one of TypeScript, Python, Go, or Rust
  • Comfortable reading code in languages you don't write daily (JavaScript, Ruby, Java, PHP, etc)
  • Proven ability to write a good blog post fast
  • Hands‑on use of LLMs as a research tool
  • Understanding of LLMs to know where they break, which prompts and models work best, and when to reach for a model vs. when not to
  • Prior work on software supply chain attacks
  • Contributions to OpenSSF, OSV, Sigstore, SLSA, or adjacent projects are a plus
  • Reverse engineering chops - obfuscated JavaScript droppers, packed binaries, malicious post‑install scripts are a plus
  • A conference talk or two (DEF CON, Black Hat, BSides, OffensiveCon, Kaspersky SAS) is a plus
  • Experience with eBPF, sandboxing, or dynamic analysis infrastructure is a plus

What we offer

  • Private health insurance
  • 25 days of vacation / PTO
  • 7 days of sick leave at 100% pay
  • Outstanding referral bonuses
  • Paternity leave – 15 days for new dads
  • Reduced working hours for the first month after returning from maternity
  • Development program (training & conferences, internal knowledge sharing)
  • Flexible work environment

Senior Security Researcher employer: Devtech

At Devtech, we pride ourselves on being an exceptional employer that champions innovation and professional growth. Our collaborative work culture fosters autonomy and mastery, allowing team members to thrive while tackling cutting-edge challenges in software supply chain security. With a commitment to employee well-being, we offer generous benefits including private health insurance, ample vacation time, and a flexible work environment, making Devtech an ideal place for those looking to make a meaningful impact in their careers.

D

Contact Detail:

Devtech Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Researcher

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at Devtech. A friendly chat can sometimes lead to opportunities that aren’t even advertised!

Tip Number 2

Show off your skills! If you’ve got a portfolio or GitHub repo, make sure it’s up to date. Share your projects related to security research and detection pipelines. This is your chance to shine and demonstrate what you can bring to the table.

Tip Number 3

Prepare for the interview by diving deep into Devtech’s mission and recent projects. Be ready to discuss how your experience aligns with their goals, especially in software supply chain security. Tailor your answers to show you’re the perfect fit!

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining the Devtech team. Let’s get you on board!

We think you need these skills to ace Senior Security Researcher

Vulnerability Detection
Malicious Package Identification
CI/CD Pipeline Security
Threat Hunting
Programming in TypeScript, Python, Go, or Rust
Static Analysis
AI Model Utilisation

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Senior Security Researcher role. Highlight your experience with vulnerability detection and any relevant projects you've worked on that align with our mission at Devtech.

Show Off Your Skills:Don’t hold back on showcasing your programming skills! Whether it’s TypeScript, Python, or Rust, let us know how you’ve used these languages in real-world scenarios, especially in building detection pipelines or analysing vulnerabilities.

Be Clear and Concise:When writing your application, keep it straightforward. We appreciate clarity, so make sure your points are easy to understand. If you can write a good blog post, you can definitely write a compelling application!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at Devtech

Know Your Stuff

Make sure you brush up on your knowledge of vulnerability classes and detection pipelines. Be ready to discuss your past experiences with finding vulnerabilities and how you've contributed to the security community. Having specific examples, like published CVEs or blog posts, will really help you stand out.

Show Off Your Coding Skills

Since this role requires strong programming skills, be prepared to demonstrate your coding abilities. You might be asked to solve a problem on the spot or discuss your approach to writing secure code. Practising coding challenges in languages like TypeScript, Python, or Go can give you an edge.

Stay Current with Trends

The security landscape is always changing, so it's crucial to stay updated on the latest threats and detection techniques. Bring up recent trends or news in the software supply chain security space during your interview to show that you're engaged and knowledgeable about the field.

Communicate Clearly

You'll need to write clear and concise blog posts about your findings, so practice explaining complex concepts in simple terms. During the interview, focus on articulating your thoughts clearly and confidently. This will demonstrate your ability to communicate effectively with both technical and non-technical audiences.