
Sr Security Researcher
Endor Labs6 months ago
Bengaluru, IndiaSenior
Responsibilities
- Discover and evaluate vulnerabilities in first- and third-party software components, with a focus on application security.
- Detect zero-day vulnerabilities in open-source projects and develop exploit code and proofs of concept for known vulnerabilities.
- Evaluate and compare security tools, detect malicious open-source components, and configure and operate SAST or DAST tools.
- Oversee and potentially extend the vulnerability database and ingestion process to ensure accurate, timely advisories.
- Present novel research at security conferences and contribute to blogs, technical reports, and whitepapers.
Requirements
- Bachelor’s degree in engineering and at least 5 years of application security experience.
- Programming experience with Go, Java, JavaScript, and Python.
- Understanding of software weaknesses and vulnerabilities.
- Experience configuring and operating security tooling such as SCA and SAST.
- Understanding of industry standards including CVE and EPSS.
- Experience developing security tools or SAST rules is preferred.
- Knowledge of software supply chains and their attack surface is preferred.
- Publicly reported zero-day vulnerabilities are preferred.
- Experience in malware detection and analysis is preferred.
- Security certifications such as OSCP or CEH are preferred.
Tech Stack
Categories
About Endor Labs
Endor Labs builds an application security platform that maps code and dependencies to prioritize and remediate risks across the SDLC for AppSec and engineering teams. It supports SCA, SAST, container scanning, and software supply chain controls, including code produced by humans or AI. Founded in 2021 and headquartered in Palo Alto, it is privately held and sells to enterprises through multi-stakeholder security and engineering buyers.