Padmi

Lead Security Researcher

MumbaiPosted 3 months ago
Computer ResearchSeniorFull Time; Regular
Apply at RAPID7 LLC

Opens the source posting on shine.com

Source description

About the role

View original

As an experienced vulnerability researcher in Rapid7's Vulnerability Intelligence team, you will contribute to the team's overall goals of uncovering and prioritizing risks for organizations worldwide. You will work with a skilled group of technical and cross-team leaders who are highly collaborative and deeply embedded in the security community. Key Responsibilities: - Work with the broader Vulnerability Intelligence team to support day-to-day research operations, including coordinated vulnerability disclosures and rapid responses to major security incidents (Note: there is no on-call requirement for this role). - Perform and publish root cause analyses of high-priority vulnerabilities and potential threats that highlight Rapid7's attacker-focused approach to vulnerability intelligence. - Develop and publish new exploits and attack techniques, working alongside the Metasploit team to incorporate them into Metasploit Framework as needed. - Conduct zero-day vulnerability research against popular enterprise technologies (e.g., network appliances, VPN gateways, CI/CD servers, file transfer and backup solutions, etc). - Advise security and threat detection engineers as they develop vulnerability checks, fingerprints, and detections; contextualize risk and explain attack patterns to cross-team technical stakeholders. Qualifications Required: - Hands-on experience with common vulnerability classes and exploitation techniques (e.g., command injection, deserialization, etc). - Experience producing vulnerability root cause analyses or other technical writing on vulnerabilities and exploits. - Hands-on experience reverse engineering, patch diffing, and developing exploits. - Prior experience developing Metasploit modules is a plus. - Prior experience reverse engineering at least one common enterprise software development language (e.g. Java, .NET, C/C++) is also a plus. - Familiarity with common security research tooling (e.g., IDA, Ghidra, Binary Ninja, Burpsuite, etc). - An instinct for where and how to obtain or emulate vulnerable software. - Deep empathy for the challenges that security teams and global organizations face in today's threat climate; willingness to listen, mentor, and collaborate across teams. Rapid7's vision is to create a secure digital world for customers, the industry, and communities by harnessing collective expertise and passion to challenge what's possible and drive extraordinary impact. The company values new ideas and is committed to building a dynamic and collaborative workplace where diverse backgrounds and professional experiences are embraced. If you are excited about contributing to a secure digital world and believe your experience can make an impact, Rapid7 encourages you to apply for this role. As an experienced vulnerability researcher in Rapid7's Vulnerability Intelligence team, you will contribute to the team's overall goals of uncovering and prioritizing risks for organizations worldwide. You will work with a skilled group of technical and cross-team leaders who are highly collaborative and deeply embedded in the security community. Key Responsibilities: - Work with the broader Vulnerability Intelligence team to support day-to-day research operations, including coordinated vulnerability disclosures and rapid responses to major security incidents (Note: there is no on-call requirement for this role). - Perform and publish root cause analyses of high-priority vulnerabilities and potential threats that highlight Rapid7's attacker-focused approach to vulnerability intelligence. - Develop and publish new exploits and attack techniques, working alongside the Metasploit team to incorporate them into Metasploit Framework as needed. - Conduct zero-day vulnerability research against popular enterprise technologies (e.g., network appliances, VPN gateways, CI/CD servers, file transfer and backup solutions, etc). - Advise security and threat detection engineers as they develop vulnerability checks, fingerprints, and detections; contextualize risk and explain attack patterns to cross-team technical stakeholders. Qualifications Required: - Hands-on experience with common vulnerability classes and exploitation techniques (e.g., command injection, deserialization, etc). - Experience producing vulnerability root cause analyses or other technical writing on vulnerabilities and exploits. - Hands-on experience reverse engineering, patch diffing, and developing exploits. - Prior experience developing Metasploit modules is a plus. - Prior experience reverse engineering at least one common enterprise software development language (e.g. Java, .NET, C/C++) is also a plus. - Familiarity with common security research tooling (e.g., IDA, Ghidra, Binary Ninja, Burpsuite, etc). - An instinct for where and how to obtain or emulate vulnerable software. - Deep empathy for the challenges that security teams and global organizations face in today's threat climate; willingness to listen, mento

One address, no account. We’ll tell you when matching roles go live.

More at RAPID7 LLC

Related open roles

View all roles