As the, you will lead a highly experienced team of researchers focused on web application security, threat intelligence, and detection development. You’ll play a dual role: providing hands-on technical direction in the analysis of web-based threats, and fostering a strong, collaborative team environment through effective leadership and mentorship. You’ll also work closely with cross-functional teams to ensure our WAF and security products are ahead of evolving threats.
Responsibilities:
Lead, mentor, and grow a team of expert security researchers.
Provide technical guidance and review in areas such as web exploitation, WAF evasion, and threat intelligence.
Oversee research into web frameworks, application servers, and modern attack vectors.
Manage the development and continuous refinement of attack signatures to defend against evolving threats.
Drive initiatives around Honeynet deployments, threat intelligence collection, and automated analysis tools.
Coordinate vulnerability replication and PoC development for both internal testing and product validation.
Build and maintain team infrastructure, tooling, and research pipelines.
Promote collaboration between research and development teams to enhance product defenses.
Represent the research team in strategic discussions, roadmap planning, and leadership forums.
Contribute to thought leadership via blogs, reports, and security conference presentations.
Qualifications:
At least 6 years of experience in web application security, with hands-on research or red-teaming background.
Proven experience managing or leading a technical security team, with strong interpersonal and mentoring skills.
Deep understanding of networking, HTTP protocol, web servers, and web application internals.
Extensive experience analyzing and reproducing web application vulnerabilities.
Practical knowledge of WAF evasion techniques and detection logic.
Expertise in creating and analyzing attack signatures (e.g., regex, SNORT-style rules).
Strong coding/scripting skills in Python, including building research and automation tools.
Familiarity with threat intelligence techniques and sources (e.g., forums, CVEs, blogs, honeynets).
Experience with security efficacy testing across WAFs, API protections, and other security products.
Advantage: background in malware analysis or malicious script behavior.
Advantage: knowledge of both front-end and back-end web development.
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.