Posted on: 15/04/2026
Description :
Job Description : Security Researcher (Application Security & SAST)
Core Responsibilities :
- Manual Source Code Review : Perform deep-dive security audits of complex in any programming like Python /Java/JavaScript/C# applications, focusing on logic flaws, injection vulnerabilities, and broken access controls.
- SAST Engineering : Customize and extend SAST tools. You will write and maintain custom CodeQL or Semgrep rules to eliminate entire classes of vulnerabilities.
- Vulnerability Research : Stay ahead of the curve by researching 0-day vulnerabilities in third-party Programming libraries or frameworks.
- Remediation Guidance : Partner with Engineering teams to provide high-quality fix recommendations, ensuring security is baked into the SDLC.
Technical Requirements :
Experience :
- 4+ years in Application Security or Security Research.
- Language Mastery : Good experience in any programming language like Python, Java, C#, JavaScript. You should be able to read and understand complex asynchronous code and decorate patterns.
- Tooling : Hands-on experience with enterprise SAST tools (e.g., Checkmarx, Fortify, Snyk) and a strong preference for CodeQL or Semgrep.
- Security Logic : Proven ability to track "Tainted Data" from entry points (API endpoints) to dangerous sinks (OS commands, DB queries).
- Vulnerability Knowledge : Deep understanding of OWASP Top 10 and CWE, specifically how they manifest in Programming environment.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1628593