Application Security Research Engineer
CommIT
Toulouse, France
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Artificial Intelligence
Software System Penetration Testing
Architectural Patterns
Burp Suite
Software as a Service
Cloud Computing
Cloud Engineering
Fuzz Testing
Systems Integration
Software Security
Kubernetes
+5 more
Metasploit
Free and Open-Source Software
Software Coding
Vulnerability Analysis
Microservices
Job description
Company is seeking an Application Security Research Engineer. In this role, you will lead a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of company products and help scale secure-by-design principles. This is a hands-on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.
What You will Do:
- Build and lead a team of security researchers and penetration testers.
- Help to reshape company Product Security
- Plan and execute advanced penetration testing campaigns.
- Develop tools and frameworks for scalable security testing and fuzzing.
- Lead Security innovation by building and managing penetration testing tools \ AI Agents
- Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
- Identify systemic product weaknesses and help define long-term mitigations.
- Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
- Contribute to security research publications, CVE submissions, and industry knowledge sharing.
- Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.
Requirements:
- Proven 2 years of experience in leading application security research Teams (SAAS or software company).
- 7 year experience in Research and penetration testing.
- Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.
- AI and LLM Penetration testing knowldge and Experience
- Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.
- Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
- Familiarity with secure software architecture and typical attack vectors.
- Demonstrated ability to lead security testing engagements and report technical findings effectively.
- Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
- Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines,
- Publications or open-source contributions in the security domain are a plus.
Requirements
Etudes/recherche, Security
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on fr.engineering.jobsGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
CH
Chris Heilmann
Dev Digest 131 - AI'm not sure about OSS
almost 2 years ago
LM
Luis Minvielle
The 8 Best Code Testing Tools
over 2 years ago
CH
Chris Heilmann
Dev Digest 120 - Apple and peers
about 2 years ago
LM
Luis Minvielle
The 12 Best Jobs for Software Engineers
over 2 years ago