This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Team Cortex Platform - Cortex is the industry's only open and integrated, AI-based, continuous security platform. Cortex is a significant evolution of the Application Framework designed to simplify security operations and considerably improve outcomes. Deployed on a global, scalable public cloud platform, Cortex allows security operations teams to speed the analysis of massive data sets. Join the elite Vulnerability Assessment Research team within Cortex Exposure Management and be at the forefront of cybersecurity! You'll be instrumental in groundbreaking research into vulnerabilities and exposures, engineering cutting-edge exploits and robust vulnerability tests, and building and maintaining the essential, high-impact tooling that powers our team. This is your chance to directly shape the future of exposure management. This capability serves as the cyber knowledge backbone of the exposure management product, and is crucial for customers to prioritize and fix critical vulnerabilities using the XSIAM platform.
Job Responsibility:
Develop and maintain a comprehensive, industry-leading repository of vulnerability content to enhance detection and mitigation strategies
Shape and drive the tactical response to zero-day and critical vulnerabilities across all attack surfaces, ensuring rapid containment and mitigation
Conduct research and testing, enhance automation processes, and ensure a smooth workflow for identifying, validating and mitigating security risks
Analyze existing solutions, identify barriers to quality, recommend changes, then implement
Take part in architecture strategy sessions
design solutions that accommodate the requirements of the various groups across Cortex
Collaborate with teams to solve problems, reduce technical debt, and evolve development practices. Drive technical best practices and evangelize new technologies within the engineering organization
Mentor other researchers and ensure that your team delivers high-quality output
Take ownership of projects, drive them to completion, and support them in production
Requirements:
5+ years of experience in vulnerability management, offensive security or security research
Experience contributing to public vulnerability research, submitting CVEs or creating proof-of-concept exploits
Strong understanding of TCP/IP and networking protocols (eg. HTTP, FTP, SSH, SNMP)
Familiarity with common open source security software such as Nuclei, OpenVAS, and Nmap
Knowledge of cybersecurity frameworks and vulnerability methodologies
Familiarity with current penetration and security assessment tools such as Metasploit, Nmap, Burp Suite, Wireshark, etc.
Proficient in Python. Familiar with, or eager to learn Java, Golang, C/C++ or RUST
Deep understanding of Windows, Linux, macOS and Unix-based systems
Able to switch between research, design, prototype, and implementation
Cybersecurity knowledge demonstrated with base level certifications (eg. OSCP, GPEN, or Pentest+) or willingness to obtain
Nice to have:
Familiarity with patch management processes and tools (eg.WSUS or SCCM) knowing how vulnerabilities are remediated
Familiarity with enterprise/cloud deployed embedded systems
Experience using cloud managed services (ideally in GCP)
Knowledge of network architectures
understands subnetting and routing and how VLANs work and affect network scanning
Are familiar with distributed data stores, such as BigQuery and BigTable, as well as relational databases such as PostgreSQL and MySQL
Experience working in security operations centers (SOC), red/blue teams or as a security analyst