This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Endor Labs is building the Application Security platform for the software development revolution. Modern software is complex and dependency-rich, making it increasingly difficult to pinpoint the risks that truly matter. This role involves leading offensive security research efforts in software supply chain security, identifying vulnerabilities, analyzing attack trends, and influencing security capabilities. Ideal for professionals with deep expertise in application security, vulnerability research, reverse engineering, and offensive techniques.
Job Responsibility:
Conduct offensive security research on software supply chain threats, identifying and analyzing zero-day vulnerabilities
develop and refine exploit techniques to understand modern attack vectors targeting software supply chain through malicious code, 3rd party libraries, and CI/CD systems
work closely with Product Management to translate research findings into innovative security capabilities within Endor Labs' products
publish research findings through technical blogs, white papers, and industry-leading security conferences
collaborate with security engineers and developers to prototype and implement detection and mitigation strategies for emerging threats
contribute to the security community by developing open-source tools, methodologies, or frameworks that enhance software supply chain security
stay ahead of the latest threats, attacker methodologies, and evolving security trends to continuously refine our research efforts.
Requirements:
5+ years of experience in security research, vulnerability discovery, and offensive security
deep expertise in reverse engineering, exploit development, and software vulnerability analysis
strong understanding of software supply chain security, including package management systems, CI/CD pipelines, and dependency analysis
experience discovering and responsibly disclosing zero-day vulnerabilities
proven track record of publishing high-quality research or presenting at top security conferences (e.g., Black Hat, DEF CON, RSAC, BSides)
proficiency in programming languages such as Python, Rust, or Go
strong analytical skills and the ability to conduct complex security research autonomously
excellent communication skills, both written and verbal, to convey technical concepts to diverse audiences.
What we offer:
Work with a world-class team dedicated to pushing the boundaries of security research
directly influence the security of modern software supply chains
a culture that values innovation, collaboration, and continuous learning
competitive compensation, flexible work environment, and a generous benefits package
opportunity to present groundbreaking research and contribute to the global security community.
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.