Senior Security Researcher

Snyk Snyk · Enterprise · Lisbon, Portugal

This role focuses on developing and improving Snyk's vulnerability scanner for AI software development, aiming to reduce false positives and enhance detection capabilities for web and API attack surfaces. It involves working with Java, understanding web/API security, and integrating AI systems.

What you'd actually do

  1. Develop Snyk API & Web’s vulnerability scanner, adding new features and supporting existing ones
  2. Reasearch develop and improve the scanner vulnerability detection capabilities, while keeping our 0.08% false-positive rate amazingly low
  3. Contribute to our firing range by adding new vulnerable applications and endpoints for testing purposes
  4. Work with the engineering team to discuss and implement technical solutions, fix and identify bugs
  5. Mentor and coach more junior engineers on the team, regularly reviewing and testing teammates' code

Skills

Required

  • Proficiency in Java
  • Good understanding of how web applications and APIs work, down to the HTTP layer
  • Familiarity with high-level vulnerability classes, such as those enumerated in the OWASP Top 10
  • A strong desire to keep up to date with new research and technologies from across the industry, and the ability to bring new ideas into the team
  • Basic usage and knowledge of AI systems, such as chatbots and code editor extensions

Nice to have

  • ideas for novel and impactful security research targets and areas
  • A basic understanding of popular infrastructure components, such as Docker, or AWS
  • You are comfortable with the programming languages Python or Go, or have a willingness to learn

What the JD emphasized

  • award-winning team
  • enterprise needs
  • 0.08% false-positive rate