resu·mail

Sr Security Researcher

at Endor Labs

Bangalore, India Senior Posted 2024-05-15

Don't apply into the void — reach the hiring manager

ResuMail finds the recruiters and hiring managers behind this Sr Security Researcher role at Endor Labs, drafts a personalised outreach email, and schedules the send — so your application actually gets seen.

Reach the hiring manager ›

About this role

<h2><strong>Who we are</strong></h2> <p>Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder &amp; CEO here:&nbsp;<a href="https://www.youtube.com/watch?v=B0wmZBcPkFE">https://www.youtube.com/watch?v=B0wmZBcPkFE</a></p> <p>Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.</p> <p>The company was founded by&nbsp;<a href="https://www.linkedin.com/in/vbadhwar/">Varun Badhwar</a>&nbsp;and&nbsp;<a href="https://www.linkedin.com/in/stiliadis/">Dimitri Stiliadis</a>, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.</p> <h2><strong>What you’ll do</strong></h2> <ul> <li style="font-weight: 400;">The primary tasks of this position relate to the broad field of software vulnerability research, i.e. the discovery and evaluation of security vulnerabilities in first- and third-party software components. The focus clearly lies on application security, in contrast to network security, cryptography or other security fields.</li> <li style="font-weight: 400;">The tasks comprise, for example, the detection of 0-day vulnerabilities in open source projects, the development of exploit code and PoCs for known vulnerabilities, the evaluation and comparison of security tools, the detection of malicious open source components, or the development, configuration and use of SAST or DAST tools.</li> <li style="font-weight: 400;">One specifically important task includes the oversight (and possible extension) of Endor Labs’ vulnerability database and ingestion process, to ensure the timely production of accurate advisories by our third-party suppliers, and their ingestion by our cloud platform.</li> <li style="font-weight: 400;">All those tasks include the opportunity to present novel research at security conferences or other events, and – more generally – participate in dissemination and communication efforts, e.g. through the writing of blog posts or technical reports/whitepapers.</li> </ul> <h2><strong>What </strong><strong>we're looking for&nbsp;</strong></h2> <ul> <li>Bachelor's degree in engineering with at least 5 years of experience in application security</li> <li>Programming experience (Go, Java, JS, Python)</li> <li>Understanding of software weaknesses and vulnerabilities</li> <li>Experience in configuring and operating security tooling (SCA, SAST, etc.)</li> <li>Understanding of industry standards in the field (CVE, EPSS, etc.)</li> </ul> <h2><strong>Nice to have</strong></h2> <ul> <li>Experience in developing own security tools or SAST rules</li> <li>Understanding of software supply chains and their attack surface</li> <li>Publicly reported 0-day vulnerabilities</li> <li>Experience in malware detection and analysis</li> <li>Security certification like OffSec Certified Professional (OSCP) or Certified Ethical Hacker (CEH)</li> </ul> <h2><strong>At Endor Labs, we:</strong></h2> <ul> <li style="font-weight: 400;">Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.</li> <li style="font-weight: 400;">Engage in first principles thinking to debate ideas, test assumptions, and make decisions.</li> <li style="font-weight: 400;">Put data above opinions, seeking truth and clarity in all our endeavors.</li> <li style="font-weight: 400;">Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.</li> <li style="font-weight: 400;">Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.</li> </ul> <p>&nbsp;</p>

How to get this job at Endor Labs

  1. Don't rely on the portal. Cold applications for a role like Sr Security Researcher land in a pile of hundreds. A direct, personalised message to the hiring manager or a referrer is the fastest way in.
  2. Find the right person. ResuMail surfaces the actual recruiters and hiring managers at Endor Labs — not a generic careers inbox.
  3. Send tailored outreach. ResuMail drafts an email personalised to your resume and this role, then paces and schedules sends so you stay out of spam.
  4. Follow up. One polite nudge after 5–7 days roughly doubles reply rates — scheduled for you.

Reach Endor Labs's hiring managers today.

Free to start. No credit card. Built for Indian job seekers.

Start free with ResuMail ›