Back to jobs

Security Researcher

London

Every day, the world gets more digital thanks to tens of millions of developers building the future faster than ever. But with exponential growth comes exponential risk, as outnumbered security teams struggle to secure mountains of code. This is where Snyk (pronounced “sneak”) comes in. Snyk is a developer security platform that makes it easy for development teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and cloud infrastructure — and do it all right from the start. Snyk is on a mission to make the world a more secure place by empowering developers to develop fast and stay secure.

 

 

Joining Snyk means embracing our core values: One Team, Care Deeply, Customer Centric, and Forward Thinking. As a member of our team, you’ll have the opportunity to thrive in a dynamic environment where fostering collaboration, leading with empathy, driving business impact, and inspiring trust are at the heart of everything we do.

Our Opportunity

We’re looking for a Security Researcher to join Snyk’s Rules Intelligence team and take part in research-led work developing rules for the Snyk Code SAST engine. We regularly look at new and emerging languages, technologies and frameworks to better model threats and vulnerabilities in source code, helping developers identify potential security vulnerabilities before their code reaches production. 

You’ll Spend Your Time:

  • Writing security rules to detect known and unknown vulnerabilities using a proprietary language and built-for-purpose tooling. 
  • Working closely with our Program Analysis and Machine Learning teams to shape our engine capabilities.
  • Learning the mechanics of a programming language or a framework, including looking at best practices and common vulnerable patterns.
  • Working with customers, understanding their pain points and challenges, and helping secure the world’s largest companies.
  • Helping shape our product roadmap and driving innovation and guidance to the business with regards to up-and-coming security risks.
  • Taking part in research endeavors (where applicable), contributing back to the security community and publishing written papers, i.e: https://snyk.io/blog/finding-yaml-injection-with-snyk-code/, https://snyk.io/blog/the-dangers-of-setattr-avoiding-mass-assignment/

What You’ll Need:

  • Demonstrated experience and knowledge of Application Security Vulnerabilities.
  • Proficiency with Python and/or Javascript, as well as some familiarity with OOP languages such as Java or C#.
  • Interest in learning about the mechanics and inner workings of a language or a framework, and the ability to self-study highly technical concepts.
  • A passion for cybersecurity, and a desire to contribute and be an active participant in the security community.

We’d be Lucky if You:

  • Are experienced working with, developing, or using AppSec tools.
  • Have experience programming or researching low-level languages and vulnerabilities.
  • Are an active participant in “community efforts”, such as CTFs, bug-bounty programs or similar.
  • Have experience researching and (responsibly) disclosing security vulnerabilities or any CVE/paper publications.

#LI-CR1

We care deeply about the warm, inclusive environment we’ve created and we value diversity – we welcome applications from those typically underrepresented in tech. If you like the sound of this role but are not totally sure whether you’re the right person, do apply anyway!

 

About Snyk

Snyk is committed to creating an inclusive and engaging environment where our employees can thrive as we rally behind our common mission to make the digital world a safer place. From Snyk employee resource groups, to global benefits that help our employees prioritize their health, wellness, financial security, and a work/life blend, we aim to support our employees along their entire journeys here at Snyk.

Benefits & Programs

Prioritize health, wellness, financial security, and life balance with programs tailored to your location and role.

  • Flexible working hours, work-from home allowances, in-office perks, and time off for learning and self development
  • Generous vacation and wellness time off, country-specific holidays, and 100% paid parental leave for all caregivers
  • Health benefits, employee assistance plans, and annual wellness allowance
  • Country-specific life insurance, disability benefits, and retirement/pension programs, plus mobile phone and education allowances

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Snyk is an equal-opportunities company and believes firmly in the power of creating a richly diverse workforce. To help us to achieve this, we'd like to invite you to voluntarily disclose your gender identity. We'll use this information anonymously to assess and improve our interview process.

Completion of this question is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter.

Select...

When you apply for a job at Snyk, Snyk Limited will be the controller for the personal data contained in your application. You can reach us at Snyk Limited, Highlands House, Basingstoke Road, Spencers Wood, Reading, Berkshire, RG7 1NT United Kingdom or contact our Data Protection Coordinator at privacy@snyk.io. We process your personal data to set up and conduct interviews and tests for applicants, evaluate and assess the results, and otherwise as needed in our recruitment and hiring processes. Your personal data was either obtained from publicly available sources (e.g. LinkedIn) or provided to Controller by someone who referred you for potential employment. This processing is necessary for our legitimate interests in finding, choosing and hiring employees and is  legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation). You can read more about how we process your data in the Snyk Recruitment Privacy Statement.

Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider who helps manage the recruitment and hiring process on our behalf. Greenhouse is based in the United States, and the transfer will be subject to the safeguards of Greenhouse's Privacy Shield certification. We keep your personal data as long as necessary to evaluate your application and in accordance with the Snyk Recruitment Privacy Statement. You have the right to request access to your personal data and to request that it be corrected, restricted, erased, or ported to a new provider under certain circumstances. In addition, you may lodge a complaint with an EU supervisory authority.

Select...
Tell us how you came across this opportunity: *