Endor Labs is looking to strengthen its software supply chain security by identifying and analyzing zero-day vulnerabilities in software artifacts and CI/CD systems.
Requirements
- Deep expertise in reverse engineering, exploit development, and software vulnerability analysis.
- Strong understanding of software supply chain security, including package management systems, CI/CD pipelines, and dependency analysis.
- Experience discovering and responsibly disclosing zero-day vulnerabilities.
- Proficiency in programming languages such as Python, Rust, or Go.
- Strong analytical skills and the ability to conduct complex security research autonomously.
- Experience with Bazel Monorepos is a plus.
- Experience with C++ is a plus.
Responsibilities
- Conduct offensive security research on software supply chain threats, identifying and analyzing zero-day vulnerabilities.
- Develop and refine exploit techniques to understand modern attack vectors targeting software supply chain through malicious code, 3rd party libraries, and CI/CD systems.
- Work closely with Product Management to translate research findings into innovative security capabilities within Endor Labs' products.
- Collaborate with security engineers and developers to prototype and implement detection and mitigation strategies for emerging threats.
- Contribute to the security community by developing open-source tools, methodologies, or frameworks that enhance software supply chain security.
- Stay ahead of the latest threats, attacker methodologies, and evolving security trends to continuously refine our research efforts.
- Publish research findings through technical blogs, white papers, and industry-leading security conferences.
Other
- 5+ years of experience in security research, vulnerability discovery, and offensive security.
- Proven track record of publishing high-quality research or presenting at top security conferences (e.g., Black Hat, DEF CON, RSAC, BSides).
- Excellent communication skills, both written and verbal, to convey technical concepts to diverse audiences.
- A culture that values innovation, collaboration, and continuous learning.
- Competitive compensation, flexible work environment, and a generous benefits package.