Senior CyberSecurity Researcher, Paris Ajouter aux favoris

Paris 1er
About GitGuardian

GitGuardian is a global cybersecurity scale-up. The company is based in Paris, New-York City, Boston.

Among our early investors who saw our market value proposition, are the co-founder of GitHub, Scott Chacon, along with Solomon Hykes , Docker's co-founder. American and European top-tier VC firms have also invested in GitGuardian.

GitGuardian leads the way in Non-Human Identity security , offering end-to-end solutions from secrets detection in code, productivity tools and environments to strong remediation, observability and proactive prevention of leaks. Our solutions are already used by more than 600K developers worldwide!

About your team and your mission

We are seeking a highly skilled and motivated senior security researcher to join our team and focus on addressing security challenges related to secrets in the new world of agentic AI.

You'll join the cybersecurity research team. The team brings backgrounds from CISO roles, red teaming, penetration testing, development, and vulnerability research, with recent participation at major conferences such as Real World Crypto, SSTIC, Black Alps, Northsec and KubeCon.

Day-to-day, you will investigate novel and existing tactics to find and abuse exposed credentials, then publish your findings as authoritative research. This means analyzing ongoing threats and attacks, exploring new exploitation techniques, and documenting emerging tactics. You will also collaborate with our engineering teams to identify ways to improve our products in terms of secret validation and coverage.

This role requires cross-functional expertise, primarily in cybersecurity, as well as in software development and data analysis. You will collaborate closely with colleagues in the internal Security team and report to the cybersecurity research lead. You'll spend roughly 70% of your time on research and 30% producing content to share findings with the security community.

As a researcher, you will track offensive trends and techniques , and work closely with our marketing team to produce 2-3 technical deep-dive articles or talks per quarter. Recent publications can be found on our security research blog.

About you

If you think you match at least 70% of these criteria, please apply!

Here's what we consider essential for success in this role:
  • 5+ years of experience working in a security engineer role, with 2+ years dedicated to research-related work, or equivalent.
  • Strong offensive security background (pentesting, vulnerability research, or red team experience) with the ability to think like an attacker and translate that into defensive insights.
  • Experience with reverse engineering (binary analysis, malware inspection, malicious packages) and API/web security (OAuth, JWT, token validation, secret exposure patterns).
  • Comfortable working with modern infrastructure , such as cloud platforms (AWS, GCP, or Azure) or AI/LLM ecosystems, and able to assess their specific security implications.
  • Leverage AI tools actively in your day-to-day research workflow, whether for automation, analysis, or accelerating prototyping.
  • Proficient in at least one system or scripting language (Python, Go, or Rust) , fluent with a terminal, and able to independently retrieve, transform, and analyze datasets to support research conclusions.
  • Track down complex security problems in software and infrastructure and define their solutions.
  • Enjoy hacking things and rapidly prototyping ideas.
  • Drive research autonomously, identify topics, conduct investigations, and publish findings, while partnering with engineering and product teams to translate insights into platform improvements.
  • Public research track record: CVEs, conference presentations, open-source tooling, or technical publications.
  • Fluent in English (written and spoken), with strong communication skills: you can explain complex vulnerabilities clearly to both technical and non-technical audiences and present at international conferences.
The following skills would strengthen your application but aren't required:
  • Understand supply chain security, including how attacks propagate through package registries (npm, PyPI, DockerHub), GitHub Actions workflows, and dependency automation tools.
  • Experience monitoring ongoing attacks, correlating signals across multiple data sources, reconstruct breaches, and having published your findings to the security community.
The interview process

At GitGuardian, we are committed to building a diverse, equitable and inclusive workforce.

We will ask for your gender on the application page to help us understand the diversity of our applicant pool and to track our progress in attracting and hiring a diverse workforce. The information is optional and will not be disclosed to the hiring manager or the interview team and will not be considered in the hiring process. We appreciate your willingness to share this with us so that we can continue to improve our diversity and inclusion efforts.

1. First Screening Call (Virtual)

To discover your professional project and evaluate if there could be a mutual match.

2. Interview with your future manager

To walk through your offensive security background and how you take research from idea to published finding.

3. Technical Test / Research Case (2 sessions x 60 min)
  • First session (Engineering focused) example tasks might include parsing a dataset of potential secret exposures, building a detector for a specific credential type, or investigating an internal security incident from telemetry data
  • Second session (Research focused) example tasks might include investigating a credential leak by digging into source code and CI logs, then pivot into cloud infrastructure using the exposed credentials
4.1 Meet the team (onsite)

An on-site lunch with the research and marketing team members, to meet the people you'll publish and work with.

4.2 Final Interview with an Executive Member

To detail our company's vision and ambitions for the next couple of years.

5. References check

You can start thinking about two contacts who can attest to your previous or current professional experiences. These contacts should be as recent as possible, and we will call them at the end of the process.

Benefits
  • Package that includes BSPCE
  • Lunch voucher (Swile, 12€ at 50%)
  • Sponsored Wellpass (gymlib)
  • Non-charged health insurance for children (Sidecare / Generali)
  • Up to €300 to improve your home office set-up
  • Yearly holiday allowance
  • Referral bonus of 4000€ for any new Guardian we might hire thanks to you
  • Team building: monthly budget dedicated to each employee that you can spend as you wish, with colleagues (latest examples to date: Michelin star restaurant, karaoke, stand-up show, kitesurfing week-end, ...)
And also...
  • Remote policy: hybrid (3 days/week at the office in Paris)
  • Opportunities for career development in the long term
Team Marketing Locations Paris Remote status Hybrid Employment type Full-time
Publié le 2026-06-21

Emplois Recommandés

Ingénieur DevOps - expertise cloud - Freelance

Collective.work
Paris

Contexte Le bénéficiaire souhaite une prestation d'accompagnement dans le cadre de la construction et le maintien en condition opérationnel des outils DevOps pour un acteur majeur de la finance pers…

Voir les Détails
Publié le 2026-05-29

Chef de mission expertise H/F

WINSEARCH - PARIS AEC
Paris

Sous la supervision des Experts Comptables, vos missions sont les suivantes : - Portefeuille diversifié (groupes, associations, PME) ; - Gestion et révision des comptes ; - Vérification des travau…

Voir les Détails
Publié le 2026-05-29

Merchandising Manager

coty
Paris 2e

Coty is one of the world’s largest beauty companies with an iconic portfolio of brands across fragrance, color cosmetics, skincare and body care. Coty is the global leader in fragrance and number thr…

Voir les Détails
Publié le 2026-06-24

STAGE - SUPPORT IT () H/F

Les Bons Artisans
Paris

On recrute notre prochain stagiaire Support IT ! Notre entreprise, Les Bons Artisans, spécialisée dans le secteur du dépannage à domicile et des petits travaux, n’attend que toi ? Tu auras la charge d…

Voir les Détails
Publié le 2026-06-09

AI Software Engineer Ajouter aux favoris

Paris

Beamy détecte l'usage réel de 50K+ applications chez 500K+ utilisateurs dans les grandes entreprises, grâce à une extension navigateur déployée à grande échelle. Des millions de signaux captés chaque …

Voir les Détails
Publié le 2026-05-30

Enterprise Account Executive

uipath
Paris

Life at UiPath The people at UiPath believe in the transformative power of automation to change how the world works. We’re committed to creating category-leading enterprise software that unleashes…

Voir les Détails
Publié le 2026-06-26

Auxiliaire de puériculture — H/F

PARIS 11 - CAVAIGNAC LEO LAGRANGE PETITE ENFANCE
Paris

Auxiliaire de puériculture — H/F En tant qu’auxiliaire de puériculture vos missions s’articulent autour de plusieurs dimensions, les relations avec les familles, l’accompagnement de l’enfant, la part…

Voir les Détails
Publié le 2026-05-06

- F/H Coordonnateur de formations

Réseau Paris Formations & Compétences
Paris

Rejoignez le GRETA GPI2D ! Poste à pourvoir : Coordonnateur·trice de formation Lieu : Lycée Raspail, Paris 14e Début : Septembre 2026 Contrat : CDD 12 mois renouvelable – Temps plein …

Voir les Détails
Publié le 2026-06-10

Responsable Test et Déploiement CI/CD - Freelance

Collective.work
Paris

Contexte Le service hypervision vise à développer et supporter les solutions NOI d’event management (gestion et automatisation des alertes de production informatique). Les enjeux sont : d'opti…

Voir les Détails
Publié le 2026-05-18

Technicien d'essais en Vibrations - Spatial (f/h)

AIRBUS
Paris

**Job Description:** * Airbus Defence & Space * recherche un * Technicien d'essais en Vibrations (f/h) * pour rejoindre notre département 'Tests Récurrents et Environnements' basé à * Elancourt, Fra…

Voir les Détails
Publié le 2026-06-09