All roles listed as ‘remote’ are available as remote within the same country.

We are looking for a curious, analytical and detail-oriented Security Analyst to join our team and help us uncover unknown vulnerabilities that exist in open source.

Your Role

In modern software development, much of any project's code relies on open source packages. These are out there in the world, visible for anyone, and within that code there are vulnerabilities. As part of our security team, you'll join us on our mission to continually improve our ability to find these open source vulnerabilities in a programmatic way.

You'll join our interdisciplinary security team, alongside fully dedicated engineers focussed on building tools that make your work more effective and have lots of opportunities to learn and grow. This role is particularly well-suited to help you develop a deep understanding of how code works, and over time you'll have the opportunity to work with just about every programming language.

You’ll spend your time:

  • Triaging and analysing potential vulnerabilities discovered within open-source dependencies
  • Further researching known vulnerabilities to determine characteristics such as severity and exploitability
  • Using research to verify or disqualify potential vulnerabilities
  • Building data models and structures
  • Using data analyst techniques to answer research questions about vulnerabilities, and general threat intelligence trends
  • Training machine learning models to find where vulnerabilities are mostly likely to lie, using a combination of our unique database of verified known vulns; information about how the open source community operates; and the static code itself
  • Developing and testing theories and hypotheses around new areas that Snyk tackles
  • Exploring and establishing the new abilities we need to develop our product to further achieve our mission

You should apply if you:

  • You're comfortable working with large datasets (we use BigQuery; ideally you'll have used one of BigQuery, elasticsearch, kibana, hadoop etc.)
  • You have a passion for security and an interest in the problem space
  • You have 2+ years work experience in a relevant field
  • You’ve triaged and analysed data before using techniques and tools such as pandas and jupyter
  • You have experience using statistical tools to help answer research questions
  • You love to automate your work, through writing your own scripts (we use Python and JavaScript)
  • You love learning new techniques and getting experience in new fields
  • You have previous experience working with open source codebases

We’d especially love to hear from you if you:

  • You have worked with researchers before, ideally in the security space or have conducted security research yourself
  • You have experience PoCing vulnerabilities and dealing with vulnerability disclosures
  • You have worked closely with Data Scientists in the past and have experience working with ML

Interested?

Please apply below! We care deeply about the warm, inclusive environment we’ve created and we value diversity - we welcome applications from those typically underrepresented in tech. If you like the sound of this role, but are not totally sure whether you’re the right person, do apply anyway :)

Want to learn more about the role?

Read about the team’s mission and methodologies

Read about our open source vulnerability disclosure program

Read an example of how we find and disclose vulnerabilities

Read some of our research on HTTP Request Smuggling or breaking out of message brokers

About Snyk

Snyk’s mission is to help developers use open source code and stay secure. 

The use of open source is booming, but security is a key concern (https://snyk.io/stateofossecurity/). Snyk’s unique product enables developers and enterprise security teams to continuously find & fix vulnerable dependencies without slowing down, offering seamless integration into Dev, DevOps, and DevSecOps workflows. We care deeply about the quality and usefulness of the tools we develop, always focusing on our customers and users. 

We are experiencing rapid growth - and we want you to join us! By the end of Q3 2019 alone, Snyk was already adopted by over 450,000 developers, including multiple enterprise customers (such as Google, New Relic, ASOS, and others). We also raised an additional $150 Million, announced January 21st, 2020, from investors such as Stripes and Salesforce Ventures, demonstrating that they are as excited as we are by Snyk’s progress and potential.

We believe open-source software is a force for good, and we’re building Snyk to make it easier for developers who aren’t security experts to stay secure.

 

#LI-FS1

Apply for this Job

* Required