About the role
What we do at Detectify
We’re Detectify, and we’re not your average cybersecurity company. We’re a team obsessed with building cutting-edge tech that actually makes a difference in making the internet a safer place. We’re talking about real-life hackers who know their stuff—you’ll learn from the best and join a team that combines human ingenuity with automation to streamline asset discovery and vulnerability assessments.
The Vulnerability Assessment Research team
This team is currently composed of security researchers focused on making sure that the members of Detectify Crowdsource - our network of ethical hackers - are engaged and enjoying the best possible experience when collaborating with Detectify.
When our hackers submit a vulnerability through our Crowdsource platform, our team builds a module for it and adds it to the Detectify service. Once a vulnerability is reported to us, it becomes a security test which is then made available to all our customers - this is how Detectify combines automation and crowdsourcing.
These tests come in various unique flavors and are driven by crowdsourced security knowledge. We in the Vulnerability Assessment Research team are responsible for validating, configuring, and executing such tests on our customers’ web applications.
We aim for the best possible scanning performance with comprehensive coverage of possible security issues, optimizing for flow, fast feedback, and quality. We follow lean and DevOps concepts, aiming to be innovative and helpful, and to have a strong sense of ownership of all the things we build.
What you'll get to do
As a Security Researcher, your main responsibility will be to validate and implement proof of concepts, uploaded by our Crowdsource and internal researchers, into our scanners. This is a great opportunity to boost your knowledge around hacking and vulnerabilities.
Other responsibilities include:
• Communicate with our internal security researchers in order to gather all necessary information to understand the submitted vulnerabilities.
• Develop modules from vulnerability reports using a JSON-based DSL or Go.
• Perform code reviews to ensure accuracy and reduce false positives.
• Consistently review behavior of implemented modules to identify false positives or negatives.
• Work with continuous automation of module development.
Who you are
We believe that you are a student and want to do your LIA (work placement) with us here at Detectify for a period of 6 months. You are a highly versatile and self-motivated individual who can create and drive change. You are involved with the security community and understand how vulnerabilities work. You have a strong interest in internet security and you want to engage with an international network of security researchers. Ideally, you have some hands-on experience with bug bounties, CTFs (Capture the Flag), or similar.
So, what do you think?
We are proud to foster an inclusive workplace free from discrimination. We strongly believe that diversity of experience, perspectives, and backgrounds will lead to a better environment for our employees and a better product. This is something we value deeply and we encourage everyone to be a part of changing the way the world thinks about security! Go hack yourself!
Location
This position is for the Stockholm office and we'd like to see you there in person a few times per week.
So, what do you think? We are proud to foster an inclusive workplace free from discrimination. We strongly believe that diversity of experience, perspectives, and background will lead to a better environment for our employees and a better product. This is something we value deeply and we encourage everyone to be a part of changing the way the world thinks about security! Go hack yourself!
