Subscribe job alerts


Remote Job

Senior Web Application Vulnerability Researcher

Defiant, Inc.
  • Posted : one year ago

Headquarters: Seattle, WA
URL: https://www.defiant.com/

Description

Wordfence is owned and operated by Defiant Inc. We are a small, dynamic, fast-growing, and profitable company with loyal customers who love our products and services. We are the global leader in WordPress security, protecting over 4 million websites. We regularly release high-quality software, firewall rules, and threat intelligence to millions of customers around the world. We also publish ground-breaking security research weekly that is covered by journalists and information security professionals and publications around the world.

If you are excited about working for a technology company that is securing a huge part of the Web and are looking for a full-time job with flexible hours working remotely, this may be your dream job! Our core hours are 10 am to 1 pm Pacific time and our team has flexibility outside those hours.

Full time salary of $115,000 to $130,000, depending on experience.
This position requires that you be eligible to work in the US without immigration assistance and that you currently live in the US.

Company Culture

You'll work with a talented and highly-motivated team that is friendly, fast-moving, self-managing, and highly capable with a sense of humor. Our team's family time is important; we won't typically require long hours when we can avoid it, which is almost always.

Our entire team works remotely using Slack for casual interaction, ­so you can live practically anywhere in the World if you have an Internet connection. There's no micro-­management here—we trust that you will see tasks through to completion and communicate with your fellow team members when needed or ask for help when needed.

At Defiant, ‘trust’ is the attribute we value most highly among our team members. We need to know that you can grab a task, communicate clearly with stakeholders, and see the task to completion with superb attention to detail.

We use apps like Slack, FogBugz, GitHub, and Google Apps for our workflow. 

Requirements
  • Perform vulnerability analysis to determine vulnerability type, impact, severity, and more. Prioritize response based on this data. 
  • Review source code changes in WordPress based software to identify common vulnerabilities that may have been patched.
  • Perform responsible disclosure for vulnerabilities discovered by themself or reported to the Wordfence Threat Intelligence team.
  • Develop proofs of concept, programmatically or conceptually, to test the exploitability of vulnerabilities. 
  • Replicating exploitation of a vulnerability in a test environment.
  • Manage database of known WordPress vulnerabilities and continue to populate new records based on incoming vulnerability feeds. 
  • Perform WordPress vulnerability research to uncover new vulnerabilities when not handling other responsibilities. 

Our ideal candidate has:
  • Technical experience with WordPress.
  • Experience with security research and writing vulnerability reports.
  • Experience with responsible vulnerability disclosure.
  • Experience generating/modifying HTTP requests.
  • Experience working with BURP suite, or similar software, and a PHP debugger.
  • Familiarity with the CVE Program and CVE IDs.
  • Certifications, or desire to obtain certifications, are always a bonus (OSWE, eWPTx, PenTest+, Security+, eWPT, GWAPT, etc..) 
  • Experience formulating CVSS scores and identifying CWEs for vulnerability types.
  • Experience programmatically interacting with REST APIs.
  • Experience with writing and/or testing Web Application Firewall rules, or familiarity with functionality of access control lists. 
  • Comfortable with diff'ing and searching files using command line tools.
  • Basic understanding of WordPress hooks and how they are used. 
  • Experience working with REGEX.
  • Experience with requesting CVE IDs for vulnerabilities is a plus. 
  • Eagerness to learn and think outside of the box. 

Desired Qualifications:
  • Familiarity with applicable OWASP vulnerabilities and their basic operation.
  • Comfortable with reading and reviewing PHP code and identifying common vulnerabilities.
  • Familiarity with common WordPress related vulnerabilities - both generic and WordPress specific related coding flaws. 
  • Comfortable writing simple scripts and automations.
  • Comfortable writing basic SQL queries.

Hiring Process:
  1. Please fill in the form provided in this application. The hiring team will look at this first. The way you answer our form will determine if your application moves to the next step. Please note that we read every answer and this form is a critical part of our hiring process. 
  2. Candidates who appear to have the right skills from the initial application will be sent a more detailed Assessment Test to further assess skills.
  3. Participate in a series of phone interviews. We are respectful of your time, and keep the number of interviews you will need to attend to a minimum. This is usually two or three interviews. 
  4. All contracts and offers of employment are contingent on the successful completion of a background check. The results of the background check are considered as they relate to the position and do not automatically disqualify someone from a contract or employment with the company.
  5. Join our fast-paced team and start testing our products and and helping release software to over 4 million customers! All positions require a trial period of approximately 2-3 weeks with a minimum commitment of 10 hours per week. You will be paid for this short-term contract, and it will be used to evaluate whether both parties want to pursue an ongoing, regular employment relationship.

Benefits
  • Full time telecommuting and flexible working hours, with a company that has been 100% remote for over 8 years.
  • 100% employee premium and 50% of dependent premium paid by company for premier- level medical, dental, and vision insurance.
  • 21 days PTO per year to start.
  • 11 paid company holidays including the week from December 25 to January 1.
  • 401(k) with a 4% Safe Harbor company match that is 100% vested immediately.
  • Latest in laptop and workstation technology.
  • Wellness reimbursement program for health and fitness purchases.
  • Mobile phone and internet reimbursement up to $100 per month.
  • Monthly beverage reimbursement for coffee, tea, water, etc.
  • Paid training and study time for work-related training and certifications.
  • College tuition and Student Loan reimbursement.

Diversity at Defiant

We value diversity and do not discriminate based on race, color, religion or creed, national origin or ancestry, sex, age, physical or mental disability, military or veteran status, gender identity or expression, marital status, sexual orientation, political ideology, economic status, parental status, or any other non-performance-related status.

Skills
  • researcher
  • php
  • sql
  • wordpress
  • infosec

Similar Jobs

Remote Job

Senior Figma UX/UI Designer for Web Applications

Quantenwerft International GmbH
  • 2 weeks ago
  • Job Title: Senior Figma UX/UI Designer (Remote)Location: Remote (Candidates must be based in Europe, USA, South America, Canada, or England)Job Overview: We seek a Senior Figma UX/UI Designer with advanced design skills and profound knowledge of Figma’s most intricate functionalities. This pos

Remote Job

Chief React WordPress Developer & Gutenberg Master – CTO Track

Quantenwerft International GmbH
  • 2 weeks ago
  • Position: Chief React WordPress Developer & Gutenberg Master – CTO Track (Europe, USA, South America, Canada, England)Location: Fully Remote (Applicants must reside in Europe, the USA, South America, Canada, or England)Employment Type: Full-time, Permanent or Part-Time Compa

Remote Job

Head of Data Engineering

Realiste
  • 2 weeks ago
  • Realiste is emerging global prop-tech company with headquarters in Dubai. Here at Realiste we have a mission of creating a digital online platform that will allow people from around the world to find and invest in real estate market. We want our clients to have convenient and transparent tools to na

Remote Job

Senior Full Stack WordPress Developer – React & Gutenberg Mastery

Quantenwerft International GmbH
  • 2 weeks ago
  • Position: Senior Full Stack WordPress Developer – React & Gutenberg, Full Site Editing MasteryThe developer should be based in one of the following countries: Europe, the United Kingdom, the United States, South America, Canada, or Bangladesh.Type of employment: Full-time Co

Remote Job

Senior Wordpress Developer

Proxify
  • 4 weeks ago
  • About us: Talent has no borders. Proxify's mission is to connect top developers around the world with opportunities they deserve. So, it doesn't matter where you are; we are here to help you fast-track your independent career in the right direction. 🙂 Since our launch, Proxify&#

Remote Job

Senior Laravel Developer

Proxify
  • 4 weeks ago
  • About us: Talent has no borders. Proxify's mission is to connect top developers around the world with opportunities they deserve. So, it doesn't matter where you are; we are here to help you fast-track your independent career in the right direction. 🙂Since our launch, Proxify's d

Remote Job

Remote Frontend Developer / Engineer for an AI Tech Chatbot Called Clepher

Clepher
  • a month ago
  • We are seeking a Frontend Developer / Engineer with 2+ years of experience. Our ideal candidate should be able to write readable, scalable, and reusable code. Definitely a plus if you're proficient in legacy PHP, jQuery, and JS code, as we're rebuilding our app from the ground up using newer

Remote Job

Website Developer / Designer - Remote (Work from Home)

StubGroup
  • a month ago
  • Who we are:We are a team of hard-working marketers running a Google Partner ad agency.We help businesses large and small. Most of our clients are located in the United States, and our team members are located throughout the United States and around the world.Check out our website: stubgroup.comWhat

Remote Job

Mobile Application Developer

PRI Technology
  • 2 months ago
  • Please note that though the work is remote the end client requires candidates to be living in the greater NYC metro area. No exceptions!No third parties. Boutique Mobile and Web Software Development company located in lower Hudson Valley, NY is seeking an iOS software developer, android experience a

Remote Job

Senior WordPress Developer - Contract (Fully Remote in East Coast)

Atlantic Partners Corporation
  • 2 months ago
  • Our client, located in Atlanta, GA, is seeking a Senior WordPress Developer for a fully remote contract opportunity. This role will be responsible for migrating their Cwicly toolkits and plugins to Elementor. Requirements: 5+ years of WordPress development experience. Experience working with Cwicl

View All