Security Researcher II (WAF)
Most boards and executives are currently flying blind when it comes to cyber risk. They are guessing. At Safe, we’ve built an AI-driven engine that finally gives the C-Suite a clear, quantified, and real-time view of their security posture. We don’t just provide data; we provide certainty.
We are a $170M Series C-funded category leader. We don’t play in the mid-market; we operate at the highest levels of global enterprise. Today, we are proud to serve 10% of the Fortune 500, protecting global icons such as Apple, Netflix, AT&T, Verizon, and Victoria’s Secret.
As we scale toward our next chapter, we are looking for high-performers who want to do the best work of their careers at the intersection of AI and Cybersecurity.
The Culture Memo: Our Operating System
Safe is not a typical corporate environment. We are a high-intensity, mission-driven team. We value builders who want to define a category and work alongside people who are equally committed to excellence.
-
Extreme Ownership: We don’t do "not my job." We hire people who see a gap and own the solution from start to finish.
-
The Elite Standard: We serve the most sophisticated companies on the planet. Our work must be bulletproof. Whether it’s a line of code or a sales deck, we aim for Tier-1 quality every time.
-
Methodology & Rigor: We don’t wing it. From Force Management and MEDDICC in sales to data-driven sprints in engineering, we rely on proven frameworks to stay disciplined and predictable.
-
Radical Candor: We move too fast for politics or sugar-coating. We value direct, honest feedback that helps us find the right answer quickly.
-
The Series C Hustle: We have the stability of a well-funded leader but the heart of a startup.
The Perks & Ownership:
We want our team to feel like owners because they are owners. We trust our people to manage their results and their time.
-
Meaningful Equity: Every "Safestar" is a shareholder. You aren’t just an employee; you are a partner in our success.
-
Unlimited Leaves: We don’t believe in clock-watching. We offer unlimited leave because we trust you to take the time you need to recharge while staying committed to the mission.
-
Comprehensive Benefits: We provide top-tier medical insurance and wellness benefits to ensure you and your family are well cared for.
-
Career Trajectory: We are growing aggressively. For high-performers, the path for advancement moves at the speed of your ambition.
Location: Bangalore Experience: 2 to 4 years
Core Responsibilities:
-
Primary role is to work with the Threat Research team focussing on vulnerability research to analyze affected products and trigger conditions for newly released vulnerabilities
-
Utilize vulnerability and exploit intel feeds to identify applicable compensating controls and policies to prevent successful exploitation of these CVEs
-
Research various WAF products to identify APIs that provides details about attack surface protected, policies applied and the enforcement status of these policies
-
Build automation that continuously monitor changes in these policies and APIs of these WAF solutions
-
Setup a lab to apply compensating controls and policies to validate whether that can prevent the exploitation of the CVE in question
-
Map and review auto generated mapping of CVEs to compensating controls and policies which feeds back to our CTEM product
Essential Skills, Experience and Qualifications:
-
M.Tech or B.Tech / B.E. / BCA in Computer Science or Information Technology
-
Must have hands-on experience in working with WAF products (implementation, fine tuning and building automations)
-
Strong understanding of HTTP protocol
-
Proficiency in Python (or a similar language) and experience working with REST APIs.
-
Must have experience in effectively utilizing LLMs for automation engineering and research such as using LLMs to parse advisories, generate mappings, or build agentic workflows
-
Contributions to open source tools or published research is nice-to-have
-
Able to clearly document technical findings for both research team and customer success team
-
Able to work independently with minimum supervision
-
Effective communication, and interpersonal skills
-
Vendor WAF Certification
Any of the following certifications would be preferred:
Source: the employer's careers page. Last checked 2026-09-30. Posted 2026-09-28.
More jobs at Safe Security · On-site jobs in India · Security and compliance jobs