Endor Labs logo

Endor Labs

Security Engineer - Vulnerability at Endor Labs

Bengaluru, IndiaFull-timeEngineeringPosted about 1 month ago
Apply with Pipeline

About the Role

<h2><strong>Who we are</strong></h2> <p>Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder &amp; CEO here:&nbsp;<a href="https://www.youtube.com/watch?v=B0wmZBcPkFE">https://www.youtube.com/watch?v=B0wmZBcPkFE</a></p> <p>Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.</p> <p>The company was founded by&nbsp;<a href="https://www.linkedin.com/in/vbadhwar/">Varun Badhwar</a>&nbsp;and&nbsp;<a href="https://www.linkedin.com/in/stiliadis/">Dimitri Stiliadis</a>, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.</p> <h2><strong>What you’ll do</strong></h2> <ul> <li>The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines,<br>e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit&nbsp;generation.</li> <li>Day-to-day work includes monitoring and managing pipelines that triage, enrich, and&nbsp;prioritize vulnerabilities at scale, working with the standards and data sources the<br>ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) and&nbsp;continuously improving the accuracy, coverage, and timeliness of our data.</li> <li>You will work hand-in-hand with our world-class 0-day researchers to scale automated&nbsp;vulnerability discovery — turning manual research workflows into repeatable,<br>production-grade systems.</li> <li>You will investigate high-impact vulnerabilities and the vulnerability landscape at large,&nbsp;and author external-facing content — blog posts, technical write-ups, and advisories —<br>communicating findings clearly to both technical and non-technical audiences.</li> <li>You will collaborate with internal teams to feed findings into detection and analysis&nbsp;pipelines, enrich our vulnerability database, and help improve automated coverage over<br>time</li> </ul> <h2><strong>What </strong><strong>we're looking for&nbsp;</strong></h2> <ul> <li>Bachelor's degree in engineering or a related field, with at least 3 years of hands-on&nbsp;professional experience in vulnerability research, vulnerability management, product<br>security, or application security</li> <li>Extensive knowledge of software vulnerabilities, triage, and prioritization, including deep&nbsp;familiarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS,<br>PURLs, NVD, OSV, VEX, SBOM formats)</li> <li>Hands-on experience building production-grade solutions at enterprise scale — e.g.,&nbsp;CI/CD automation, management of SAST/SCA findings, or comparable security tooling<br>deployed across large engineering organizations</li> <li>Demonstrated experience shipping AI/agentic systems to production — LLM pipelines,&nbsp;agent frameworks, tool use, prompt and eval design — with a clear track record of<br>measuring output quality and a sound sense of where these approaches hold up and&nbsp;where they don't</li> <li>Proficiency in reading and analyzing code across multiple languages (Python,&nbsp;JavaScript/TypeScript, Java, Go), and comfort reasoning about patches, root causes,<br>and exploitability</li> <li>Experience producing external security communications: blog posts, advisories, or&nbsp;technical reports intended for a public or customer-facing audience</li> </ul> <h2><strong>Nice to have</strong></h2> <ul> <li>Experience writing proof-of-concept exploits, or with fuzzing, static analysis, or&nbsp;automated vulnerability discovery</li> <li>Contributions to open source vulnerability databases, scanners, or related tooling (OSV,&nbsp;osv-scanner, OpenVEX, etc.)</li> <li>Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output at&nbsp;scale</li> <li>Understanding of software supply chain security standards and frameworks (SLSA,&nbsp;SSDF, etc.)</li> <li>Prior public research, CVE credits, or published vulnerability findings</li> <li>Security certifications such as OSCP, OSCE, or equivalent</li> </ul> <h2><strong>At Endor Labs, we:</strong></h2> <ul> <li style="font-weight: 400;">Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.</li> <li style="font-weight: 400;">Engage in first principles thinking to debate ideas, test assumptions, and make decisions.</li> <li style="font-weight: 400;">Put data above opinions, seeking truth and clarity in all our endeavors.</li> <li style="font-weight: 400;">Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.</li> <li style="font-weight: 400;">Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.</li> </ul>