Commit

Application Security Research Engineer

Commit  •  Manila, PH (Onsite)  •  20 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We're a global leader in software supply chain management, trusted by thousands of customers including the majority of Fortune 100 companies to manage, accelerate, and secure their software delivery from code to production.

We're looking for an Application Security Research Engineer to join a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. This hands-on role emphasizes offensive security, code exploitation, automation, and innovation — directly shaping our product security posture and scaling secure-by-design principles.

Responsibilities:

  • Help to reshape company Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long-term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.

Requirements

Requirements

  • 5+ year experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.
  • AI and LLM Penetration testing knowldge and Experience
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to lead security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines,
  • Publications or open-source contributions in the security domain are a plus.
Commit

About Commit

Commit is a global tech services company with offices in Israel, US, Canada, UK, and Europe.

The company was founded in 2005 and has over 1000 multi-disciplinary innovation experts who serve a broad range of companies, from small startups to large enterprises in multiple business sectors.

Commit specializes in advanced technologies and applications with dedicated practices in Cloud, GenAI, Software, IoT, Big Data, Cyber, Collaboration, Data center migration projects, and more.

Commit offers innovative, end-to-end technology solutions by developing custom software and IoT platforms for clients looking to build their next-gen products within the modern ICT world.

Commit’s complete and comprehensive engineering powerhouse of resources and proprietary Flexible R&D methodology helps transform its clients’ technology visions into high-quality products while reducing costs and improving time-to-market.

Industry
IT & Software
Company Size
501-1,000 employees
Headquarters
Petah Tikva, IL
Year Founded
2005
Social Media