Research Engineer I - Python & Security
Summary
As a Security Research Engineer on the Product Content Research team, you’ll develop and test Python‑based security configurations, enhance real‑time detection for ERP systems, and research and resolve vulnerabilities, collaborating with defensive researchers in a Linux environment.
About the job
The world’s most critical--and at-risk--business applications have been neglected for far too long. Onapsis eliminates this blind spot by providing cybersecurity solutions dedicated to business-critical applications. Whether running on-premises, in the cloud, or in a hybrid environment, Onapsis helps nearly 30% of the Forbes Global 100 understand the threats and risks across their SAP and Oracle landscapes.
We are seeking a self-motivated and enthusiastic Security Research Engineer to join our Product Content Research team. As a Research Engineer, you will assist in advancing, maintaining, and enhancing our platform features in Threat Detection and Response, Vulnerability Management, Static Code Analysis, and Compliance Automation. This role is ideal for an entry-level professional with knowledge and experience in Python development and a big willingness to dive deep in the cybersecurity field.
What you will be doing, your legacy:
In this role, you will work closely with our defensive research team to evaluate security vulnerabilities, create and analyze exploits, and generate the content that drives our business solutions. Collaborating with a team of dedicated researchers, you will enhance your skills in both security and SAP. You will:
- Develop and test a comprehensive portfolio of security configurations.
- Enhance detection in real time of user behaviors that could impact the security of ERP systems.
- Research and resolve vulnerabilities to ensure robust protection for our customers.
Your contributions will help secure our customers' critical systems and data, making a significant impact on the cybersecurity landscape.
Requirements:
- 1 year of programming experience with Python
- Knowledge of Python best practices
- Basic experience working with API Calls (REST, GraphQL, Django, Flask).
- Experience developing under Linux environments
- Familiar with security and networking protocols
- Practical experience in security software development
- Effective communication skills, both written and verbal
- Good English skills
Desired skills or interests in:
- Basic knowledge of cybersecurity principles, including confidentiality, integrity, and availability (CIA)
- Interest in research on security challenges and potential solutions
- Basic knowledge of network protocols, architecture, and security mechanisms.
- Basic understanding of common network vulnerabilities and attacks.
- Basic knowledge of Regular Expressions (regex).
- Basic experience with Python Async Technologies desired (Celery, AMQP, MQTT, Redis)
What we offer:
- A role in shaping the future of protecting the most critical applications that run the world's business and a career that grows as the company grows.
- A unique culture of high achievement and teamwork.
- Supportive and humble colleagues are the space's top problem solvers and innovators.
- Financial security through competitive compensation and incentives.
Employment: Onapsis only hires full-time employees in Romania. We do not entertain SRLs or B2B contract situations.
Location: Onapsis is establishing a new development center in Bucharest. This is a hybrid role (1-2 days per week from the office), so candidates must be commutable to Bucharest.
About Onapsis:
Onapsis protects the business applications that run the global economy. The Onapsis Platform delivers vulnerability management, change assurance, and continuous compliance for business applications from leading vendors such as SAP, Oracle, and others. The Onapsis Platform is powered by the Onapsis Research Labs, the team responsible for the discovery and mitigation of more than 1,000 zero-day vulnerabilities in business applications.
Onapsis is headquartered in Boston, MA, with offices in Heidelberg, Germany and Buenos Aires, Argentina, and proudly serves hundreds of the world’s leading brands, including close to 30% of the Forbes Global 100, six of the top 10 automotive companies, five of the top 10 chemical companies, four of the top 10 technology companies, and three of the top 10 oil and gas companies.
For more information, connect with Onapsis on LinkedIn or visit https://www.onapsis.com.
#LI-AC1
#Hybrid
As published by greenhouse · 6 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (1)
- LinkedIn Profile
Pick from a list (5)
- Are you legally authorized to work in Romania?
- Will you now or will you in the future require work visa sponsorship for employment in Romania?
- Do you reside within commutable distance to Bucharest?
- I understand that the role to which I'm applying is for a full-time employee position with Onapsis Romania, SRL, and I acknowledge that Onapsis Romania does not entertain B2B or sole-proprietor SRL relationships for employment in this role.
- Onapsis, Inc. (“Onapsis”, “We” or “us”), respects your privacy and is committed to protecting it through our compliance with our Privacy Policy, a copy of which can be found at https://onapsis.com/privacy-policy (the “Policy”) . This Policy is designed to describe to you the basis for the processing of the personal data we collect from you, or that is provided by you as part of our recruitment process. Onapsis engages with Greenhouse, a web-based hiring platform, as Sub-processor to assist in our recruiting process. As part of that process, Greenhouse will be collecting and processing the personal data you have shared. See Greenhouse’s Privacy Policy. When you apply for a job posted by Onapsis and you provide us with your personal data, we and our Sub-processor will use that for the purposes of determining whether or not you’re a good fit for current and future roles at Onapsis. Onapsis and our Sub-processor will keep your personal data for up to 12 months or for as long as required pursuant to applicable legal and/or regulatory requirements. If it turns out we’d like to keep it around longer, we’ll reach out to you to extend the consent. optional