Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here: https://www.youtube.com/watch?v=B0wmZBcPkFE
Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.
The company was founded by Varun Badhwar and Dimitri Stiliadis, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.
What you’ll do- The primary tasks of this position relate to the detection, triage, and analysis of malicious open source software components — identifying threats across public package ecosystems (npm, PyPI, Maven, etc.) and assessing their scope, intent, and impact.
- Day-to-day work includes triaging and assessing incoming malware alerts, reviewing Indicators of Compromise (IoCs), and maintaining threat campaign records to track attacker infrastructure, tactics, and patterns over time.
- A core responsibility is the in-depth technical analysis of suspicious packages: reverse-engineering obfuscated code, identifying malicious behaviors (exfiltration, backdoors, dependency confusion, typosquatting, etc.), and producing detailed internal assessments.
- You will author and publish external-facing content — blog posts, technical write-ups, and security advisories — communicating findings clearly to both technical and non-technical audiences, and contributing to the broader security community's awareness of emerging threats.
- You will collaborate with internal teams to feed findings into detection pipelines, enrich our vulnerability and threat database, and help improve automated detection coverage over time.
- Bachelor's degree in engineering or a related field, with at least 3 years of hands-on professional experience specifically in malware analysis, threat intelligence, or open source package security
- Demonstrated experience triaging security alerts at scale and working within or alongside a SOC or threat intelligence team
- Hands-on experience reviewing and interpreting IoCs (file hashes, domains, IPs, behavioral signatures) and maintaining threat campaign tracking
- Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go) — including obfuscated or minified code
- Experience producing external security communications: blog posts, advisories, or technical reports intended for a public or customer-facing audience
- Understanding of package manager ecosystems and common attack patterns (typosquatting, dependency confusion, malicious install scripts, etc.)
- Experience contributing to or operating threat intelligence platforms or malware databases
- Familiarity with static and dynamic analysis tooling (sandboxes, YARA rules, SAST tools)
- Understanding of software supply chain security standards and frameworks (SLSA, SSDF, etc.)
- Prior public research, CVE credits, or published malware findings
- Security certifications such as GREM (GIAC Reverse Engineering Malware) or equivalent
- Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.
- Engage in first principles thinking to debate ideas, test assumptions, and make decisions.
- Put data above opinions, seeking truth and clarity in all our endeavors.
- Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.
- Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.
Skills Required
- Bachelor's degree in engineering or related field with at least 3 years professional experience in malware analysis, threat intelligence, or open source package security
- Experience triaging security alerts at scale and working within or alongside a SOC or threat intelligence team
- Hands-on experience reviewing and interpreting IoCs (file hashes, domains, IPs, behavioral signatures) and maintaining threat campaign tracking
- Proficiency reading and analyzing code across multiple languages, including obfuscated or minified code (Python, JavaScript/TypeScript, Java, Go)
- Experience producing external security communications such as blog posts, advisories, or technical reports for public or customer audiences
- Understanding of package manager ecosystems and common attack patterns (typosquatting, dependency confusion, malicious install scripts)
- Experience contributing to or operating threat intelligence platforms or malware databases
- Familiarity with static and dynamic analysis tooling (sandboxes, YARA rules, SAST tools)
- Understanding of software supply chain security standards and frameworks (SLSA, SSDF)
- Prior public research, CVE credits, or published malware findings
- Security certifications such as GREM or equivalent
What We Do
At Endor Labs, we’re building the modern Application Security platform for the AI-driven era of software development. Our mission is simple but bold: help every organization ship secure software fast with clarity on what matters, and the power to fix it quickly. Today’s AppSec teams are buried in noisy alerts and fragmented tools, while developers race to innovate using open source and AI-generated code. This gap between speed and security puts both innovation and trust at risk. Endor Labs bridges that gap. We unify intelligent code reviews, static analysis, and guided remediation into one connected platform that gives security teams visibility and developers clear, actionable fixes without slowing them down. Our technology deeply analyzes how your software actually works, building a complete graph across first-party, open-source, and AI-generated code. With this context, Endor Labs filters out 92 % of false positives and surfaces the risks that truly matter. Developers can fix vulnerabilities six times faster, automate reviews with AI, and even enable guardrails for AI coding assistants to write secure code by default. We’re trusted by organizations like OpenAI, Snowflake, Peloton, Dropbox, Robinhood, and Rubrik to secure some of the most advanced codebases in the world. Backed by top investors including Lightspeed Venture Partners, DFJ Growth, Coatue, Salesforce Ventures, Dell Technologies Capital, and Citi Ventures, Endor Labs is one of the fastest-growing companies in cybersecurity. But beyond our technology, what truly sets Endor Labs apart is our culture of builders. We’re a team of passionate engineers, researchers, and security experts, over a third with PhDs, united by curiosity, rigor, and the belief that great engineering and great security go hand in hand. We move fast, value craft, and empower each other to innovate boldly while staying grounded in impact.
Why Work With Us
We’re a team of curious builders redefining software security for the AI era. Our culture values ownership, collaboration, and bold thinking where every employee has the freedom to innovate and the support to thrive.
Gallery








