Senior Security Researcher (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Researcher (Cybersecurity): Conducting internet-wide threat research and developing offensive security capabilities using large-scale scan data with an accent on adversary emulation and agentic AI frameworks. Focus on identifying vulnerability signals, building autonomous penetration testing agents, and publishing seminal security research.
Location: Remote (Global). Candidates outside the US are considered based on local market data.
Salary: $202,000 – $278,000 USD (depending on US location; market-based for others)
Company
provides real-time Internet intelligence and actionable threat insights to global governments and Fortune 500 companies by mapping the entire Internet's attack surface.
What you will do
- Develop product capabilities by applying an offensive practitioner's perspective to scanning and fingerprinting logic.
- Conduct original research on emerging attack techniques, C2 infrastructure, and adversary tradecraft using internet-wide data.
- Build and evaluate agentic AI frameworks, including autonomous pentest agents and LLM-powered vulnerability tools.
- Produce high-impact research reports and present findings at conferences like DEF CON and Black Hat.
- Collaborate with Engineering and Product teams to translate research into detection features and risk indicators.
- Mentor internal teams as a subject-matter expert on offensive security techniques.
Requirements
- 5+ years of experience in penetration testing, red teaming, or adversary emulation.
- Hands-on experience building or operating LLM-powered attack agents and autonomous pentest frameworks.
- Strong proficiency in Python, Go, or similar languages for automation and data analysis.
- Deep understanding of network protocols, service fingerprinting, and internet-scale scanning.
- Proven ability to independently characterize vulnerabilities and exploitation techniques.
- Required to travel once per quarter for industry events and team onsites.
Nice to have
- Relevant certifications such as OSCP, OSCE, OSEP, or GXPN.
- Experience in IoT, OT/ICS, or embedded device security research.
- A track record of public contributions, including CVEs, conference talks, or tool releases.
- Prior experience working as a researcher at a security vendor.
Culture & Benefits
- Access to a comprehensive, continuously updated map of the entire Internet's exposed attack surface.
- Competitive US benefits package including equity, health, dental, and vision coverage.
- Retirement plan with company contributions and flexible PTO.
- Professional development stipend to support continuous learning.
- Collaborative environment with world-class researchers and engineers.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →