
Senior Security Researcher
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States.
• Perform in-depth vulnerability research, reverse engineering, and threat analysis across Web/API platforms, mobile operating systems, low-level OS stacks, cloud infrastructures, and essential enterprise software systems.
• Discover high-impact vulnerabilities and innovative attack surfaces; create proof-of-concept exploit techniques to illustrate real-world risks.
• Investigate emerging threat vectors and maintain testing protocols across cloud environments, APIs, mobile platforms, and AI/ML technologies.
• Work alongside Product and Engineering teams to transform research insights into scalable security assessment capabilities, automated testing workflows, and platform intelligence.
• Collaborate with engineering, product, and operations teams to convert security research into customer value and enhancements to the platform.
• Offer technical guidance, benchmarking, mentorship, and quality assurance for junior researchers and community members.
• Represent Cobalt through technical blog posts, advisories, whitepapers, and presentations at conferences.
• Over 5 years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering, or 3+ years with a proven history of published research, CVE disclosures, or contributions to open-source security tools.
• Proficiency in modern application stacks such as Node.js, Go, Python, Java, and Rust.
• Strong understanding of Linux, Windows, and macOS internals, along with operating system security fundamentals.
• Experience with containerized cloud environments, including Docker, Kubernetes, AWS, and GCP.
• Ability to analyze binary, source code, or bytecode and develop reliable proof-of-concept exploits.
• Familiarity with complex vulnerability classes, including memory corruption, deserialization, auth bypass, SSRF/RCE, and cloud privilege escalation.
• Proficient in Python, Go, Bash, or Rust for creating custom research tools, scripts, and testing utilities.
• Capacity to document intricate technical findings as actionable remediation guidance.
• Must reside in the United States; preference for alignment with EST or CST time zones.
• Nice-to-have: knowledge of AI/ML security concepts, LLM risk models, and innovative software integrations.
• Nice-to-have: experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB.
• Nice-to-have: published CVEs, security advisories, or recognition in bug bounty programs.
• Nice-to-have: active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist.
• Nice-to-have: contributions to open-source security tools or research.
• Receive competitive compensation along with an appealing equity plan.
• Save for retirement with a 401(k) program (US) or pension plan (EU).
• Enjoy benefits such as medical, dental, vision, and life insurance (US) or statutory healthcare (EU).
• Access a wellness stipend.
• Get support for work-from-home equipment and a wifi stipend.
• Benefit from a learning and development stipend.
• Enjoy flexible and generous paid time off.
• Receive paid parental leave.
• Participate in ongoing mentorship opportunities.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.