Conduct advanced vulnerability research and security assessments across modern application and cloud stacks.
Develop proof-of-concept exploits and collaborate with cross-functional teams to strengthen customer security.
Provide mentorship to junior researchers and represent Cobalt in the security research community.
Cobalt provides offensive security testing via a SaaS platform and a community of over 400 vetted testers. The company is fully remote and values diversity and inclusion.
Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Design, develop, integrate, and maintain CPU firmware, BIOS, boot loader software, and low-level system components.
Bring up and validate new CPU boards, working closely with hardware engineers and technology vendors.
Provide technical leadership across engineering projects and mentor junior engineers to support knowledge sharing.
This position is listed on behalf of a partner company that develops advanced networking systems. They foster a collaborative and inclusive engineering culture that values diverse perspectives and innovation.
You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
You will develop tools and scripts for capability analysis and inform detection strategies.
Your work directly enhances Dragos' ability to defend against advanced threats.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.
Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.
Conduct deep technical research into malware, firmware, and adversary tools targeting industrial environments.
Develop YARA signatures and detection strategies to protect critical infrastructure.
Collaborate with analysts and engineers to transform research into actionable defenses.
The company defends critical infrastructure from advanced cyber threats. It operates with a remote-first, mission-driven culture focused on innovation and transparency.
Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data.
Conduct original research on emerging attack techniques using Internet-wide scan data and publish findings at major conferences.
Collaborate with engineering and product teams to translate research into new scanning modules, fingerprints, and detection features.
Censys provides real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide. The company values collaboration, innovation, and impact, with a team of world-class researchers and engineers.
Diagnose and resolve customer-reported issues quickly, from investigation through durable fix.
Deliver high-quality engineering work that improves platform reliability and directly addresses customer needs.
Partner closely with Customer Success to align on technical solutions and maintain backend systems, APIs, and data pipelines.
VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for exploitation prevention. Founded in 2021, the company has a transparent, collaborative, and supportive culture with a team of cybersecurity experts.
Deploy and support Scout products in real customer environments, building and improving deployment automations.
Prototype integrations with customer systems and turn repeatable issues into actionable product requirements.
Communicate clearly with technical and non-technical customers while researching cybersecurity trends.
Volexity is a cybersecurity company that builds products used in real-world security environments, including incident response and threat intelligence. The company values diversity and is an equal opportunity employer, hiring based on qualifications and merit.
Develop and maintain a multi-platform implant in Rust for Windows, Linux, and macOS.
Build C2 infrastructure, post-exploitation modules, and AV/EDR evasion techniques.
Design network pivoting and tunneling capabilities, and write integration tests.
Horizon3 is a cybersecurity company that provides the NodeZero autonomous pentesting platform to help organizations find and fix exploitable attack vectors. They are a remote team of former U.S. Special Operations cyber operators and engineers, committed to a culture of respect, collaboration, and ownership.
Build into the product by writing investigation flows, building integrations with security tools, and fixing bugs.
Evolve the investigation logic and pipelines to handle new classes of security alerts, balancing accuracy, performance, and maintainability.
Contribute directly to the Python codebase while influencing architectural decisions and long-term product strategy.
Dropzone AI scales cybersecurity beyond human limits by augmenting security engineers with AI specialists. The venture-backed company is disrupting the $200B+ cybersecurity market and has a team with deep experience in cybersecurity, AI/ML, and SaaS.
Provide technical leadership and assist sales teams by presenting products and managing trials.
Conduct file analysis, malware analysis, and reverse engineering for enterprise clients.
Maintain relationships with technical staff and complete RFPs and security questionnaires.
ReversingLabs develops cyber threat detection and mitigation tools that address advanced persistent threats and polymorphic malware. The company has an international team and fosters a collaborative, growth-oriented culture.
Conduct hands-on security research across Active Directory, Windows, and Entra ID environments to identify vulnerabilities and attack techniques.
Design, develop, and validate proof-of-concept exploits and security research tools.
Collaborate with engineering and product teams to translate research findings into product enhancements.
The company is a partner organization specializing in identity security research and innovation. They maintain a remote-first culture with a collaborative, team-oriented environment, valuing diverse perspectives and professional growth.
Own the engine-integration framework, including Unreal and Unity SDKs, and keep them working across engine versions.
Own the hooking and cross-DLL machinery, including vtable, pointer-slot, and inline hooks.
Enable the rest of engineering by designing SDK, scripting, and reflection surfaces that are clean and maintainable.
Wand builds game customization and guidance tools that help players have more fun in their favorite games. They have over 40 million players and a team that loves games, moves fast, and cares deeply about their work.
Identify innovative ways to detect Windows OS threats and develop cross-platform features leveraging telemetry from OS subsystems.
Collaborate with Product, Engineering, and Security teams to implement detection logic and address gaps in product coverage.
Apply AI to improve research quality and speed, and mentor team members to advance technical expertise.
Huntress is a cybersecurity company founded by former NSA operators that provides enterprise-grade cybersecurity to businesses of all sizes. They are a remote-first team securing over 5 million endpoints and 11 million identities, with a culture focused on collaboration and making a meaningful impact.