Source Job

$202,000–$278,000/yr
US Unlimited PTO

  • Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data.
  • Conduct original research on emerging attack techniques using Internet-wide scan data and publish findings at major conferences.
  • Collaborate with engineering and product teams to translate research into new scanning modules, fingerprints, and detection features.

Penetration Testing Red Teaming Python Go Network Protocols

20 jobs similar to Senior Security Researcher

Jobs ranked by similarity.

$140,000–$140,000/yr
US

  • Lead advanced penetration tests and adversary emulation in ICS/OT environments, performing hands-on exploitation of customer networks and systems.
  • Conduct deep technical analysis of network data to identify attack paths and vulnerabilities, while researching threat actor TTPs.
  • Deliver clear reports and briefings to customers, mentor team members, and contribute to the OT security community.

Dragos defends industrial organizations providing essentials like water, electricity, and safe working environments. As a market leader in ICS/OT cybersecurity, we are remote-first with global operations and seek mission-oriented teammates embodying authenticity, transparency, and trust.

$100,000–$130,000/yr
US

  • Perform offensive security assessments on cloud infrastructure, web applications, APIs, and traditional networks for clients across various industries.
  • Develop detailed penetration testing documentation and collaborate with teams to integrate security into CI/CD pipelines.
  • Contribute to building a new offensive security service line within a top-rated CPA and advisory firm.

Aprio is a top 20 CPA-led advisory firm serving fast-growing industries with expertise in assurance, tax, and advisory services. The firm has over 3,200 team members across 40+ offices globally, and is recognized as a Best Place to Work with a collaborative culture.

UK

  • Lead and mentor an internal red team, establishing scalable offensive security practices.
  • Conduct advanced penetration testing and adversarial simulations across cloud infrastructure and AI environments.
  • Research emerging attack techniques and collaborate with detection teams during purple team exercises.

They operate a cutting-edge cloud platform that supports advanced AI workloads. The company is remote-first, emphasizes innovation and continuous improvement, and has a collaborative international team.

Germany

  • Perform penetration tests of IT infrastructures, web applications, and web services.
  • Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
  • Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.

SITS Deutschland GmbH is part of the SITS Group, a leading IT security provider offering holistic security solutions. The company has over 700 employees and fosters a culture of appreciation, team spirit, and work-life blending.

$120,000–$155,000/yr
US

  • Perform Red Team engagements including stealth and purple teaming to simulate advanced cyber attacks and test security posture.
  • Collaborate with blue team members in real time to identify and address security gaps, and document findings for technical and executive audiences.
  • Stay current on attack vectors, develop new tools and techniques, and provide technical leadership to junior team members.

NBCUniversal is a leading media and entertainment company, creating world-class content across film, television, streaming, and theme parks. As a subsidiary of Comcast, we employ a global workforce and foster an inclusive culture focused on innovation and community.

US Unlimited PTO

  • Execute semi-automated and manual red team operations on sensitive OT environments, including ICS, SCADA, and embedded systems, with a focus on safety and uptime.
  • Identify and exploit weaknesses across diverse attack surfaces, such as OT protocols, Active Directory, PKI, and container technologies, while maintaining operational security.
  • Produce clear, actionable reports and collaborate with internal teams to translate validated kill chains into inputs for AI-driven defensive systems.

Armadin is a group of engineers, researchers, and hackers on a mission to redefine proactive security in the AI era by building autonomous security agents that discover and remediate risks before breaches occur. Led by Kevin Mandia, founder of Mandiant, the team includes researchers from Google, xAI, Meta, Stanford, and MIT, focusing on reinventing security for an ever-evolving threat landscape.

$155,520–$228,700/yr
US

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps.
  • Conduct internal/external network audits and vulnerability validation.
  • Develop custom exploits, adversary emulation, and AI/LLM security testing.

Twilio is shaping the future of communications by delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide. The company values a remote-first work culture, global inclusion, and diverse experiences.

Europe 6w PTO

  • Monitor and test Sporty's entire external attack surface across domains, subdomains, and public IP addresses.
  • Conduct adversary emulation exercises against endpoints to validate EDR/XDR and SOC defenses.
  • Translate offensive findings into actionable defensive improvements and remediation blueprints.

Sporty Group is a remote-first company operating in the sports and gaming industry. It focuses on sustainability and offers a competitive salary with quarterly bonuses and annual retreats.

US Unlimited PTO

  • Deliver attack-oriented professional services including penetration testing, red teaming, and social engineering for clients.
  • Author comprehensive assessment deliverables detailing technical execution, core deficiencies, and remediation strategies.
  • Contribute to practice development and marketing initiatives through research, speaking, and tool creation.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations minimize risk. The company has over 1,200 employees and focuses on a collaborative, enjoyable workplace atmosphere.

US

  • Design, build, and operate an AI-augmented red teaming harness using frontier LLM APIs.
  • Conduct adversarial testing across four attack perspectives to discover and chain vulnerabilities.
  • Assume ownership of security stage-gates within our CI/CD pipeline.

We provide a cloud-native platform called Silo that enables digital analysts to securely and anonymously investigate threats. We serve over 750 organizations and value integrity, collaboration, and innovation.

$160,000–$200,000/yr
Global Unlimited PTO

  • Lead a multifaceted security research team to develop new data collection prototypes and risk assessment methodologies.
  • Collaborate with product and engineering to align capability development roadmaps and transfer research prototypes to production.
  • Recruit, train, and develop an international team of security researchers with diverse backgrounds.

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk. With over 3,000 customers and 750+ teammates globally, they foster an inclusive culture that puts people first.

Indonesia

  • You will lead Ajaib's offensive security program and take a hands-on role in testing the resilience of our technology.
  • You will design and execute penetration tests, red-team exercises, and security assessments across mobile apps, APIs, cloud, and corporate environments.
  • You will partner with engineering and security teams to validate remediation and provide clear guidance to reduce risk without slowing delivery.

Ajaib is an Indonesian investment platform helping people access and manage investments across stocks, crypto, and US stocks. As a growing fintech company, we are committed to protecting our customers, products, and technology to maintain trust.

United States

  • Design, build, and operate an AI-augmented red teaming harness using advanced LLM APIs for autonomous vulnerability discovery.
  • Conduct adversarial testing across external, internal, and privileged perspectives, chaining and validating vulnerabilities.
  • Collaborate with DevSecOps, SOC, and engineering teams to improve security automation and detection workflows.

This company provides a cloud-based platform for highly security-conscious organizations. It fosters a remote-first culture focused on innovation, ownership, and continuous learning.

UK 5w PTO

  • Research and create defensive security labs and crisis simulation content for the platform.
  • Work with the Product team on innovations and deploy new features.
  • Compile technical research into clear content for both technical and non-technical audiences.

Immersive Labs provides a cyber resilience platform that simulates real-world threats to test skills and measure performance. Founded in 2017, the company has grown to over 300 employees globally, secured over £150 million in funding, and been voted a best place to work.

$180,000–$240,000/yr
Global Unlimited PTO

  • Develop and maintain a multi-platform implant in Rust for Windows, Linux, and macOS.
  • Build C2 infrastructure, post-exploitation modules, and AV/EDR evasion techniques.
  • Design network pivoting and tunneling capabilities, and write integration tests.

Horizon3 is a cybersecurity company that provides the NodeZero autonomous pentesting platform to help organizations find and fix exploitable attack vectors. They are a remote team of former U.S. Special Operations cyber operators and engineers, committed to a culture of respect, collaboration, and ownership.

US 4w PTO

  • Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
  • Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.

ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.

$235,000–$280,000/yr
US

  • Lead a team of Attack and Full-Stack Engineers to design and scale offensive capabilities for the NodeZero platform.
  • Drive external attack strategy across public-facing infrastructure, SaaS platforms, and enterprise software.
  • Partner with Product and Design to translate field insights into productized capabilities and roadmap.

Horizon3.ai is a fast-growing, remote cybersecurity company focused on enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. The team is a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, and results.

$160,000–$185,000/yr
US Unlimited PTO

  • Represent SpecterOps at industry conferences and events as a public-facing advocate.
  • Develop high-quality technical content such as blogs, tutorials, and videos to educate users.
  • Partner with the Community Manager to execute community growth initiatives and engagement campaigns.

SpecterOps is a cybersecurity company specializing in attack path management and open-source security tools like BloodHound. They are a remote-first organization with a focus on community engagement and employee growth, offering comprehensive benefits and a collaborative culture.

$152,000–$152,000/yr
US

  • You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
  • You will develop tools and scripts for capability analysis and inform detection strategies.
  • Your work directly enhances Dragos' ability to defend against advanced threats.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

India

  • Design, implement, and maintain secure network architectures, systems, and infrastructure to mitigate cyber security risks.
  • Evaluate, deploy, and configure security technologies including IDS/IPS, SIEM, IAM, and endpoint protection solutions.
  • Provide expert-level support for incident response and conduct forensic analysis to determine root cause and impact of security breaches.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence to organizations worldwide. With nearly 4,000 employees, Hyland fosters an employee-centric culture focused on career development, wellbeing, and community impact.