Source Job

$120,000–$150,000/yr
US

  • Conduct advanced vulnerability research and security assessments across modern application and cloud stacks.
  • Develop proof-of-concept exploits and collaborate with cross-functional teams to strengthen customer security.
  • Provide mentorship to junior researchers and represent Cobalt in the security research community.

Penetration Testing Reverse Engineering Python Cloud Security

18 jobs similar to Senior Security Researcher

Jobs ranked by similarity.

Global

  • Conduct advanced offensive security research across cloud infrastructure (AWS, GCP), production services, internal tooling, and AI platforms.
  • Design and execute realistic adversary simulations targeting identity systems, cloud control planes, supply chains, and distributed architectures.
  • Research emerging attack vectors against LLMs, AI agents, retrieval systems, MCP integrations, prompt orchestration, and autonomous workflows.

This venture-backed AI company combines world-class human expertise with advanced machine learning workflows to help leading AI organizations build and improve cutting-edge models. Backed by over $40 million in funding and a rapidly expanding international network, it operates as a distributed, remote-first team.

$202,000–$278,000/yr
US Unlimited PTO

  • Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data.
  • Conduct original research on emerging attack techniques using Internet-wide scan data and publish findings at major conferences.
  • Collaborate with engineering and product teams to translate research into new scanning modules, fingerprints, and detection features.

Censys provides real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide. The company values collaboration, innovation, and impact, with a team of world-class researchers and engineers.

UK

  • Lead and mentor an internal red team, establishing scalable offensive security practices.
  • Conduct advanced penetration testing and adversarial simulations across cloud infrastructure and AI environments.
  • Research emerging attack techniques and collaborate with detection teams during purple team exercises.

They operate a cutting-edge cloud platform that supports advanced AI workloads. The company is remote-first, emphasizes innovation and continuous improvement, and has a collaborative international team.

$155,520–$228,700/yr
US

  • Perform full-stack penetration testing of web applications, APIs, and mobile apps.
  • Conduct internal/external network audits and vulnerability validation.
  • Develop custom exploits, adversary emulation, and AI/LLM security testing.

Twilio is shaping the future of communications by delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide. The company values a remote-first work culture, global inclusion, and diverse experiences.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

Indonesia

  • You will lead Ajaib's offensive security program and take a hands-on role in testing the resilience of our technology.
  • You will design and execute penetration tests, red-team exercises, and security assessments across mobile apps, APIs, cloud, and corporate environments.
  • You will partner with engineering and security teams to validate remediation and provide clear guidance to reduce risk without slowing delivery.

Ajaib is an Indonesian investment platform helping people access and manage investments across stocks, crypto, and US stocks. As a growing fintech company, we are committed to protecting our customers, products, and technology to maintain trust.

US

  • Lead the maturation of Delinea's Offensive Security program, including penetration testing and red teaming operations.
  • Manage a team of penetration test engineers, set performance objectives, and provide mentorship.
  • Collaborate with Product Development, DevOps, IT, and SecOps to test security controls and report findings to technical and executive audiences.

Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to govern interactions across the modern enterprise. The company is a global, passionate team backed by TPG, valuing diversity, innovation, and a culture of respect and fairness.

US Unlimited PTO

  • Lead end-to-end penetration testing and red team engagements for customer environments including internal networks, web applications, and cloud infrastructure.
  • Perform in-depth testing with manual techniques to find business-logic flaws and high-impact attack chains that automated tools miss.
  • Deliver high-quality client-ready reports with clear risk ratings, business impact, and practical remediation guidance.

Horizon3 is a fast-growing cybersecurity company whose NodeZero platform delivers autonomous pentests and assessment operations for organizations of all sizes. The team is a fusion of former U.S. Special Operations cyber operators, startup engineers, and cybersecurity practitioners, committed to a culture of respect, collaboration, ownership, and results.

US 4w PTO

  • Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
  • Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
  • Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.

ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

UK Unlimited PTO

  • Design and build scalable backend systems, APIs, and data pipelines for the vulnerability intelligence platform.
  • Own services end-to-end including architecture, development, deployment, and operation.
  • Lead technical design discussions and contribute to system architecture decisions while mentoring junior engineers.

VulnCheck transforms vulnerability intelligence by helping security teams act faster with more confidence. Founded in 2021, the company has a transparent, collaborative, and supportive culture with a fast-growing team of experts.

US Unlimited PTO

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
  • Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
  • Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.

Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.

United States

  • Design, build, and operate an AI-augmented red teaming harness using advanced LLM APIs for autonomous vulnerability discovery.
  • Conduct adversarial testing across external, internal, and privileged perspectives, chaining and validating vulnerabilities.
  • Collaborate with DevSecOps, SOC, and engineering teams to improve security automation and detection workflows.

This company provides a cloud-based platform for highly security-conscious organizations. It fosters a remote-first culture focused on innovation, ownership, and continuous learning.

Germany

  • Perform penetration tests of IT infrastructures, web applications, and web services.
  • Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
  • Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.

SITS Deutschland GmbH is part of the SITS Group, a leading IT security provider offering holistic security solutions. The company has over 700 employees and fosters a culture of appreciation, team spirit, and work-life blending.

$201,300–$352,300/yr
Americas Unlimited PTO

  • Lead deep-dive investigations and coordinate resolution across engineering teams during significant security events.
  • Drive coordinated response across releases, balancing risk and remediation feasibility to reduce exposure window.
  • Author postmortems and drive continuous improvement after product security incidents.

ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter. They foster an AI-native culture with a focus on innovation, flexibility, and trust.

$235,000–$280,000/yr
US

  • Lead a team of Attack and Full-Stack Engineers to design and scale offensive capabilities for the NodeZero platform.
  • Drive external attack strategy across public-facing infrastructure, SaaS platforms, and enterprise software.
  • Partner with Product and Design to translate field insights into productized capabilities and roadmap.

Horizon3.ai is a fast-growing, remote cybersecurity company focused on enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. The team is a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, and results.

$190,000–$319,000/yr
US

  • Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
  • Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
  • Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.

Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.