Source Job

United States

  • Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capabilities and transition to a Continuous Threat Exposure Management model.
  • Conduct hands-on vulnerability research, technical analysis, and security validation to eliminate false positives, characterize exploitability, and provide actionable remediation guidance.
  • Partner across Information Security and engineering teams to evolve platforms, integrations, and automation for improved discovery, prioritization, and remediation outcomes.

Vulnerability Management Security Research Python Threat Intelligence

16 jobs similar to Senior Security Research Engineer

Jobs ranked by similarity.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

US 3w PTO

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Correlate vulnerability findings with threat intelligence, exploit availability, and operational risk to improve remediation prioritization.
  • Collaborate with incident responders, penetration testers, and security engineers to refine enterprise risk prioritization.

True Zero Technologies is a veteran-owned small business founded on the principle that enabling people and technology drives quality outcomes. We are a people-first company recognized as a Best Place to Work and on the Inc. 5000 list of fastest-growing companies.

$41–$51/hr
US

  • Own the vulnerability management program, prioritizing and driving a culture of ownership across business units.
  • Drive metrics and program review to transparently communicate performance and accountability.
  • Provide expert leadership to highly visible, multi-faceted projects while coordinating across teams and geographies.

We empower organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. We are based in San Francisco and New Hampshire, supported by General Catalyst and others, and we foster a diverse and inclusive culture.

India

  • Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
  • Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
  • Collaborate with engineering teams to communicate risks and drive remediation efforts.

This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

$120,000–$150,000/yr
US

  • Conduct advanced vulnerability research and security assessments across modern application and cloud stacks.
  • Develop proof-of-concept exploits and collaborate with cross-functional teams to strengthen customer security.
  • Provide mentorship to junior researchers and represent Cobalt in the security research community.

Cobalt provides offensive security testing via a SaaS platform and a community of over 400 vetted testers. The company is fully remote and values diversity and inclusion.

$121,000–$181,600/yr
United States Canada

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
  • Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

$78,300–$104,220/yr
Netherlands

  • Implement and enable Tenable's Exposure Management solutions to help organizations manage cyber risks.
  • Onboard Tenable technologies, following industry standards, to deliver customized solutions addressing vulnerabilities.
  • Provide consultative advice and build positive client relationships to ensure ongoing satisfaction and partnership.

Tenable is an exposure management company that helps organizations understand and reduce cyber risk. With over 40,000 clients globally, including 65% of the Fortune 500, the company fosters a culture of belonging, respect, and excellence.

$170,000–$170,000/yr
US

  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

US

  • Conduct vulnerability research and reverse engineering on diverse hardware and software targets.
  • Develop, test, and integrate cybersecurity tools and capabilities for critical missions.
  • Collaborate with specialized engineers to solve complex security challenges and shape next-generation solutions.

They are a cybersecurity firm focused on vulnerability research and development of advanced cyber capabilities for critical missions. They offer a collaborative environment with highly skilled professionals and significant autonomy for technical ownership.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

$129,280–$161,600/yr
US

  • Lead, coach, and develop a team of Security Consultants while driving operational excellence and process improvements.
  • Serve as a subject matter expert in application security, incident response, and vulnerability assessment, and handle complex escalations.
  • Build strong cross-functional partnerships and stay current on security industry standards to continuously improve team capabilities.

Bugcrowd is a crowdsourced security platform that empowers organizations to stay ahead of threat actors by uniting the ingenuity of elite hackers with our patented data and AI-powered Security Knowledge Platform. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst and Rally Ventures, and we foster a diverse, inclusive culture where we value perspectives from all backgrounds.

US

  • Perform incident response and forensic analysis of compromised systems, identifying and recommending remediation.
  • Formulate and direct incident response efforts, prioritizing actions and creating detailed reports on compromise vectors and attacker methodologies.
  • Build incident response plans, playbooks, and attack scenarios for customer tabletop exercises, maintaining sandbox environments to evaluate malicious code.

Check Point Software Technologies is the world's leading vendor of cyber security, facing sophisticated threats and attacks. Honored by Time Magazine as one of the World's Best Companies and on Forbes' list of the World's Best Places to Work, we have a global team of driven and innovative people.