Senior Security Researcher
$220,000–$220,000 year
RemoteAnn Arbor, Michigan, United States
Job Summary
Drive product capability by bringing an offensive practitioner's perspective to Censys's scanning, fingerprinting, and attack surface data to identify gaps in detection logic and protocol coverage. Conduct original research investigating emerging attack techniques, exploitation trends, and adversary tradecraft using Internet-wide scan data and your own testing methodology. Publish seminal work including research reports, technical blog posts, and conference-caliber material to establish Censys as an authoritative voice in offensive security. Collaborate cross-functionally with Engineering and Product to translate findings into new scanning modules, fingerprints, and detection features. Lead agentic AI threat research by building, deploying, and evaluating autonomous penetration testing agents and LLM-powered vulnerability research tools. Track adversary infrastructure to identify how threat actors configure and hide systems, encoding that knowledge into repeatable detection logic. Mentor internal teams as a subject-matter expert on offensive techniques. This role is remote with quarterly travel and offers a salary range of $202,000–$278,000 USD plus bonus and equity.
Required Qualifications
- 5+ years of hands-on penetration testing, red teaming, or adversary emulation experience against enterprise, cloud, or Internet-facing environments
- Demonstrated ability to independently identify and characterize vulnerabilities, misconfigurations, or exploitation techniques
- Strong understanding of network protocols, service fingerprinting, and Internet-scale scanning concepts (or a fast ability to pick them up)
- Hands-on experience with agentic systems for offensive security
- Proficiency in scripting or coding (Python, Go, or similar) to build tooling, automate testing, or analyze large datasets
- Familiarity with red team frameworks and tradecraft (C2 frameworks, initial access techniques, living-off-the-land methods, evasion)
- Comfort working with large-scale Internet scan data or a strong interest in learning to do so
- Must be able to travel once per quarter for industry events and team onsites
- Must be available for remote work with no expectation to work from a Censys office
- Demonstrates curiosity, a willingness to learn, and sound judgment in applying AI
Desired Qualifications
- Relevant certifications (OSCP, OSCE, OSEP, GXPN, or equivalent demonstrated skill)
- Experience with IoT, OT/ICS, or embedded device security research
- Prior work as a researcher at a security vendor
- Evidence of research/tooling contributions to the agentic offensive space (e.g., benchmarks, PoCs, AI-assisted vulnerability discoveries) and demonstrated agentic AI red teaming work (e.g., Microsoft's PyRIT, the Cloud Security Alliance's Agentic AI Red Teaming Guide, or equivalent tooling and methodology)
- A track record of public research output — CVEs, conference talks, technical blog posts, or tool releases — that shows you can communicate findings clearly to a technical audience
- Familiarity with compliance-adjacent security testing (e.g., how pentest findings map to SOC 2, ISO 27001, or CMMC control requirements)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.