Senior Security Researcher
$120,000–$150,000 year
RemoteUnited States
Job Summary
Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, and cloud infrastructures including GCP, AWS, Azure, and Kubernetes. Identify high-impact vulnerabilities and develop proof-of-concept exploit techniques to demonstrate real-world risk, while collaborating with product and engineering teams to translate findings into scalable security assessment capabilities and automated testing workflows. Maintain industry-leading testing guidelines across emerging threat vectors and provide technical mentorship to junior researchers. Represent Cobalt in the security community through high-impact blog posts, advisories, and conference presentations such as DEF CON and Black Hat.
Required Qualifications
- 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering
- 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling
- Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust)
- Operating system security fundamentals (Linux/Windows/macOS internals)
- Containerized cloud environments (Docker, Kubernetes, AWS/GCP)
- Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation)
- Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities
- Ability to document complex technical findings into clear, actionable remediation guidance for engineers, product teams, and executive stakeholders
- US-Based
- EST or CST time zone alignment
Desired Qualifications
- Familiarity with modern AI/ML security concepts, LLM risk models, and novel software integrations
- Hands-on experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB debugging
- Published CVEs, security advisories, or bug bounty hall-of-fame recognitions
- Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist
- Active contributions to open-source security tools or research projects
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.