Cobalt logo
CobaltPosted 3 weeks ago

Senior Security Researcher

$120,000–$150,000 year

RemoteUnited States

Full TimeSenior LevelMediumCybersecurity

Job Summary

Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, and cloud infrastructures including GCP, AWS, Azure, and Kubernetes. Identify high-impact vulnerabilities and develop proof-of-concept exploit techniques to demonstrate real-world risk, while collaborating with product and engineering teams to translate findings into scalable security assessment capabilities and automated testing workflows. Maintain industry-leading testing guidelines across emerging threat vectors and provide technical mentorship to junior researchers. Represent Cobalt in the security community through high-impact blog posts, advisories, and conference presentations such as DEF CON and Black Hat.

Required Qualifications

  • 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering
  • 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling
  • Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust)
  • Operating system security fundamentals (Linux/Windows/macOS internals)
  • Containerized cloud environments (Docker, Kubernetes, AWS/GCP)
  • Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation)
  • Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities
  • Ability to document complex technical findings into clear, actionable remediation guidance for engineers, product teams, and executive stakeholders
  • US-Based
  • EST or CST time zone alignment

Desired Qualifications

  • Familiarity with modern AI/ML security concepts, LLM risk models, and novel software integrations
  • Hands-on experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB debugging
  • Published CVEs, security advisories, or bug bounty hall-of-fame recognitions
  • Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist
  • Active contributions to open-source security tools or research projects

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce