1

Independent Security Researcher Jobs (NOW HIRING)

... research, web security, cryptography, and/or reverse engineering--people who can find bugs no one ... A healthy dose of skepticism and the ability to think independently and critically * An interest in ...

Senior Security Researcher

Ann Arbor, MI ยท On-site

$202 - $278/hr

As a Security Security Researcher, you'll have the opportunity to work at the intersection of large ... Demonstrated ability to independently identify and characterise vulnerabilities, misconfigurations ...

You work independently and thrive in ambiguous, fast-moving environments with minimal supervision ... research context. * Strong proficiency with offensive security tooling such as Burp Suite, OWASP ...

... Senior Security Researcher to join our Counter Adversary Operations Team. This position will ... Ability to work as part of a team, as well as self-motivation to collect independently and ...

Vulnerability Researcher

Dayton, OH ยท On-site

$84K - $126K/yr

Participation in CTFs or evidence of independent security research projects. #LI-ZS1 #HYBRID Two Six Technologies is committed to providing competitive and comprehensive compensation packages that ...

Vulnerability Researcher

Dayton, OH ยท On-site

$84K - $126K/yr

Participation in CTFs or evidence of independent security research projects. #LI-ZS1 #HYBRID Two Six Technologies is committed to providing competitive and comprehensive compensation packages that ...

next page

Showing results 1-20

Independent Security Researcher information

See salary details

$47

$51

$54

How much do independent security researcher jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for independent security researcher in the United States is $51.44, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $53.12 per hour, depending on experience, location, and employer.

What is an independent security researcher?

An independent security researcher is a professional who investigates and analyzes computer systems, networks, and software for vulnerabilities, often working outside of formal employment with a company or organization. These researchers typically identify security flaws, report them to affected parties, and may participate in bug bounty programs or publish their findings for public awareness. They play a vital role in the cybersecurity ecosystem by helping to uncover and address security weaknesses before malicious actors can exploit them.

What are the key skills and qualifications needed to thrive as an independent security researcher, and why are they important?

To thrive as an Independent Security Researcher, you need a deep understanding of cybersecurity principles, vulnerability assessment, and programming or scripting languages, often supported by a relevant degree or recognized certifications like OSCP or CEH. Familiarity with penetration testing tools (e.g., Metasploit, Burp Suite), operating systems, and responsible disclosure processes is essential. Critical thinking, persistence, and effective communication help researchers uncover vulnerabilities and share findings responsibly. These skills are crucial to identifying security weaknesses, protecting systems, and building trust within the cybersecurity community.

What are some common challenges independent security researchers face when working with organizations to disclose vulnerabilities?

Independent Security Researchers often encounter challenges such as varying responsiveness from organizations, legal ambiguity regarding responsible disclosure, and the need to clearly communicate technical findings to non-technical stakeholders. Establishing trust and credibility is essential, as some companies may initially be skeptical or unresponsive to external reports. Researchers must also stay current with evolving disclosure policies and frameworks to ensure their work is ethical and recognized, which often involves participating in bug bounty programs or coordinated vulnerability disclosure platforms.

What is the difference between Independent Security Researcher vs Penetration Tester?

AspectIndependent Security ResearcherPenetration Tester
CertificationsOSCP, CEH, CISSPOSCP, CEH, GPEN
Work EnvironmentSelf-directed, often freelance or contract-basedTypically employed by security firms or organizations
Industry UsageResearching vulnerabilities, discovering exploits, publishing findingsSimulating attacks to test security defenses

While both roles focus on cybersecurity, Independent Security Researchers primarily discover and analyze vulnerabilities independently, often publishing their findings. Penetration Testers conduct controlled security assessments for organizations, focusing on exploiting vulnerabilities to evaluate defenses. Both roles require similar certifications and skills but differ in work setting and objectives.

How do you become an independent security researcher?

To become an independent security researcher, develop strong knowledge of cybersecurity principles, programming, and networking, often through self-study, online courses, or formal education. Gaining experience with security tools, participating in bug bounty programs, and building a portfolio of research can help establish credibility and attract opportunities.
More about Independent Security Researcher jobs
Infographic showing various Independent Security Researcher job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $107,000 per year, or $51.4 per hour.

Security Researcher

Zellic

Manhattan, NY โ€ข On-site

Other

Posted 22 days ago


Job description

Vulnerability Research Position

We're looking for individuals with exceptional talent in vulnerability research, web security, cryptography, and/or reverse engineeringโ€”people who can find bugs no one else can.

We do the best security reviews in the world. Our clients include Polymarket, Canonical, Protonmail, Cognition, and the Solana Foundation. Before Zellic, we previously founded perfect blue, the #1 CTF team in 2020, 2021, and 2023 as part of Blue Water.

We are an employee-owned company. We're consistently profitable, with a team of 50+ and growing (mostly CTF players). We value steady, long-term success over short-term gains.

What You'll Do

You'll work alongside the best hackers in the world. Day-to-day, that means:

  • Auditing client code across a wide range of challenging targetsโ€”compilers, virtual machines, web apps, databases, circuits, proof systems, and more
  • Writing clear, professional reports that explain vulnerabilities and their impact
  • Keeping up with new attacks, techniques, and research
  • Contributing to Zellic's public research through blog posts and, optionally, conference talks
Qualifications

You should be strong in at least one of these areas:

  • Pwn. Finding and exploiting vulnerabilities in native software. You know the AFL++ command line parameters by heart. We especially value browser exploitation, kernel exploitation, or virtual machine escapes.
  • Web. Breaking web applications. You believe CSP stands for "Client Side Puzzle". You find and abuse logic bugs and design flaws. You have a track record as a bug bounty veteran.
  • Cryptography. Attacks, protocol design, and secure implementation. You enjoy diving into and reimplementing a paper. Strong math background paired with broad knowledge of important primitives. Knowledge of hash-based crypto or lattices is a plus.
  • Reverse Engineering. Decompilation, program analysis, formal methods, and programming languages. You love Z3 and SSA form. You can take apart anything and aren't afraid to tackle an obfuscated VM.
  • Misc. You intimidate software into finding bugs in itself, simply by looking at it.

Other Nice-To-Haves

  • A healthy dose of skepticism and the ability to think independently and critically
  • An interest in finance or blockchain is welcome but not required. Many of our hires have no prior blockchain experience.
What You'll Like About Us
  • Ask your friends. You probably know someone who's working or has worked here.
  • Flexible hours, remote work, and both full-time and part-time opportunities. We have a NYC office you can visit as much (or as little) as you'd like.
  • Competitive salaries, with two major bonuses per year
  • Direct equity participation
  • Paid travel to two security conferences per year
  • A complete benefits package. Among other perks, our team enjoys multiple fully-funded offsites each year. Past locations include Japan, France, and Bali.

Full-time roles include all of the above. Benefits vary for part-time roles.