1

Offensive Security Researcher Jobs (NOW HIRING)

This role blends hands-on offensive security, GenAI attack simulation, security engineering, and ... Stay current on GenAI security research, adversarial ML techniques, evolving threat intelligence ...

You'll work closely with our security researchers, AI engineers, and product engineers to turn offensive security techniques into reliable autonomous capabilities. When an agent fails to find a ...

The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next ...

The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next ...

Senior Security Researcher (Red Team)

$117K - $160K/yr

This role blends hands-on offensive security, GenAI attack simulation, security engineering, and ... Stay current on GenAI security research, adversarial ML techniques, evolving threat intelligence ...

Senior Security Researcher

$117K - $160K/yr

Operating within Cobalt's Offensive Security Research team, you will bridge the gap between cutting-edge adversary tradecraft, platform-driven security testing, and actionable remediation guidance.

Qualifications * 3+ years of full-time experience in security research, offensive security, or related fields. * Experience with finding vulnerabilities in source code * Experience creating PoC ...

What you'll bring * 10+ years of experience in security research, penetration testing, or offensive security roles * Strong ability in discovering and exploiting vulnerabilities in large codebase and ...

What you'll bring * 7+ years of experience in security research, penetration testing, or offensive security roles * Hands-on experience discovering and exploiting vulnerabilities. * Be a subject ...

We are seeking candidates with a passion for offensive security, deep technical expertise in ... security research, and participation in relevant industry groups. * Contribute to the continuous ...

Showing results 21-40

Offensive Security Researcher information

See salary details

$47

$51

$54

How much do offensive security researcher jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for offensive security researcher in the United States is $51.44, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $53.12 per hour, depending on experience, location, and employer.

What is an offensive security researcher?

Offensive Security Researchers are cybersecurity professionals who identify, analyze, and exploit vulnerabilities in software, systems, or networks to help organizations strengthen their security. They perform penetration testing, vulnerability assessments, and develop attack simulations to uncover weaknesses before malicious hackers can exploit them. Their work often involves staying updated on the latest threats and attack techniques, as well as creating tools or proof-of-concept exploits to demonstrate potential risks. By thinking like attackers, they help organizations proactively protect their assets and data.

What are the key skills and qualifications needed to thrive as an offensive security researcher, and why are they important?

To thrive as an Offensive Security Researcher, you need a deep understanding of cybersecurity principles, penetration testing, vulnerability research, and programming, typically supported by a degree in computer science or related certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, IDA Pro, and scripting languages like Python is essential for identifying and exploiting security flaws. Analytical thinking, creativity, and strong written and verbal communication skills help researchers document findings and collaborate with teams. These skills are crucial for proactively uncovering vulnerabilities and strengthening organizational security before malicious actors can exploit weaknesses.

What types of collaboration can an offensive security researcher expect with other teams in an organization?

Offensive Security Researchers frequently collaborate with various teams, including incident response, software development, and IT operations. They share their findings about vulnerabilities and attack techniques, helping to inform security improvements and incident mitigation strategies. Regular interaction with development teams is common to ensure secure coding practices, while partnerships with security operations help prioritize threats and remediation efforts. This collaborative environment not only enhances the organization's security posture but also provides researchers with a broader perspective and learning opportunities.

What is the difference between Offensive Security Researcher vs Penetration Tester?

AspectOffensive Security ResearcherPenetration Tester
CertificationsOSCP, OSWE, GPENOSCP, CEH, GPEN
Work EnvironmentResearch-focused, developing exploits, analyzing vulnerabilitiesClient engagement, conducting security assessments
Industry UsageSecurity firms, research labs, product companiesConsulting firms, security service providers

While both roles involve identifying security weaknesses, Offensive Security Researchers focus on discovering new vulnerabilities and developing exploits in a research setting. Penetration Testers typically perform simulated attacks on client systems to evaluate security posture. The roles overlap in skills and certifications but differ mainly in scope and environment.

What cities are hiring for Offensive Security Researcher jobs?

Cities with the most Offensive Security Researcher job openings:

What states have the most Offensive Security Researcher jobs?

States with the most job openings for Offensive Security Researcher jobs include:

What are popular job titles related to Offensive Security Researcher jobs?

For Offensive Security Researcher jobs, the most frequently searched job titles are:

Infographic showing various Offensive Security Researcher job openings in the United States as of September 2026, with employment types broken down into 60% Full Time, and 40% Contract. Highlights an 60% In-person, and 40% Remote job distribution, with an average salary of $107,000 per year, or $51.4 per hour.

Senior Security Researcher (Red Team)

Remote

Pindrop
Network Security • 201 - 500 employees

Full-time

Dental, Vision, PTO

Re-posted 11 days ago


Job description

Who We Are
Pindrop is the Real Human + Right Human® Identity Trust Platform for the AI era. As AI-driven fraud and deepfakes erode trust in digital communication, Pindrop delivers continuous identity verification and deepfake detection across voice, video, and digital interactions in real time.
Enterprises rely on Pindrop to secure billions of high-risk customer interactions each year, including top U.S. banks, as well as leading insurers and healthcare providers. Powered by models trained on more than 1.5 billion real-world interactions annually and protected by 300+ patents, Pindrop restores trust while reducing fraud, lowering operational costs, and improving customer experience.
Recognized by TIME as one of the Top 10 Most Influential Software Companies of 2026 and by Inc. for Best in Business for Innovation, Pindrop is backed by leading investors including Andreessen Horowitz, IVP, and CapitalG.
What you'll do
As a Senior Security Researcher (Red Team), you will help Pindrop proactively identify and exploit weaknesses across product, cloud, and AI-powered systems so we can strengthen defenses before adversaries do. This role blends hands-on offensive security, GenAI attack simulation, security engineering, and operational partnership with blue-team, product, and AI/ML stakeholders.
  • Design and execute red team operations against Pindrop's GenAI systems, LLM pipelines, RAG architectures, autonomous agents, APIs, SaaS products, and cloud environments, simulating real-world attacks across both traditional and AI-specific attack surfaces.
  • Conduct adversarial testing focused on prompt injection, indirect prompt attacks, jailbreaking, model extraction, training-data poisoning, data leakage, inference abuse, and unauthorized output manipulation.
  • Use deepfake generation, voice synthesis, and related spoofing techniques to test and attempt to defeat Pindrop's voice authentication and deepfake detection capabilities, helping identify model robustness and detection gaps.
  • Develop novel attack chains that combine GenAI vulnerabilities with infrastructure, application, identity, and API weaknesses to create realistic end-to-end threat scenarios.
  • Plan and execute full-scope penetration tests and support bug bounty efforts across Pindrop's web applications, APIs, SaaS products, and AWS/GCP environments using commercial and open-source offensive tooling.
  • Perform architecture reviews, security code reviews, and threat modeling with emphasis on vulnerabilities introduced by AI/ML components, model integrations, and LLM-facing services.
  • Build automation for offensive security workflows, testing, compliance checks, alerting, and reporting using Python or similar scripting languages, including AI-native attack tooling where useful.
  • Partner closely with SecOps and security engineering to improve detections, tune response workflows, and translate red team findings into practical remediation and defensive improvements.
  • Stay current on GenAI security research, adversarial ML techniques, evolving threat intelligence, and relevant regulatory developments, then apply those insights to Pindrop's security program.
Who you are
  • You are an adversarial thinker who approaches security from an attacker's perspective and brings the creativity, rigor, and curiosity to prove it.
  • You have genuine hands-on experience attacking AI systems, not just reading about them, and you enjoy breaking assumptions that others consider safe.
  • You continuously look for automation and AI-powered efficiencies in offensive security workflows.
  • You communicate clearly and can translate technical findings into prioritized, actionable guidance for technical and executive audiences alike.
  • You work independently and thrive in ambiguous, fast-moving environments with minimal supervision.
  • You are resilient, optimistic, accountable, and adaptable when priorities shift.
Your skill-set
Must-haves
  • 3+ years of hands-on penetration testing and red team experience across SaaS applications, cloud infrastructure, APIs, and web applications.
  • Demonstrable experience attacking GenAI or LLM-based systems, including prompt injection, jailbreaking, indirect prompt attacks, model extraction, or adversarial input generation.
  • Hands-on experience with deepfake tools, voice synthesis, or audio/visual spoofing technologies in an offensive or research context.
  • Strong proficiency with offensive security tooling such as Burp Suite, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, or equivalent frameworks.
  • Experience configuring and operating SAST and DAST tools and integrating them into CI/CD pipelines.
  • Proficiency in at least one scripting or programming language, with Python strongly preferred, for custom attack tooling and workflow automation.
  • Familiarity with AI-specialized security tools or frameworks such as Garak, PyRIT, Claude Security, or similar adversarial ML tooling.
  • Strong understanding of cloud security architecture, container security, API security, and common security standards including ISO 27001/27002, NIST, CIS, PCI DSS, OWASP, and SOC 2.

Nice-to-haves
  • Prior software development or secure architecture experience, including the ability to reason about production code across multiple languages.
  • Research, publication, or deep practitioner background in adversarial machine learning, LLM security, or voice/audio deepfake detection.
  • Relevant certifications such as OSCP, GPEN, GWAPT, GXPN, CEH, or equivalent.
  • Prior experience in voice biometrics, AI security, fraud prevention, or similarly high-risk product environments.
What's in it for you
As a Pindropper, you'll join a rapidly growing company making technology more human with the power of voice. You'll help shape how Pindrop attacks and defends modern AI-enabled systems, working at the intersection of offensive security, GenAI, deepfake defense, and cloud security. Your work will have direct impact on how we protect voice identity and high-trust customer interactions. You'll work alongside a passionate, high-performing team committed to excellence and enjoying the journey together.
What we offer
As a part of Pindrop, you'll have a direct impact on our growing list of products and the future of security in the voice-driven economy. We hire great people and take care of them. Here's a snapshot of the benefits we offer:
  • Competitive compensation package, including RSUs (Restricted Stock Units) for all employees, so everyone shares in our long-term success.
  • Remote-first environment - giving you flexibility and autonomy in how you structure your day.
  • While we work flexibly, we prioritize meaningful in-person moments through regular team on-sites, company-wide events, and intentional gatherings that foster connection, collaboration, and shared success.
  • Unlimited Paid Time Off (PTO)
  • Generous health and welfare plans to choose from - including one employer-paid "employee-only" plan!
  • Best-in-class Health Savings Account (HSA) employer contribution
  • Low-cost vision and dental plans for you and your family, providing comprehensive coverage and peace of mind.
  • Paid Parental Leave - Including birth, adoptive & foster parents
    • One year of diaper delivery for your newest addition to the family! It's our way of welcoming new Pindroplets to the family!
  • Recurring monthly phone and internet allowance to help cover essential connectivity costs and support flexible work.
  • Enhanced fertility and GLP-1 benefits to support family-building journeys and personalized health needs.
  • Annual Learning & Development stipend to support your professional growth, skill-building, certifications, and continued education.

#LI-Remote
Please note that the base pay range is a general guideline only. Pindrop considers factors such as (but not limited to) scope and responsibilities of the position, a candidate's work experience, education/training, and key skills, as well as market and business considerations, when extending an offer.
US Base Pay Range
$125,000-$165,000 USD
Not sure if this is you?
We want a diverse, global team, with a broad range of experience and perspectives. If this job sounds great, but you're not sure if you qualify, apply anyway! We carefully consider every application and will either move forward with you, find another team that might be a better fit, keep in touch for future opportunities, or thank you for your time.
AI - A Transformative Force
At Pindrop, we view artificial intelligence as a transformative force that, when harnessed responsibly, can unlock unprecedented value for our customers, partners and society and enable and empower us to continue to deliver cutting-edge technology to combat fraud and unblur the lines between what it means to be human versus machine.
Pindrop may use AI tools to help prioritize job applications for human review. The AI tool may analyze your work experience and skills to assess fit for the role, but does not consider your name or contact details. Applications with the strongest match to job requirements are prioritized for human review; not all applications may be individually reviewed.
Pindrop is an Equal Opportunity Employer
Here at Pindrop, it is our mission to create and maintain a diverse and inclusive work environment. As an equal opportunity employer, all qualified applicants receive consideration for employment without regard to race, color, age, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetic information, disability, marital and/or veteran status.