1

Salaried Exploit Development Jobs in Phoenix, AZ

Hands-on expertise analyzing malware, exploit kits, and adversary infrastructure. * A proven track ... Bonus Points * Strong scripting/development skills (Python, Go, C/C++) for automating malware ...

Salaried Exploit Development information

See Phoenix, AZ salary details

$8

$16

$24

How much do salaried exploit development jobs pay per hour?

As of Aug 29, 2026, the average hourly pay for salaried exploit development in Phoenix, AZ is $16.92, according to ZipRecruiter salary data. Most workers in this role earn between $14.33 and $19.09 per hour, depending on experience, location, and employer.

What is a salaried exploit developer?

A Salaried Exploit Developer is a cybersecurity professional who is employed by an organization to research, identify, and develop software exploits—ways to take advantage of vulnerabilities in computer systems or applications. Unlike freelance or independent security researchers, salaried exploit developers work as part of a security team, often within penetration testing firms, defense contractors, or tech companies. Their work can involve both offensive (discovering vulnerabilities to test defenses) and defensive (helping to patch or mitigate vulnerabilities) tasks. These roles require strong programming skills, a deep understanding of operating systems, and knowledge of security protocols. Salaried Exploit Developers may also be involved in responsible disclosure of vulnerabilities to affected vendors.

What are the key skills and qualifications needed to thrive as a salaried exploit developer?

To thrive as a Salaried Exploit Developer, you need deep expertise in computer science, reverse engineering, vulnerability analysis, and low-level programming, often backed by a degree in computer science or related field. Familiarity with tools like IDA Pro, Ghidra, debuggers, and operating system internals is crucial, and certifications such as OSCP or OSCE can be advantageous. Creativity, persistence, and strong problem-solving abilities are standout soft skills in this role. These qualifications are essential for identifying, developing, and responsibly handling software exploits in a secure and ethical manner.

What are some typical challenges encountered by professionals in salaried exploit development roles?

Professionals in salaried exploit development roles often face challenges such as staying current with rapidly evolving security technologies and patch cycles. They must continuously research new vulnerabilities and develop creative solutions to bypass updated security mechanisms, which can be highly demanding. Collaborating closely with security analysts and other developers is essential to ensure responsible disclosure and risk management. Additionally, balancing project deadlines with the need for meticulous testing and documentation can be a significant challenge in this field.

What is the difference between Salaried Exploit Development vs Penetration Tester?

AspectSalaried Exploit DevelopmentPenetration Tester
CredentialsSecurity certifications, programming skillsSecurity certifications, testing experience
Work EnvironmentResearch labs, security firms, internal teamsClient sites, corporate environments, consulting firms
Industry UsageCybersecurity, offensive securityCybersecurity, vulnerability assessment

Salaried Exploit Developers focus on creating and testing exploits for security research or defensive purposes, often working in labs or R&D settings. Penetration Testers simulate attacks to identify vulnerabilities in client systems. While both roles require security knowledge and technical skills, Exploit Developers primarily develop exploits, whereas Penetration Testers perform assessments and reporting. Understanding these differences helps clarify career paths and employer expectations in cybersecurity.

What are popular job titles related to Salaried Exploit Development jobs in Phoenix, AZ?

For Salaried Exploit Development jobs in Phoenix, AZ, the most frequently searched job titles are:

Infographic showing various Salaried Exploit Development job openings in Phoenix, AZ as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, and 3% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $35,184 per year, or $16.9 per hour.

Senior Vulnerability Management Analyst

Scottsdale, AZ • On-site

Advisor Group
Finance and Insurance • 1 - 5K employees

$105K - $120K/yr

Full-time

Medical, Dental, Vision, Retirement

Re-posted 24 days ago


Job description

Current Employees and Contractors Apply Here
Osaic Careers
IT Vulnerability Opportunity in Financial Services
Senior Vulnerability Management Analyst
Location(s):
Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339
La Vista:12325 Port Grace Blvd, La Vista, NE 68128
Oakdale: 7755 3rd St. N, Oakdale, MN 55128
Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255
St. Petersburg: 877 Executive Center Dr. W, Suite 300, St. Petersburg, FL 33702
Osaic has returned to the office on a hybrid schedule requiring a minimum of 4 days weekly in the office. Applicants should be located at one of our hubs listed above and must be willing to work this schedule.
Role Type: Full-time, Non-Exempt
Salary: $105,000 - $120,000 per year + annual performance-based bonus
Actual compensation offered will be determined individually, based on a number of job-related factors, including location, skills, licensure, experience, and education.
Our competitive compensation is just one component of Osaic's total compensation package. Additional benefits include health, vision, dental insurance, 401k, paid time away, volunteer days and much more. To view more details of what you can look forward to, visit our careers page: Osaic Benefits.
Summary:
We're seeking a Senior Vulnerability Analyst to lead and mature our enterprise vulnerability programs across SDLC (secure development lifecycle), external attack surface, and internal infrastructure/applications. This role drives end-to-end vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics, while partnering closely with Engineering, Product, Cloud/SRE, and IT. You'll also coordinate penetration testing readiness, evidence collection, and remediation plans, and help embed security into the development workflow. The ideal candidate has strong application development experience, practical threat modeling skills, and a pragmatic approach to risk.
Education Requirements:
Bachelor's degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.
Responsibilities:
  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross-team resolution.
  • Mentor junior analysts and help improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Help with pen test pre-work: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder comms.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internet-exposed services, DNS, certificates, cloud perimeters, API endpoints, and third-party exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement "shift-left" controls (pre-commit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for high-risk components (authN/Z, crypto, secrets handling, supply chain, multi-tenant boundaries).
  • All other duties as assigned.

Basic Requirements:
  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Preferred Requirements:
  • Experience with KEV catalog operationalization and threat-intel integrations.
  • Knowledge of automation platforms
Current Employees and Contractors Apply Here

Advisor Group logo

About Advisor Group

Sourced by ZipRecruiter

Be a part of the team behind our success! At Advisor Group, we support financial professionals nationwide, the people who help everyday Americans achieve their dreams. We're a billion-dollar business with the mentality and drive of a startup. Join us in building something special.

Industry

Finance and insurance

Company size

1,001 - 5,000 Employees

Headquarters location

Phoenix, AZ, US

Year founded

1988

Social media