1

Security Research Jobs (NOW HIRING)

Security Research Engineer

New York, NY ยท On-site

$120K - $175K/yr

We are seeking a Security Research Engineer to operate as a hybrid Forward Deployed Engineer and offensive security researcher. You'll be on the front lines of customer engagements - using our open ...

This manager position will be tasked with building out a multifaceted security research team that addresses a broad range of Bitsight's strategic technical challenges. This role will be ideally ...

Security Research Internship

New York, NY ยท On-site +1

$3.0K - $8.0K/mo

About the role We are seeking security research interns to join a top-notch security research team. We are working on a wide range of security research topics, including malware analysis ...

The Research Architect for Dynamic Application Security Testing (DAST) is responsible for overseeing the security capabilities of Veracode's dynamic scanner offerings. Responsibilities ยท Conduct ...

Security Research Internship

New York, NY ยท Remote

$3.0K - $8.0K/mo

About the role We are seeking security research interns to join a top-notch security research team. We are working on a wide range of security research topics, including malware analysis ...

The Research Architect for Dynamic Application Security Testing (DAST) is responsible for overseeing the security capabilities of Veracode's dynamic scanner offerings. Responsibilities โ€ข Conduct ...

Security Research Engineer

Fulton, MD ยท On-site

$135K - $195K/yr

Security research includingMalwareanalysis andThreat Detectionmitigation. * Researchroot cause and input conditions related toa vulnerability. * Writedetailed technical reports, summaries, and ...

Translate research into usable outcomes for engineering and security teams, including proof-of-concept demonstrations, benchmarks, technical guidance, mitigations, and secure-by-design ...

next page

Showing results 1-20

Security Research information

See salary details

$47

$51

$54

How much do security research jobs pay per hour?

As of Jul 27, 2026, the average hourly pay for security research in the United States is $51.44, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $53.12 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What are some common challenges faced by professionals in Security Research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.
More about Security Research jobs
What cities are hiring for Security Research jobs? Cities with the most Security Research job openings:
What states have the most Security Research jobs? States with the most job openings for Security Research jobs include:
Infographic showing various Security Research job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 88% Full Time, 10% Part Time, and 1% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $107,000 per year, or $51.4 per hour.

Security Research Engineer

Pensar

New York, NY โ€ข On-site

$120K - $175K/yr

Full-time

Medical, Dental, Vision

Posted 24 days ago


Job description

We are seeking a Security Research Engineer to operate as a hybrid Forward Deployed Engineer and offensive security researcher. You'll be on the front lines of customer engagements - using our open source tool Apex to run pentests, curate and present findings, and stand up our platform inside customer environments. In parallel, you'll drive original offensive and open source security research, and feed everything you learn in the field back into the product so Pensar keeps getting sharper as a pentesting platform.
This role is customer-facing by design. The ideal candidate is equally comfortable in a terminal popping shells with Apex, on a Zoom with a CISO walking through findings, and in a design review arguing for the next product capability.
Key Responsibilities
Customer Engagements & Forward Deployed Work
  • Run end-to-end pentest engagements for customers using Apex, our open source offensive security tool
  • Curate, triage, and contextualize findings for customer audiences ranging from engineers to executives
  • Deliver clear, prioritized write-ups and walk customers through results, exploitation paths, and remediation
  • Set up and configure the Pensar platform inside customer environments, including integrations and workflows
  • Act as a trusted technical partner for customers throughout onboarding, engagements, and ongoing usage
  • Travel to customer sites as needed for kickoffs, readouts, and on-site testing
Offensive Security Research
  • Conduct original offensive security research across web, cloud, infrastructure, and AI/LLM attack surfaces
  • Develop new exploitation techniques, payloads, and tooling that extend Apex's capabilities
  • Build automated testing methodologies for emerging vulnerability classes and attacker tradecraft
  • Track the evolving threat landscape and translate it into concrete detections and capabilities
Open Source Security Research
  • Lead vulnerability research across high-impact open source projects and ecosystems
  • Verify findings, build proof-of-concept exploits, and coordinate responsible disclosure with maintainers
  • Contribute patches, advisories, and tooling back to the open source community
  • Grow Pensar's reputation in the security research community through publications, talks, and contributions
Product Feedback & Pentesting Roadmap
  • Translate firsthand engagement experience into concrete recommendations for the product roadmap
  • Partner with engineering and product on capabilities, UX, and automation that make pentesting faster and more reliable
  • Participate in architecture and design reviews with a focus on the pentester's workflow
  • Help shape Apex's direction as an open source project alongside the internal platform
Compensation
  • Base salary: $120,000 - $175,000 per year, depending on experience
  • Meaningful equity in an early-stage offensive security company
  • Final offers calibrated to depth of offensive security experience, the breadth of your research record, and the level you join at
Reports To
CEO / CTO
We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.
Requirements
  • 5+ years of experience in offensive security, pentesting, red teaming, or vulnerability research
  • Strong programming skills in multiple languages (Python, Go, JavaScript, C/C++)
  • Deep, hands-on understanding of modern vulnerability classes across web, cloud, and infrastructure
  • Proven track record of running pentest engagements end-to-end and delivering findings to customers
  • Excellent customer-facing communication skills - comfortable presenting to both engineers and executives
  • Experience contributing to or maintaining open source security tooling
  • Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience
Preferred Qualifications
  • Experience with AI/LLM-assisted offensive security or building security automation on top of LLMs
  • Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or developer tools company
  • Security certifications (OSCP, OSCE, OSWE, GXPN, or equivalent)
  • Public security research, CVEs, conference talks, or notable open source contributions
  • Experience with cloud security (AWS, GCP, Azure) and containerized environments
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting

Benefits
  • Comprehensive health, dental, and vision insurance
  • Direct ownership of customer engagements and offensive research at an early-stage security company
  • Professional development budget for conferences, training, and certifications
  • Support for publishing research and presenting at industry conferences
  • Direct, visible impact on both our open source tooling and commercial platform