1

Security Research Jobs in California (NOW HIRING)

Required : • 3+ years of full-time experience in security research, offensive security, or related fields. • Experience with finding vulnerabilities in source code • Experience creating PoC ...

Security Researcher

San Francisco, CA · On-site

  • Medical

  • Dental

  • Vision

Qualifications * 3+ years of full-time experience in security research, offensive security, or related fields. * Experience with finding vulnerabilities in source code * Experience creating PoC ...

Offensive Security Researcher, SEAR

Cupertino, CA

$184K - $324K/yr

  • Medical

  • Dental

  • Retirement

Apple's Security Engineering & Architecture (SEAR) organization is responsible for the security of ... You will conduct offensive research into AI-specific attack classes, including prompt injection ...

next page

Showing results 1-20

Security Research information

See California salary details

$46

$50

$53

How much do security research jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for security research in California is $50.77, according to ZipRecruiter salary data. Most workers in this role earn between $49.09 and $52.45 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What are some common challenges faced by professionals in security research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

How much do security researchers make?

Security researchers typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, location, and certifications. Entry-level positions may start lower, while experienced professionals with specialized skills or certifications like CISSP can earn higher salaries. Salaries can also vary based on the industry and the complexity of security challenges handled.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.

What do security researchers do?

Security researchers analyze computer systems, networks, and software to identify vulnerabilities and develop ways to protect against cyber threats. They often use tools like penetration testing, reverse engineering, and security analysis, and may hold certifications such as CISSP or CEH. Their work helps improve cybersecurity defenses and prevent cyberattacks.

How do you become a security researcher?

To become a security researcher, individuals typically pursue a bachelor's degree in computer science, cybersecurity, or a related field, and develop skills in programming, network analysis, and vulnerability assessment. Gaining experience through internships, participating in Capture The Flag (CTF) competitions, and obtaining certifications like Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) can also enhance prospects in this field.
What job categories do people searching Security Research jobs in California look for? The top searched job categories for Security Research jobs in California are:
Infographic showing various Security Research job openings in California as of August 2026, with employment types broken down into 83% Full Time, 13% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $105,598 per year, or $50.8 per hour.

Principal Security Researcher (AI-Assisted Vulnerability Research)

Palo Alto Networks

Santa Clara, CA • On-site

Full-time

Posted 3 days ago

New


Job description

Job Summary:
Palo Alto Networks is dedicated to protecting our digital way of life through innovative technology and collaboration. The Principal Security Researcher will focus on AI-assisted vulnerability research, designing and improving systems for discovering and validating high-impact vulnerabilities in software and open-source projects.
Responsibilities:
• Design, build, and improve AI/security harnesses for vulnerability research, with emphasis on reproducibility, validation quality, exploitability clarity, false-positive reduction, and stable evidence generation.
• Produce high-quality research and security artifacts, such as improved harness capabilities, validated findings, root-cause analyses, technical reports, benchmarks, internal research artifacts, open-source tools, responsible disclosures, publications, or CVEs where appropriate.
• Conduct deep technical analysis across real-world software and open-source projects, including reverse engineering, fuzzing, root-cause analysis, exploitability assessment, patch analysis, variant analysis, and PoC validation.
• Build reusable research infrastructure, including target setup automation, fuzzing harnesses, AI agent workflows, benchmark environments, validation oracles, triage pipelines, evaluation metrics, and maintainer-facing reporting workflows.
• Use LLMs, AI agents, fuzzing, static/dynamic analysis, program analysis, reverse engineering automation, and security automation to improve the quality, speed, coverage, and reliability of vulnerability research workflows.
• Analyze large-scale harness outputs, including successful findings, failed attempts, crash clusters, validation traces, false positives, patch comparisons, and target patterns, to identify new research opportunities and improve future harness capabilities.
Qualifications:
Required:
• Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
• Demonstrated ability to independently drive a technical research project from problem formulation to implementation, evaluation, and written results.
• Evidence of original security research or high-signal technical output, such as CVEs, responsible disclosures, bug bounty findings, security conference papers, technical writeups, GitHub projects, fuzzers, harnesses, exploit analyses, AI/security benchmarks, open-source security tools, or comparable research artifacts.
• 7+ years of experience in vulnerability research, offensive security research, reverse engineering, fuzzing, exploit development, program analysis, security automation, or a closely related security research role.
• Demonstrated experience in one or more of the following: vulnerability research, reverse engineering, fuzzing, exploit development, root-cause analysis, exploitability assessment, PoC development, patch analysis, program analysis, or security tooling.
• Experience designing or building reproducible security experiments, including target setup, harness development, validation logic, oracle design, evaluation metrics, false-positive analysis, or reporting workflows.
• Strong programming skills. Strong knowledge of modern operating systems, network protocols, application security, software vulnerability classes, and common exploitation or validation techniques.
• Strong written communication skills, including the ability to document methods, evidence, limitations, reproduction steps, impact, and remediation guidance clearly.
Preferred:
• PhD in Computer Science, Cybersecurity, AI/ML, Systems, Programming Languages, or a related field, or equivalent demonstrated research experience.
• Experience building AI agent harnesses, fuzzing harnesses, evaluation harnesses, vulnerability validation workflows, exploitability triage systems, patch validation pipelines, security benchmarks, or open-source vulnerability research tooling.
• Experience handling real vulnerabilities end-to-end, including target selection, environment setup, harnessing, reproduction, root-cause analysis, exploitability assessment, patch comparison, responsible disclosure, and maintainer communication.
• Knowledge of security in one or more of the following areas: Web Security, OS & Kernel Security, Browser Security, Software Supply Chain Security, OT/IoT Security, Network/Protocol Security, Cloud Security, Application Security, file parser security, or protocol parser security.
• Strong practical artifacts are highly valued. A public track record of security research, such as conference presentations, publications, CVEs, responsible disclosures, bug bounty results, technical blogs, GitHub projects, open-source security tools, AI/security benchmarks, agent frameworks, or security research artifacts.
• High-impact maintainer relationships, experience reporting vulnerabilities to major open-source projects, or a track record of clear, actionable, well-received vulnerability disclosures is a strong plus.
Company:
Palo Alto Networks is a cybersecurity company that offers cybersecurity solutions for organizations. Founded in 2005, the company is headquartered in Santa Clara, USA, with a team of 10001+ employees. The company is currently Late Stage.