1

Security Research Jobs in California (NOW HIRING)

Required : • 3+ years of full-time experience in security research, offensive security, or related fields. • Experience with finding vulnerabilities in source code • Experience creating PoC ...

Qualifications * 3+ years of full-time experience in security research, offensive security, or related fields. * Experience with finding vulnerabilities in source code * Experience creating PoC ...

Qualifications * 3+ years of full-time experience in security research, offensive security, or related fields. * Experience with finding vulnerabilities in source code * Experience creating PoC ...

Apple's Security Engineering & Architecture (SEAR) organization is responsible for the security of ... You will conduct offensive research into AI-specific attack classes, including prompt injection ...

next page

Showing results 1-20

Security Research information

See California salary details

$46

$50

$53

How much do security research jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for security research in California is $50.77, according to ZipRecruiter salary data. Most workers in this role earn between $49.09 and $52.45 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What are some common challenges faced by professionals in security research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

How much do security researchers make?

Security researchers typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, location, and certifications. Entry-level positions may start lower, while experienced professionals with specialized skills or certifications like CISSP can earn higher salaries. Salaries can also vary based on the industry and the complexity of security challenges handled.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.

What do security researchers do?

Security researchers analyze computer systems, networks, and software to identify vulnerabilities and develop ways to protect against cyber threats. They often use tools like penetration testing, reverse engineering, and security analysis, and may hold certifications such as CISSP or CEH. Their work helps improve cybersecurity defenses and prevent cyberattacks.

How do you become a security researcher?

To become a security researcher, individuals typically pursue a bachelor's degree in computer science, cybersecurity, or a related field, and develop skills in programming, network analysis, and vulnerability assessment. Gaining experience through internships, participating in Capture The Flag (CTF) competitions, and obtaining certifications like Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) can also enhance prospects in this field.
What job categories do people searching Security Research jobs in California look for? The top searched job categories for Security Research jobs in California are:
Infographic showing various Security Research job openings in California as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $105,598 per year, or $50.8 per hour.

Staff Security Research Engineer

Harness

Mountain View, CA • On-site

Full-time

Re-posted 4 days ago


Job description

Job Summary:
Harness is a high-growth company that is disrupting the software delivery market, and they are seeking a Staff Security Research Engineer to lead research into cutting-edge threats targeting APIs and CI/CD pipelines. This role involves collaborating with teams to develop detection capabilities and customer protection strategies while representing Harness at security conferences.
Responsibilities:
• Conduct cutting-edge research on modern attack vectors across AppSec, CI/CD pipelines, runtime environments, and emerging technologies like LLMs
• Develop and refine advanced exploit techniques to prevent attacks targeting software delivery, runtime from code to cloud
• Collaborate with research, product and engineering to prototype and implement detection and mitigation strategies for emerging threats
• Perform in-depth security assessments and penetration testing of web applications, APIs, build systems, and cloud-native environments
• Engage with customers to understand their application landscape and provide expert guidance on integrating product capabilities with their security requirements
• Support pre-sales, POCs, and post-sales engagements by troubleshooting and solving complex detection and protection challenges
• Build internal tools to automate and enhance security research workflows.
• Evangelize our research and platform through blogs, white papers, and talks at premier security conferences
• Analyze global cybersecurity incidents to extract learnings and apply them across domains
Qualifications:
Required:
• Bachelor's or Master's degree in Computer Science.
• 8-10+ years of work experience
• Deep expertise with modern application stacks (microservices, containers, Kubernetes, cloud platforms like AWS/GCP)
• Prior development experience and a fair understanding of programming languages and frameworks are a must
• Proficient in at least one modern programming language (Python, Go, Java, JavaScript, etc.)
• Demonstrated experience in penetration testing, vulnerability research, and exploitation of Web/API ecosystems
• Strong foundation in computer science fundamentals, identity aware, network, application and runtime security
• Strong experience with various pen testing tools like Burpsuite, ZAP, etc.
• Strong applied knowledge of attacks in Web/API eco-system - Web attacks, API attacks, API abuse, API Fraud, ATO, etc.
• Strong knowledge of modern application security threats and mitigation platforms like (WAFs, WAAP, RASP, etc.).
• Working knowledge of IAST, DAST, and SAST
• Experience in responsible disclosure of vulnerabilities and a track record of CVEs or similar
• Strong analytical skills and the ability to conduct complex security research autonomously
• Ability to work autonomously and drive complex security investigations from hypothesis to implementation
Preferred:
• Proven track record of publishing high-quality research or presenting at top security conferences (e.g., Black Hat, DEF CON, RSAC, BSides) is a strong plus
• Certifications such as CEH, OSCP, OSCE, or relevant security credentials
Company:
Harness provides a software delivery platform that helps engineering teams build, deploy, and operate applications through a set of tools. Founded in 2017, the company is headquartered in San Francisco, USA, with a team of 501-1000 employees. The company is currently Late Stage.