1

Security Research Jobs in California (NOW HIRING)

Research Engineer

San Francisco, CA ยท On-site

$120 - $150/hr

General Analysis is a security research lab focused on adversarial simulations, evaluations, and runtime protection. We are based in San Francisco and work across research, engineering, and product.

Senior Security Engineer, AI/ML

Foster City, CA ยท On-site

$130K - $179K/yr

Conduct in-depth research on security vulnerabilities in LLMs and AI systems, including prompt injection, jailbreaks, data leakage, model theft, and adversarial attacks. * Design and execute ...

Identifying and researching novel attack surfaces unique to LLMs and autonomous systems, contributing to internal and external AI security research * Influencing secure system design across the SDLC ...

Senior Security Engineer, AI/ML

Foster City, CA ยท On-site

$133K - $183K/yr

Conduct in-depth research on security vulnerabilities in LLMs and AI systems, including prompt injection, jailbreaks, data leakage, model theft, and adversarial attacks. * Design and execute ...

Identifying and researching novel attack surfaces unique to LLMs and autonomous systems, contributing to internal and external AI security research * Influencing secure system design across the SDLC ...

AI Security Researcher

San Francisco, CA ยท On-site

$214K - $280K/yr

THE OPPORTUNITY Apollo Research works with most frontier AI companies (OpenAI, Anthropic, Google ... Security exists at Apollo to safeguard the trust frontier labs place in us and to enable that ...

Senior Security Engineer, AI/ML

Foster City, CA ยท On-site

$130K - $179K/yr

Conduct in-depth research on security vulnerabilities in LLMs and AI systems, including prompt injection, jailbreaks, data leakage, model theft, and adversarial attacks. * Design and execute ...

Adversarial Security Test Engineer

Milpitas, CA ยท On-site

$159K - $271K/yr

Research emerging attack techniques relevant to firmware, embedded systems, storage controllers, hardware/firmware interfaces, and supply-chain attack surfaces. AI-Assisted Adversarial Security ...

Research emerging attack techniques relevant to firmware, embedded systems, storage controllers, hardware/firmware interfaces, and supply-chain attack surfaces. AI-Assisted Adversarial Security ...

Research emerging attack techniques relevant to firmware, embedded systems, storage controllers, hardware/firmware interfaces, and supply-chain attack surfaces. AI-Assisted Adversarial Security ...

Showing results 21-40

Security Research information

See California salary details

$46

$50

$53

How much do security research jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for security research in California is $50.77, according to ZipRecruiter salary data. Most workers in this role earn between $49.09 and $52.45 per hour, depending on experience, location, and employer.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.

What are some common challenges faced by professionals in security research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

How do you become a security researcher?

To become a security researcher, individuals typically pursue a bachelor's degree in computer science, cybersecurity, or a related field, and develop skills in programming, network analysis, and vulnerability assessment. Gaining experience through internships, participating in Capture The Flag (CTF) competitions, and obtaining certifications like Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) can also enhance prospects in this field.

What do security researchers do?

Security researchers analyze computer systems, networks, and software to identify vulnerabilities and develop ways to protect against cyber threats. They often use tools like penetration testing, reverse engineering, and security analysis, and may hold certifications such as CISSP or CEH. Their work helps improve cybersecurity defenses and prevent cyberattacks.
Infographic showing various Security Research job openings in California as of August 2026, with employment types broken down into 89% Full Time, 9% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $105,598 per year, or $50.8 per hour.

Senior Product Manager, Security Research

Qualys

Foster City, CA โ€ข On-site

$145K - $175K/yr

Full-time

Re-posted 21 days ago


Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Senior Product Manager, Security Research
Location: US West/Foster City
About the Qualys Threat Research Unit (TRU)
You will be joining the heartbeat of Qualys-a world-renowned team of over 120 "white hat" experts dedicated to staying ahead of the adversary. We don't just track threats; we define the defense. We are four-time Pwnie Award winners (the "Oscars" of hacking), recognized for Epic Achievement and discovering critical zero-day vulnerabilities in software such as OpenSSH and glibc.
The Mission
We are seeking a Senior Product Manager to serve as the strategic bridge between the Threat Research Unit (TRU), Engineering, and our customers. Your goal is to translate the raw, high-velocity threat landscape requirements into a concrete, executable product roadmap.
Key Responsibilities
Strategic Roadmap & Data-Driven Prioritization
  • Utilize your hands-on fluency in data analytics (Salesforce, Jira, SQL) to analyze feature impact and prioritize the roadmap based on empirical evidence rather than opinion.
  • Manage the delicate balance of adding/removing roadmap items through collaboration with Engineering, Marketing, and Product leadership. Transform high-level vision into precise technical requirements and prioritized backlogs.
  • Collaborate with PMM and Sales to ensure features provide a competitive advantage and are positioned correctly in the market.

Customer Discovery & Solution Design
  • Lead discovery sessions to identify root pain points. Move beyond solving single-customer issues to designing scalable solutions that benefit the entire user base.
  • Manage incoming requests and new cases with a systematic approach to review, validation, and communication with stakeholders.
  • Serve as a technical resource by writing impactful blog posts, leading webinars, and defining best practices that help organizations reduce risk, independent of specific product features.
  • Empower the Sales team and Strategic Accounts with compelling product pitches, demos, and deep-dive explanations of complex security capabilities.

Qualifications
  • 5+ years in Product Management with at least 3 years specifically in Cybersecurity (VM, EDR, or Threat Intel).
    • Alternatively: 8+ years in technical leadership/security engineering with a pivot to Product.
  • Deep understanding of the threat landscape (Zero-days, CVEs, Exploits). You are familiar with the distinction between a CVE and an exploit and understand how SOC/IT teams function.
  • Bachelor's degree in computer science, Engineering, or related field (MBA is a plus).
  • Proficiency in Python and SQL (or similar scripting languages) is required.
  • Exceptional ability to communicate across multiple time zones and effectively engage stakeholders from field sales to executive leadership.

Preferred & Bonus
  • Researcher-to-Product Transition: We highly prefer candidates with a background in Threat Research who are looking to pivot into Product Management while leveraging their deep security expertise.
  • Domain Expertise: Strong background in Vulnerability Management (VM), Exposure Management, or Risk Management.

The salary range for this position is $145,000 - $175,000 per year. Final compensation will be determined based on several factors, including but not limited to skills, relevant experience, and work location. Please note this range reflects base salary and does not include incentive compensation or potential equity grants. We also offer a comprehensive and highly competitive benefits package.
Qualys is an Equal Opportunity Employer, please see our EEO policy.