1

Security Research Jobs in Texas (NOW HIRING)

Security Research Engineering Technical Leader

Austin, TX ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will also have opportunities to research security topics independently or collaboratively to explore and develop tools and ideas as part of our "Free Friday" innovation and incubation process.

The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next ...

The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next ...

Software Engineer

Austin, TX ยท On-site +1

AWS, Postgres, Python (for Django, security research, and data science), open to other languages and tools What will you do? * Architect, design, and implement scalable distributed systems, like.

Adversarial AI & Research Engineer

Austin, TX ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

We are building a robust foundation for AI security through adversarial datasets, in-house content generation systems, and external knowledge sharing - establishing Salesforce as a leader in the AI ...

Senior Product Manager, Identity Security

Austin, TX

$125K - $165K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Partner with Security Research and Engineering to turn attack-path analysis and MITRE ATT&CK identity tactics into detection logic and continuous control verification Cross-Functional & Partner ...

Collaborate with experienced security consultants, researchers, and red team specialists on client engagements * Gain exposure to offensive security tooling, automation techniques, AI-supported ...

Posted today

Principal Security Engineer

Austin, TX ยท Remote

$160K - $240K/yr

  • Medical

  • PTO

Risk Research & Mitigation: Investigate emerging security risks related to blockchain protocols, institutional custody models, and novel cryptographic techniques. * Compliance & Audits: Support ...

next page

Showing results 1-20

Security Research information

See Texas salary details

$44

$47

$50

How much do security research jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for security research in Texas is $47.93, according to ZipRecruiter salary data. Most workers in this role earn between $46.35 and $49.47 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What are some common challenges faced by professionals in security research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

How much do security researchers make?

Security researchers typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, location, and certifications. Entry-level positions may start lower, while experienced professionals with specialized skills or certifications like CISSP can earn higher salaries. Salaries can also vary based on the industry and the complexity of security challenges handled.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.

What do security researchers do?

Security researchers analyze computer systems, networks, and software to identify vulnerabilities and develop ways to protect against cyber threats. They often use tools like penetration testing, reverse engineering, and security analysis, and may hold certifications such as CISSP or CEH. Their work helps improve cybersecurity defenses and prevent cyberattacks.

How do you become a security researcher?

To become a security researcher, individuals typically pursue a bachelor's degree in computer science, cybersecurity, or a related field, and develop skills in programming, network analysis, and vulnerability assessment. Gaining experience through internships, participating in Capture The Flag (CTF) competitions, and obtaining certifications like Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) can also enhance prospects in this field.

What are popular job titles related to Security Research jobs in Texas?

For Security Research jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Security Research jobs in Texas look for?

The top searched job categories for Security Research jobs in Texas are:

What cities in Texas are hiring for Security Research jobs?

Cities in Texas with the most Security Research job openings:

Infographic showing various Security Research job openings in Texas as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $99,687 per year, or $47.9 per hour.

AI Security Research & Red Team Engineer

CloudFlare

Austin, TX โ€ข On-site

$150 - $210/hr

Other

Posted 2 days ago

New


Job description

AI Security Research & Red Team Engineer

Hybrid

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the worldโ€™s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazineโ€™s Top Company Cultures list and ranked among the Worldโ€™s Most Innovative Companies by Fast Company.

At Cloudflare, weโ€™re not looking for people who wait for a polished roadmap; weโ€™re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a \"normalized\" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If youโ€™re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, youโ€™ll fit right in.

The Role:

We are seeking a highly skilled AI Security Research & Red team engineerto join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvements in Cloudflareโ€™s security posture focusing on AI, Agents, harnesses and LLMโ€™s.

Key Responsibilities:
  • AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflareโ€™s products and services.
  • Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively.
  • Adversary Simulation: Execution of full-chain red team operations targeting Cloudflareโ€™s global infrastructure, corporate networks, and product ecosystems.
  • Efficacy Testing: Establish a rigorous framework for testing \"Security Efficacy\"โ€”measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures).
  • Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements.
  • Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflareโ€™s security posture.
  • Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most.
Partnerships
  • Security Incident Response Team (SIRT): You will act as the \"sparring partner\" for SIRT. By conducting unannounced exercises, you help them refine their playbooks, test their on-call rotations, and ensure their forensic tooling is effective under pressure.
  • Threat Detection & Threat Engineering: You will partner closely with these teams to bridge the gap between adversary simulation and defensive coverage. You will proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks to test and tune detections against emerging TTPs.
  • Product Engineering/SRE: We operate as \"Customer Zero\" of our own products, your red teaming findings will drive resilience in processes and implementations, ultimately making Cloudflare and its customers more secure.
  • Governance, Risk, and Compliance (GRC): You will bridge the gap between \"paper security\" and \"technical reality.\" By providing empirical evidence of control effectiveness, you help GRC move away from manual audits and toward continuous, automated compliance validation.
Required Qualifications:
  • Experience: 4+ years in offensive security, application security or other relevant field
  • Deep knowledge: AI, Coding agents, LLMs, prompt engineering, AI-related attack vectors (e.g., prompt injection, jailbreaking), and Agentic concepts all for use in the red team but also testing Cloudflare uses.
  • Technical Roots: A strong background in manual penetration testing, exploit development, or cloud security (AWS/GCP/Bare Metal).
  • Operational Mindset: Experience using the MITRE ATT&CK framework to map coverage and identify \"blind spots\" in defensive telemetry.
  • Communication Skills: The ability to explain a complex \"0-day\" exploit to a non-technical stakeholder while maintaining the respect of a deep-dive engineering team.
  • Tooling Familiarity: Knowledge of automated breach and attack simulation (BAS) tools, as well as custom-built frameworks for payload delivery and C2 infrastructure.
Compensation

Compensation may be adjusted depending on work location.

  • For New York based hires: Estimated annual salary of $166,000 - $208,000.
Equity

This role is eligible to participate in Cloudflareโ€™s equity plan.

What Makes Cloudflare Special?

Weโ€™re not just a highly ambitious, large-scale technology company. Weโ€™re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo

Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflareโ€™s enterprise customers--at no cost.

Athenian Project

In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.

1.1.1.1

We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Hereโ€™s the deal - we donโ€™t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something youโ€™d like to be a part of? Weโ€™d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using

#J-18808-Ljbffr