1

Security Research Jobs in Virginia (NOW HIRING)

Transition of this research will take the form of developing detection capabilities, providing new requirements and feature requests for our NetSA Security tool suite, writing publications, and ...

Conducts security research and keeps abreast of latest security issues. Prepares IT security documentation, including department policies and procedures, agency notifications, Web content, and alerts.

IT Security Analyst 2

Richmond, VA · On-site

$33 - $36/hr

Conducts security research and keeps abreast of latest security issues. * Prepares IT security documentation, including department policies and procedures, agency notifications, Web content, and ...

Conduct vulnerability research (VR) on operating system internals and security mechanisms * Support ... development and testing of Computer Network Exploits (CNEs) against commercial and embedded ...

Conducts security research and keeps abreast of latest security issues. • Prepares IT security documentation, including department policies and procedures, agency notifications, Web content, and ...

next page

Showing results 1-20

Security Research information

See Virginia salary details

$47

$51

$53

How much do security research jobs pay per hour?

As of Jul 27, 2026, the average hourly pay for security research in Virginia is $51.00, according to ZipRecruiter salary data. Most workers in this role earn between $49.33 and $52.69 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Researcher, and why are they important?

To thrive as a Security Researcher, you need a solid background in computer science, cybersecurity principles, and vulnerability analysis, often supported by a relevant degree or certifications like OSCP or CEH. Expertise with tools such as IDA Pro, Wireshark, Metasploit, and reverse engineering platforms is typically required. Critical thinking, curiosity, and strong written communication are essential soft skills for investigating threats and sharing findings. These competencies enable Security Researchers to identify, analyze, and mitigate security risks in an evolving threat landscape.

What are some common challenges faced by professionals in Security Research roles?

Security Researchers often encounter the challenge of keeping up with rapidly evolving threats and technologies. The field demands continuous learning, as new vulnerabilities and attack vectors emerge regularly. Collaborating with cross-functional teams, such as software engineers and incident response, is essential to translate research findings into practical defenses. Additionally, Security Researchers must balance thorough analysis with the need to quickly communicate critical findings to stakeholders, ensuring organizational security remains robust.

What is the difference between Security Research vs Security Analyst?

AspectSecurity ResearchSecurity Analyst
CredentialsCertifications like CISSP, GIAC, OSCP often preferredCertifications like CompTIA Security+, CISSP, CEH common
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Industry UsageUsed in threat discovery, vulnerability research, developing security toolsUsed in monitoring, incident response, security monitoring

Security Research and Security Analysts both play vital roles in cybersecurity. While Security Researchers focus on discovering vulnerabilities and developing new security techniques, Security Analysts monitor systems for threats and respond to incidents. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

What is security research?

Security research is the process of studying, analyzing, and developing methods to identify and address vulnerabilities in computer systems, networks, and software. Security researchers investigate potential threats, discover security flaws, and often create proof-of-concept exploits to demonstrate risks. Their work helps organizations understand emerging threats and improve their defenses, often contributing to the wider cybersecurity community by sharing findings and best practices.
What job categories do people searching Security Research jobs in Virginia look for? The top searched job categories for Security Research jobs in Virginia are:
Infographic showing various Security Research job openings in Virginia as of July 2026, with employment types broken down into 89% Full Time, 3% Part Time, and 8% Contract. Highlights an 95% In-person, and 5% Remote job distribution, with an average salary of $106,082 per year, or $51 per hour.
Network Security Researcher

Network Security Researcher

Cmu

Arlington, VA • On-site

Full-time

Posted 19 days ago


Job description

What We Do:

Our team, within the Cyber Risk and Resilience Directorate researches, designs, and develops software tools for the collection, storage, and analysis of network data to provide security insights. We provide both the core network tools to facilitate this capability, and prototypes of new methods to present the data most effectively. We work with data at a scale generally not experienced by most organizations, handling record counts in the tens of billions per day.

Developing security insights at this scale requires creativity, efficiency, and contemporary knowledge of modern computing platforms. In some cases, the computing has outpaced the methods, and it is incumbent upon us to generate novel views of both the entire data collection, and of focused datasets tailored to specific analyst needs.

Our network situational awareness security tools are published here: https://tools.netsa.cert.org/

Position Summary:

As a network security researcher on the Network Situational Awareness team, you will research network threats to develop methods of detection and tailor these for partner environments. Transition of this research will take the form of developing detection capabilities, providing new requirements and feature requests for our NetSA Security tool suite, writing publications, and providing customer-specific training. The primary network data source for the team is netflow combined with application layer metadata, with an expanding focus on host-based (e.g., EDR) and cloud telemetry.

You will be responsible for gaining insights from data to facilitate detections, working with partners to help them to better understand their data and researching new data sources to expand the expertise of the team.

Requirements:

-Bachelor's Degree in Computer Science or a relevant technical discipline with eight (8) years of relevant work experience; or a MS in Computer Science or a relevant technical discipline with five (5) years of relevant work experience; or a PhD in Computer Science or other relevant technical discipline with two (2) years of relevant work experience.

-Movement between buildings within the SEI and CMU community required.

Willingness to travel to various locations to support the SEI's overall mission. This may include national travel to sponsor sites, conferences, and offsite meetings on occasion.

-You will be subject to a background check and will need to obtain and maintain a Department of War security clearance.

Knowledge, Skills and Abilities:

Ability to translate threat intelligence to avenues for research, prototyping, and curation of detection capabilities.

Strong knowledge of network fundamentals, common application layer protocols, and network-based telemetry.

Strong proficiency in at least one scripting or programming language such as Python, Go, Ruby, C, Java, or Scala.

Strong problem-solving and analytical skills, detailed research, and ability to document and communicate ideas and findings to diverse audiences.

Desired Experience:

Hands-on experience in a security research, threat hunting, detection engineering, or Cyber threat Intelligence (CTI) analyst role.

Experience analyzing large datasets, especially network telemetry such as netflow, application metadata, or PCAP from network sensors such as YAF, Zeek, Suricata, etc;

Experience applying cybersecurity data science methods and practices

Experience using open-source and / or commercial Internet intelligence telemetry and datasets

Strong grasp of the threat landscape and experience researching and investigating threats

Experience presenting technical topics

Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff - Regular

Full time/Part time

Full time

Pay Basis

SalaryMore Information:
  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.

  • Statement of Assurance


CMU logo

About CMU

Sourced by ZipRecruiter

Industry

Offices of mental health practitioners

Company size

201 - 500 Employees

Headquarters location

Harrisburg, PA, US