1

Security Researcher Jobs in Virginia (NOW HIRING)

Conduct vulnerability research (VR) on operating system internals and security mechanisms * Support ... development and testing of Computer Network Exploits (CNEs) against commercial and embedded ...

Conducts security research and keeps abreast of latest security issues. Prepares IT security documentation, including department policies and procedures, agency notifications, Web content, and alerts.

Lead Vulnerability Researcher

Herndon, VA · On-site

$150 - $200/hr

Working side by side with engineers and security researchers, you'll guide investigations, identify critical vulnerabilities, and develop countermeasures with operational impact. Our fast-growing ...

Showing results 21-40

Security Researcher information

See Virginia salary details

$47

$51

$53

How much do security researcher jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for security researcher in Virginia is $51.00, according to ZipRecruiter salary data. Most workers in this role earn between $49.33 and $52.69 per hour, depending on experience, location, and employer.

What is a security researcher?

A security researcher keeps up-to-date on all the latest developments in threats to computer software and networks. These threats include different types of malware, such as computer viruses, malicious software and scripts, and direct attacks on a network. The main duties of a security researcher are to investigate existing types of malware, analyze their capabilities, and attempt to predict new forms of malware to develop appropriate security responses. They may reverse engineer malware or test security systems.

What are the key skills and qualifications needed to thrive as a security researcher, and why are they important?

To thrive as a Security Researcher, you need deep expertise in computer science, networking, vulnerability assessment, and malware analysis, often supported by a degree in cybersecurity or related fields. Familiarity with tools like IDA Pro, Wireshark, Metasploit, and certifications such as OSCP or CEH is highly valued. Analytical thinking, curiosity, and strong written and verbal communication help distinguish top performers in this role. These skills are crucial for identifying emerging threats, effectively communicating risks, and developing solutions to protect organizations' digital assets.

What are some common challenges security researchers face when collaborating with development teams?

Security Researchers often encounter challenges when working with development teams, such as communicating complex vulnerabilities in a way that is actionable for developers and aligning on remediation priorities. Bridging the gap between security findings and practical implementation requires clear documentation and a collaborative mindset. Additionally, researchers must balance thorough testing with minimal disruption to production environments, ensuring security improvements integrate smoothly into development cycles.

What is the difference between Security Researcher vs Security Analyst?

AspectSecurity ResearcherSecurity Analyst
CredentialsCertifications like CISSP, CEH, OSCPCertifications like CompTIA Security+, CISSP, GIAC
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT teams
Employer & IndustryTech companies, cybersecurity firms, government agenciesFinancial institutions, healthcare, enterprise companies
Primary FocusIdentifying vulnerabilities, developing exploits, analyzing threatsMonitoring security systems, incident response, implementing security measures

While both roles focus on cybersecurity, Security Researchers primarily analyze vulnerabilities and develop exploits to understand threats better. Security Analysts focus on monitoring, detecting, and responding to security incidents within organizations. Both roles often require similar certifications and work in related environments, but their core responsibilities differ in scope and daily tasks.

What do you need to be a security researcher?

A security researcher typically needs a strong understanding of cybersecurity principles, programming skills, and knowledge of networks and systems. Relevant certifications like CISSP or CEH can enhance credibility, and familiarity with tools such as Wireshark or penetration testing frameworks is beneficial. A bachelor's degree in computer science, information technology, or a related field is often required, along with analytical and problem-solving skills.

What are the most commonly searched types of Security Researcher jobs in Virginia?

The most popular types of Security Researcher jobs in Virginia are:

What are popular job titles related to Security Researcher jobs in Virginia?

For Security Researcher jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Security Researcher jobs in Virginia look for?

The top searched job categories for Security Researcher jobs in Virginia are:

Infographic showing various Security Researcher job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $106,082 per year, or $51 per hour.

Vulnerability/Malware Researcher (Reverse Engineer)

Arlington, VA • On-site

$160K - $180K/yr

Full-time

Posted 4 days ago


Job description

Everforth ECS is seeking a Vulnerability/Malware Researcher (Reverse Engineer) to join our team in Arlington, VA (Hybrid). This position is contingent upon award.
We are seeking a highly skilled Vulnerability/Malware Researcher (Reverse Engineer) to identify, analyze, and understand complex software vulnerabilities and malicious code that may impact organizational systems, products, and infrastructure. This role will conduct in-depth malware analysis, reverse engineer software and firmware, perform exploitation and tactics, techniques, and procedures (TTPs) analysis to uncover exploitable weaknesses, and provide actionable intelligence to support detection, response, and remediation efforts.
The ideal candidate possesses strong low-level programming knowledge, reverse engineering expertise, and experience analyzing sophisticated malware, exploit techniques, and advanced adversary tradecraft.
Key Responsibilities
Malware Analysis & Reverse Engineering
  • Perform static and dynamic analysis of malicious software, including ransomware, trojans, rootkits, spyware, and advanced persistent threat (APT) malware.
  • Reverse engineer malware samples to identify functionality, persistence mechanisms, command-and-control (C2) communications, and attacker objectives.
  • Develop detailed malware analysis reports and technical documentation.
  • Research evolving malware techniques and adversary capabilities.

Vulnerability Research
  • Identify and analyze software, operating system, firmware, and application vulnerabilities.
  • Perform code analysis to discover security weaknesses and exploit paths.
  • Research emerging vulnerabilities and assess organizational exposure.
  • Validate security findings through proof-of-concept testing and exploit analysis.
  • Collaborate with remediation teams to prioritize and mitigate identified risks.

Security Research & Threat Analysis
  • Investigate adversary tactics, techniques, and procedures (TTPs) on device/service targeting procedures.
  • Analyze exploit kits, attack frameworks, and intrusion methods used by threat actors.
  • Support intelligence-driven security initiatives through technical research and threat assessments.
  • Correlate research findings with threat intelligence and incident response investigations.

Detection Development
  • Create and maintain Indicators of Compromise (IOCs), YARA rules, Sigma rules, and detection signatures.
  • Develop behavioral detections and analytic content for Security Operations Center (SOC) use.
  • Assist threat hunting teams by providing technical indicators and adversary insights.
  • Support development of MITRE ATT&CK procedure-level mapping artifacts.
  • Enhance detection coverage based on research findings and threat trends.

Research Tool Development
  • Develop custom scripts, automation tools, and utilities to support malware analysis and vulnerability research.
  • Improve reverse engineering workflows through automation and tooling enhancements.
  • Maintain secure malware analysis laboratories and research environments.
  • Evaluate emerging security research technologies and platforms.

Collaboration & Reporting
  • Partner with Incident Response, Threat Intelligence, SOC, Product Security, and Engineering teams.
  • Present technical findings to security leadership and engineering stakeholders.
  • Produce technical reports, white papers, and research briefings.
  • Contribute to internal knowledge bases and security best practices.

Salary Range: $160,000 - $180,000
General Description of Benefits
  • Top Secret Clearance
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field, or equivalent experience.
  • 7+ years of experience in malware analysis, reverse engineering, vulnerability research, or offensive security.
  • Strong understanding of operating system internals, including Windows and Linux.
  • Understanding and familiarity with MITRE ATT&CK framework.
  • Experience reverse engineering compiled software using industry-standard tools.
  • Knowledge of assembly language (x86, x64, ARM) and executable file formats.
  • Proficiency in at least one programming language such as Python, C, C++, Rust, or Go.
  • Experience analyzing malware behavior through static and dynamic analysis techniques.
  • Understanding of software exploitation concepts, memory corruption vulnerabilities, and attack methodologies.
  • Strong analytical, problem-solving, and investigative skills.