1

Senior Security Researcher Jobs (NOW HIRING)

Sr. Security Engineer, AWS Security

Seattle, WA · On-site

$130K - $178K/yr

You will work closely with security leadership, engineering teams, and researchers to validate ... As a Senior Security Engineer, you will be a hands-on technical contributor with deep expertise in ...

Senior Security Engineer, AI/ML

Foster City, CA · On-site

$133K - $183K/yr

This is a senior, dual-mandate role for an engineer who is equally comfortable orchestrating multi ... Conduct in-depth research on security vulnerabilities in LLMs and AI systems, including prompt ...

Senior Security Engineer, AI/ML

Foster City, CA · On-site

$130K - $179K/yr

This is a senior, dual-mandate role for an engineer who is equally comfortable orchestrating multi ... Conduct in-depth research on security vulnerabilities in LLMs and AI systems, including prompt ...

OR · On-site

As a Principal Product Security Researcher at Chainguard, you'll lead our product security research ... Partner with executive and senior engineering leadership to drive org-level security strategy ...

We are seeking a highly motivated and talented research scientist working in machine learning (ML), natural language processing (NLP), and Artificial Intelligence (AI) to join our Security Science ...

As a Principal Product Security Researcher at Chainguard, you'll lead our product security research ... Partner with executive and senior engineering leadership to drive org-level security strategy ...

next page

Showing results 1-20

Senior Security Researcher information

See salary details

$47

$51

$54

How much do senior security researcher jobs pay per hour?

As of Jun 29, 2026, the average hourly pay for senior security researcher in the United States is $51.44, according to ZipRecruiter salary data. Most workers in this role earn between $49.76 and $53.12 per hour, depending on experience, location, and employer.

What are some common challenges faced by Senior Security Researchers when working with cross-functional teams?

Senior Security Researchers often collaborate with engineers, product managers, and IT teams to identify and address security vulnerabilities. One common challenge is bridging the gap between technical security findings and the priorities or understanding of non-security stakeholders. Communicating complex risks in a clear, actionable way and advocating for security improvements without disrupting project timelines requires strong interpersonal skills. Building mutual trust and staying adaptable helps foster effective collaboration and ensures security is integrated into all stages of development.

What are the key skills and qualifications needed to thrive as a Senior Security Researcher, and why are they important?

To thrive as a Senior Security Researcher, you need deep expertise in cybersecurity principles, threat analysis, vulnerability assessment, and typically a degree in computer science or related field. Familiarity with tools like IDA Pro, Wireshark, Metasploit, and experience with programming languages such as Python or C/C++, as well as relevant certifications like OSCP or CISSP, are highly valuable. Analytical thinking, problem-solving, and strong written and verbal communication skills make someone stand out in this role. These skills are crucial for identifying and mitigating complex security threats, effectively sharing findings, and contributing to organizational resilience.

What does a Senior Security Researcher do?

A Senior Security Researcher is responsible for identifying, analyzing, and mitigating security threats and vulnerabilities in software, systems, or networks. They conduct advanced research on emerging cyber threats, develop new security tools and techniques, and often collaborate with other teams to improve an organization’s overall security posture. Additionally, they may publish findings, present at conferences, and contribute to the security community by sharing knowledge about the latest attack vectors and defense strategies.
More about Senior Security Researcher jobs
What cities are hiring for Senior Security Researcher jobs? Cities with the most Senior Security Researcher job openings:
What are the most commonly searched types of Security Researcher jobs? The most popular types of Security Researcher jobs are:
What states have the most Senior Security Researcher jobs? States with the most job openings for Senior Security Researcher jobs include:
Infographic showing various Senior Security Researcher job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $107,000 per year, or $51.4 per hour.
Sr Principal Security Researcher (AI-Assisted Vulnerability Research)

Sr Principal Security Researcher (AI-Assisted Vulnerability Research)

Palo Alto Networks

Santa Clara, CA • On-site

Other

Posted 6 days ago


Job description

Our Mission

At Palo Alto Networks®, we're united by a shared mission-to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you're ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you're in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

We believe collaboration thrives in person. That's why most of our teams work from the office full time, with flexibility when it's needed. This model supports real-time problem-solving, stronger relationships, and the kind of precision that drives great outcomes.

Job Summary

Your Career

As a Sr Principal Security Researcher, you will work at the forefront of AI-assisted vulnerability research, focusing on the design, implementation, and improvement of AI/security harnesses for discovering, validating, understanding, and reporting high-impact vulnerabilities in real-world software and open-source projects. You will leverage LLMs, AI agents, fuzzing, static and dynamic analysis, reverse engineering, exploitability analysis, and security automation to build reliable workflows for vulnerability discovery, PoC generation, finding validation, patch validation, variant analysis, and remediation support.

Your Impact

This is a research-heavy role for a self-directed researcher-builder. The ideal candidate can independently identify high-impact security problems, build reliable harnesses and evaluation pipelines, analyze large-scale vulnerability data, and drive projects toward concrete outcomes such as improved harness capabilities, validated findings, technical reports, benchmarks, responsible disclosures, open-source tools, CVEs where appropriate, or production-impacting security workflows. We prioritize finding quality and research impact over raw vulnerability counts.

  • Design, build, and improve AI/security harnesses for vulnerability research, with emphasis on reproducibility, validation quality, exploitability clarity, false-positive reduction, and stable evidence generation.

  • Produce high-quality research and security artifacts, such as improved harness capabilities, validated findings, root-cause analyses, technical reports, benchmarks, internal research artifacts, open-source tools, responsible disclosures, publications, or CVEs where appropriate.

  • Conduct deep technical analysis across real-world software and open-source projects, including reverse engineering, fuzzing, root-cause analysis, exploitability assessment, patch analysis, variant analysis, and PoC validation.

  • Build reusable research infrastructure, including target setup automation, fuzzing harnesses, AI agent workflows, benchmark environments, validation oracles, triage pipelines, evaluation metrics, and maintainer-facing reporting workflows.

  • Use LLMs, AI agents, fuzzing, static/dynamic analysis, program analysis, reverse engineering automation, and security automation to improve the quality, speed, coverage, and reliability of vulnerability research workflows.

  • Analyze large-scale harness outputs, including successful findings, failed attempts, crash clusters, validation traces, false positives, patch comparisons, and target patterns, to identify new research opportunities and improve future harness capabilities.

Qualifications

Your Experience

Required Qualifications:

  • Master's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.

  • Demonstrated ability to independently drive a technical research project from problem formulation to implementation, evaluation, and written results.

  • Evidence of original security research or high-signal technical output, such as CVEs, responsible disclosures, bug bounty findings, security conference papers, technical writeups, GitHub projects, fuzzers, harnesses, exploit analyses, AI/security benchmarks, open-source security tools, or comparable research artifacts.

  • 10+ years of experience in vulnerability research, offensive security research, reverse engineering, fuzzing, exploit development, program analysis, security automation, or a closely related security research role.

  • Demonstrated experience in one or more of the following: vulnerability research, reverse engineering, fuzzing, exploit development, root-cause analysis, exploitability assessment, PoC development, patch analysis, program analysis, or security tooling.

  • Experience designing or building reproducible security experiments, including target setup, harness development, validation logic, oracle design, evaluation metrics, false-positive analysis, or reporting workflows.

  • Strong programming skills. Strong knowledge of modern operating systems, network protocols, application security, software vulnerability classes, and common exploitation or validation techniques.

  • Strong written communication skills, including the ability to document methods, evidence, limitations, reproduction steps, impact, and remediation guidance clearly.

Preferred Qualifications:

  • PhD in Computer Science, Cybersecurity, AI/ML, Systems, Programming Languages, or a related field, or equivalent demonstrated research experience.

  • Experience building AI agent harnesses, fuzzing harnesses, evaluation harnesses, vulnerability validation workflows, exploitability triage systems, patch validation pipelines, security benchmarks, or open-source vulnerability research tooling.

  • Experience handling real vulnerabilities end-to-end, including target selection, environment setup, harnessing, reproduction, root-cause analysis, exploitability assessment, patch comparison, responsible disclosure, and maintainer communication.

  • Knowledge of security in one or more of the following areas: Web Security, OS & Kernel Security, Browser Security, Software Supply Chain Security, OT/IoT Security, Network/Protocol Security, Cloud Security, Application Security, file parser security, or protocol parser security.

  • Strong practical artifacts are highly valued. A public track record of security research, such as conference presentations, publications, CVEs, responsible disclosures, bug bounty results, technical blogs, GitHub projects, open-source security tools, AI/security benchmarks, agent frameworks, or security research artifacts.

  • High-impact maintainer relationships, experience reporting vulnerabilities to major open-source projects, or a track record of clear, actionable, well-received vulnerability disclosures is a strong plus.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here (https://benefits.paloaltonetworks.com/) .

$162,700.00 - $263,175.00/yr

Our Commitment

We're trailblazers that dream big, take risks, and challenge cybersecurity's status quo. It's simple: we can't accomplish our mission without diverse teams innovating, together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at accommodations@paloaltonetworks.com .

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.

Is role eligible for Immigration Sponsorship?: Yes