1

Senior Vulnerability Researcher Jobs (NOW HIRING)

As a Senior Vulnerability Researcher, you will work with disassemblers and debuggers to quickly understand how embedded devices operate. You will use and build tools that push past the edge of ...

next page

Showing results 1-20

Senior Vulnerability Researcher information

See salary details

$28.5K

$76.6K

$137.5K

How much do senior vulnerability researcher jobs pay per year?

As of Jun 9, 2026, the average yearly pay for senior vulnerability researcher in the United States is $76,607.00, according to ZipRecruiter salary data. Most workers in this role earn between $50,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Senior Vulnerability Researchers when working on complex systems?

Senior Vulnerability Researchers often encounter challenges such as reverse engineering proprietary software, analyzing obfuscated code, and dealing with a lack of documentation for complex systems. Collaboration with cross-functional teams, such as software developers and security analysts, is essential to understand system intricacies and coordinate responsible disclosure. Staying updated with the latest attack techniques and adapting to rapidly evolving technology landscapes are also key aspects of the role.

What are the key skills and qualifications needed to thrive as a Senior Vulnerability Researcher, and why are they important?

To thrive as a Senior Vulnerability Researcher, you need deep expertise in cybersecurity, reverse engineering, exploit development, and a strong background in computer science or a related field. Familiarity with tools like IDA Pro, Ghidra, debuggers, and proficiency in programming languages such as C, Python, and assembly are essential, along with relevant certifications like OSCP or CEH. Analytical thinking, attention to detail, and effective communication are critical soft skills for collaborating with teams and presenting complex findings. These competencies are vital for identifying and mitigating security risks, ensuring robust protection of digital assets, and driving advancements in security research.

What is the difference between Senior Vulnerability Researcher vs Security Analyst?

AspectSenior Vulnerability ResearcherSecurity Analyst
Required CredentialsCertifications like OSCP, CISSP, CEH; strong technical backgroundCertifications like Security+, CISSP; focus on monitoring and analysis
Work EnvironmentResearch labs, cybersecurity firms, R&D teamsSecurity operations centers, corporate IT departments
Employer & Industry UsageTech companies, cybersecurity firms, government agenciesFinancial institutions, healthcare, enterprise organizations
Common Search & Comparison IntentUnderstanding advanced vulnerability research rolesComparing security roles in cybersecurity teams

While both roles focus on cybersecurity, a Senior Vulnerability Researcher specializes in identifying and analyzing security flaws through research and testing, often working in labs or R&D environments. In contrast, a Security Analyst monitors security systems, responds to incidents, and maintains overall security posture within organizations. The roles complement each other but differ in focus and daily responsibilities.

What does a Senior Vulnerability Researcher do?

A Senior Vulnerability Researcher is responsible for identifying, analyzing, and reporting security vulnerabilities in software, hardware, or network systems. They use advanced techniques to discover potential security flaws that could be exploited by attackers. Their work involves reverse engineering, penetration testing, and developing proof-of-concept exploits to demonstrate risks. Additionally, they often collaborate with development teams to recommend mitigation strategies and help improve overall security posture.
More about Senior Vulnerability Researcher jobs
What cities are hiring for Senior Vulnerability Researcher jobs? Cities with the most Senior Vulnerability Researcher job openings:
What are the most commonly searched types of Vulnerability Researcher jobs? The most popular types of Vulnerability Researcher jobs are:
What states have the most Senior Vulnerability Researcher jobs? States with the most job openings for Senior Vulnerability Researcher jobs include:
What job categories do people searching Senior Vulnerability Researcher jobs look for? The top searched job categories for Senior Vulnerability Researcher jobs are:
Infographic showing various Senior Vulnerability Researcher job openings in the United States as of May 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $76,607 per year, or $36.8 per hour.
Senior Vulnerability Researcher

Senior Vulnerability Researcher

KBR, Inc.

Beavercreek, OH • On-site

$142K - $213K/yr

Full-time

Posted 12 days ago


KBR rating

8.3

Company rating: 8.3 out of 10

Based on 47 frontline employees who took The Breakroom Quiz

94th of 352 rated engineering


Job description

Title:
Senior Vulnerability Researcher
Why Join Us?
  • Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
  • Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
  • Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.

KBR is seeking a Senior Vulnerability Researcher to lead vulnerability discovery and validation against embedded systems and firmware. This role owns end-to-end vulnerability research: building emulation-backed test environments, designing fuzzing and analysis workflows, performing crash triage and root-cause analysis, and developing proof-of-concept exploits to validate impact in a controlled lab setting.
The Senior Vulnerability Researcher provides technical leadership, mentors engineers into defined proficiencies, and works directly with government customers to deliver reproducible findings and scalable research capability.
Key Responsibilities
  • Lead and mentor vulnerability researchers; set technical direction and intentionally develop individual proficiencies
  • Execute vulnerability research on embedded targets using asset-safe approaches
  • Build and maintain fuzzing pipelines, including target selection, harness development, seed/corpus management, and coverage-driven campaign design
  • Perform crash triage, exploitability assessment, and root-cause analysis
  • Develop proof-of-concept exploits to demonstrate vulnerability impact in controlled labs
  • Create controlled test harnesses and orchestration to exercise payload delivery and validate behavior deterministically across runs
  • Reverse engineer firmware/binaries as needed to understand vulnerable code paths, exploitation constraints, and exploit mechanics
  • Engage customers to understand mission outcomes and shape scalable research approaches
  • Produce high-quality technical reports and supporting artifacts suitable for release

Minimum Qualifications
  • Security Clearance: Must have an active U.S. government Secret security clearance, which is something only a U.S. citizen can obtain
  • Education: Master's degree in Computer Engineering, Electrical Engineering, Computer Science, or a related field
  • 10+ years of experience, including at least 5 years in vulnerability research, reverse engineering, or exploit development
  • Strong understanding of embedded systems, firmware, operating systems, and low-level software behavior
  • Proficiency in C/C++, Python, and assembly for vulnerability research, harness development, and automation
  • Experience building emulation-backed analysis environments
  • Demonstrated experience with coverage-guided fuzzing, harness development, and crash triage workflows
  • Demonstrated ability to produce proof-of-concept exploits for vulnerability validation
  • Demonstrated leadership, mentorship, and customer engagement experience

Preferred Qualifications
  • Experience with hybrid fuzzing and advanced analysis techniques
  • Experience scaling fuzzing or dynamic testing programs
  • Experience with hardware security research
  • Publications, reports, or presentations in vulnerability research or embedded security

Basic Compensation: $142,000 - $213,000 (For Beavercreek, OH Only)
The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity.
Additional Compensation:
KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of a sign on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

What KBR employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


KBR logo

About KBR

Sourced by ZipRecruiter

At KBR, we partner with government and industry clients to provide purposeful and comprehensive solutions with an emphasis on efficiency and safety. With a full portfolio of services, proprietary technologies and expertise, our employees are ready to handle projects and missions from planning and design to sustainability and maintenance. Whether at the bottom of the ocean or in outer space, our clients trust us to deliver the impossible on a daily basis.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Houston, TX, US

Year founded

1998