1

Vulnerability Research Jobs in Colorado (NOW HIRING)

Senior Security Engineer

Boulder, CO · On-site

$131K - $237K/yr

You will be embedded with software engineers, reverse engineers, and vulnerability researchers, hardening the infrastructure, supply chains and pipelines on while guiding their secure development.

You will be embedded with software engineers, reverse engineers, and vulnerability researchers, hardening the infrastructure, supply chains and pipelines on while guiding their secure development.

Conduct adversarial analysis and vulnerability assessments of IT, OT, and hybrid energy systems, identifying insights for defense design improvements. * Contribute to research proposals, technical ...

Research threat intelligence, vulnerability disclosures, and exploit activity to determine risk relevance and customer impact. * Generate reports, dashboards, and executive briefings to communicate ...

As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive ...

Vulnerability Management & Remediation Collaborate with engineering and development teams to ... Research emerging threats, attack vectors, and adversarial techniques to inform offensive and ...

Vulnerability Management & Remediation Collaborate with engineering and development teams to ... Research emerging threats, attack vectors, and adversarial techniques to inform offensive and ...

next page

Showing results 1-20

Vulnerability Research information

See Colorado salary details

$38.9K

$111.5K

$149.8K

How much do vulnerability research jobs pay per year?

As of Aug 29, 2026, the average yearly pay for vulnerability research in Colorado is $111,474.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,400.00 and $109,400.00 per year, depending on experience, location, and employer.

What is a vulnerability research?

A Vulnerability Research job involves identifying, analyzing, and reporting security weaknesses in software, hardware, or networks. Researchers use reverse engineering, fuzz testing, and other techniques to discover exploitable flaws before malicious actors can exploit them. Their findings help improve security by enabling developers and organizations to patch vulnerabilities and strengthen defenses. This role requires a deep understanding of cybersecurity, programming, and exploit development.

What are some common challenges faced in a vulnerability research role?

One of the main challenges in Vulnerability Research is keeping up with constantly evolving threat landscapes and security technologies, which requires continuous learning and adaptability. Researchers often encounter complex and undocumented systems, making analysis and exploitation both technically demanding and time-consuming. You may collaborate closely with other cybersecurity professionals, developers, and incident response teams to verify findings, replicate vulnerabilities, and share remediation strategies. Successfully navigating these challenges is rewarding and allows you to make a tangible impact on organizational security.

What are the key skills and qualifications needed to thrive in a vulnerability research position?

To thrive in Vulnerability Research, you need a strong background in cybersecurity principles, programming, reverse engineering, and deep knowledge of common operating systems and network protocols, often supported by a relevant degree in computer science or similar fields. Familiarity with tools such as IDA Pro, Ghidra, Wireshark, Metasploit, and certifications like OSCP or CEH is highly valuable. Analytical thinking, persistence, attention to detail, and effective written communication are critical soft skills in this field. These capabilities ensure you can effectively discover, analyze, and document security vulnerabilities, contributing to safer software and systems.

What are the most commonly searched types of Vulnerability Research jobs in Colorado?

The most popular types of Vulnerability Research jobs in Colorado are:

What are popular job titles related to Vulnerability Research jobs in Colorado?

For Vulnerability Research jobs in Colorado, the most frequently searched job titles are:

What job categories do people searching Vulnerability Research jobs in Colorado look for?

The top searched job categories for Vulnerability Research jobs in Colorado are:

Infographic showing various Vulnerability Research job openings in Colorado as of August 2026, with employment types broken down into 1% Internship, 1% As Needed, 84% Full Time, 11% Part Time, 1% Temporary, and 2% Contract. Highlights an 83% Physical, 4% Hybrid, and 13% Remote job distribution, with an average salary of $111,474 per year, or $53.6 per hour.

Cyber New Professionals Program with Security Clearance

MITRE Corporation

Colorado Springs, CO • On-site

Other

This job post has expired today. Applications are no longer accepted.


MITRE Corporation rating

8.2

Company rating: 8.2 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

163rd of 450 rated engineering


Job description

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us. Launch your cybersecurity career through MITRE's Cyber New Professionals (CNP) Program. You'll tackle complex national cybersecurity challenges alongside leading experts while gaining hands-on experience, developing new skills, and building your professional network. CNP combines: * Structured onboarding to MITRE, its culture and organizational structure, and the CNP program
* Varied project experience that builds broad cybersecurity expertise and depth in your areas of interest
* Curated technical and professional training
* Mentorship from MITRE cybersecurity experts
* A cohort of early-career peers and networking opportunities across MITRE How the Program Works CNP is a two-year program for staff at the beginning of their cybersecurity careers, including people who are new to many of the topics below. Project assignments are matched to your skills and interests, as well as project availability. After two years, you will graduate from CNP and transition into another MITRE department. Roles & Responsibilities may include: * Develop threat-informed, intelligence-enabled solutions using MITRE ATT&CK®, MITRE Engage™, and MITRE Caldera to counter advanced adversaries
* Research novel technical ideas, conduct rigorous analysis, and build proofs of concept that inform sponsor decisions
* Apply threat-informed cybersecurity principles to protect critical systems and infrastructure from cyberattacks and other disruptions
* Model and analyze cyber-physical, physical, human, and organizational systems
* Analyze binaries, firmware, embedded systems, and industrial protocols; conduct vulnerability research, fuzzing, crash analysis, and mitigation assessments
* Develop tested, documented, reproducible research software that integrates cybersecurity, artificial intelligence, systems engineering, and domain expertise
* Collaborate with sponsors, vendors, and academia to advance cybersecurity practices Example Focus Areas These areas show the breadth of CNP's work, not the expected profile of a single candidate. You can be a strong candidate with experience in only one or a few of them. Your assignments will reflect your skills, interests, and available projects. * Threat operations and analysis: adversary emulation; threat intelligence; defensive operations; deception and adversary engagement; cyber effects; analytics; malware analysis; forensics; assessments; and reverse engineering
* Security architecture, trust, and governance: cloud security; cross-domain solutions; cryptography and trust; enterprise security architecture; identity, credentialing, and access management; privacy; strategy and governance; and supply-chain security
* Critical and connected systems: critical infrastructure resiliency and safety; cyber resiliency and safety; Internet of Things (IoT) and operational technology (OT) security; OT engineering and response; modeling and simulation; adversary emulation; and countermeasures
* Software and device security: security automation and management; software assurance; vulnerability research and exploitability analysis; and embedded, wireless, radio frequency (RF), and cellular security
* Systems and emerging technology: autonomous cyber; systems and mission engineering; AI-enabled cross-domain engineering; and cyber-physical and human-system modeling Basic Qualifications * Bachelor's or graduate degree in a relevant field, such as engineering, applied physics, applied mathematics, computer science, or a related discipline, completed by your start date
* Typically requires less than 2 years of related experience with a related bachelor's degree, or equivalent combination of related education and work experience; internships and co-ops do not count toward this limit
* Hands-on technical experience through employment, internships or co-ops, research laboratories, independent projects, capture-the-flag competitions, or similar work
* Applied knowledge of cybersecurity principles, tools, and devices
* Ability to obtain a U.S. government Top Secret security clearance; an active clearance is not required
* Ability to work independently and collaboratively
* Strong written and verbal communication skills, including presentation skills
* Initiative and sound judgment when addressing novel, complex, or ambiguous problems
* Strong organizational skills, including attention to detail, and the ability to manage multiple project components Preferred Qualifications Experience in any of the following is helpful, but this is not a checklist. Candidates are not expected to have experience in all, or even most, of these areas: * Proficiency in one or more scripting or programming languages, such as Python, Java, C/C++, or JavaScript, with an emphasis on testing, continuous integration, reproducibility, and maintainability
* Security across operating systems, computer systems, mobile devices, enterprise and cloud environments, or wireless networks; experience with tools and frameworks such as Nmap, Metasploit, ATT&CK, RMF, CSF, or MITRE Caldera
* Advanced cyber threats, adversary methods, static or dynamic analysis, debugging, disassembly, decomplication, instrumentation, emulation, or symbolic analysis
* Vulnerability research, fuzzing, exploitability assessment, exploit development, or protocol security
* SCADA, distributed control systems, programmable logic controllers, industrial protocols, or other industrial control technologies and physical processes; familiarity with NIST SP 800-82, NERC CIP, IEC 62443, Zero Trust, or ATT&CK for ICS
* Systems or mission engineering and model-based systems engineering methods such as SysML, UAF, BPMN, or STPA-Sec
* Applied cryptography, authentication and key flows, implementation security, or side-channel analysis
* Embedded, wireless, RF, or cellular technologies and security
* An active U.S. government security clearance NOTE: Thank you for your interest in MITRE's CNP opportunities. Please be aware that this is not an application for a specific position. By submitting your information and providing your resume, you will be included in a pool of candidates for various CNP roles. If you are selected for consideration for a particular opportunity, a member of MITRE's University Recruiting team will reach out to you. You can monitor your application status here: Workday (myworkdayjobs.com). This requisition requires the candidate to have a minimum of the following clearance(s): This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s): Salary compensation range and midpoint:
$85,200 - $106,500 - $127,800 Annual Work Location Type:
Hybrid It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law. MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE's employment process, please email for general support and for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply. Benefits information may be found here . Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.

What MITRE Corporation employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom


MITRE logo

About MITRE

Sourced by ZipRecruiter

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities, and a culture of innovation that embraces diversity, inclusion, flexibility, collaboration, and career growth. If this sounds like the choice you want to make, then choose MITRE-and make a difference with us. MITRE is a trusted operator of federally funded research and development centers and we're on a mission to make the world a safer place-for all of humanity, today and in the future. To deliver on our mission, we need the world's best talent and leaders-groundbreakers and partnership-builders on a global scale in areas like healthcare, artificial intelligence, critical infrastructure resiliency, pandemic management, and cybersecurity. In return, we have the privilege of backing you with thousands of technical experts in diverse fields, a culture of innovation and knowledge sharing, access to data and resources uniquely available to MITRE through our wide-ranging partnerships across government, industry and academia.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

McLean, VA, US

Year founded

1958

Social media