1

Vulnerability Researcher Contractor Jobs (NOW HIRING)

Windows Vulnerability Research

Sterling, VA · On-site

$203K/yr

Required Qualifications In addition to meeting all baseline technical requirements for contractor ... Vulnerability Research (VR) * Reverse Engineering (RE) * Exploit development and exploitation

Windows Vulnerability Research

Sterling, VA · On-site

$203K/yr

Required Qualifications In addition to meeting all baseline technical requirements for contractor ... Vulnerability Research (VR) * Reverse Engineering (RE) * Exploit development and exploitation

next page

Showing results 1-20

Vulnerability Researcher Contractor information

See salary details

$30K

$113.1K

$164.5K

How much do vulnerability researcher contractor jobs pay per year?

As of Jun 19, 2026, the average yearly pay for vulnerability researcher contractor in the United States is $113,102.00, according to ZipRecruiter salary data. Most workers in this role earn between $67,000.00 and $154,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Researcher Contractor, and why are they important?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a Vulnerability Researcher Contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What does a Vulnerability Researcher Contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

More about Vulnerability Researcher Contractor jobs
What cities are hiring for Vulnerability Researcher Contractor jobs? Cities with the most Vulnerability Researcher Contractor job openings:
What states have the most Vulnerability Researcher Contractor jobs? States with the most job openings for Vulnerability Researcher Contractor jobs include:
What job categories do people searching Vulnerability Researcher Contractor jobs look for? The top searched job categories for Vulnerability Researcher Contractor jobs are:
Infographic showing various Vulnerability Researcher Contractor job openings in the United States as of June 2026, with employment types broken down into 5% Locum Tenens, 3% As Needed, 86% Full Time, 3% Part Time, and 3% Contract. Highlights an 80% Physical, 6% Hybrid, and 14% Remote job distribution, with an average salary of $113,102 per year, or $54.4 per hour.

Vulnerability Researcher / Reverse Engineer

Intezra, Inc.

Columbia, MD • On-site

$150K - $250K/yr

Full-time

Dental, Vision, Retirement, PTO

Posted yesterday

Be an early applicant


Job description

Job Description

Vulnerability Researcher / Reverse Engineer

Columbia, MD | Full Time | Top Secret clearance or above required*

Position: Vulnerability Researcher / Reverse Engineer

Location: Columbia, MD (on-site)

Category: Software Development / Reverse Engineering / Vulnerability Research

Clearance Requirement: Active Top Secret or above (TS/SCI or TS/SCI with Polygraph welcome)

Compensation: $150,000 – $250,000 (annualized USD)

Experience Requirement:

  • 5+ years of software engineering, reverse engineering, or vulnerability research experience with a Bachelor's degree, OR

  • 3+ years with a Master's degree, OR

  • 4 additional years of relevant experience in lieu of a degree

Description

You will act as a general-purpose, 'jack of all trades' reverse engineer / developer embedded within a small, fast-moving team. You'll combine reverse engineering of complex, networked code bases with hands-on development and testing in support of the team's work — and you'll bring enough analyst instinct to help frame problems, run down leads, and explain what you find to the people who need to act on it.

This is hands-on, deeply technical work where your impact is visible quickly: what you analyze, what you build, and what you discover all feed directly into the team's roadmap.

Responsibilities

  • Reverse engineer complex networked code bases to drive understanding and surface vulnerabilities.

  • Develop and test software in support of the team's research and capability needs.

  • Collaborate with analysts on their goals and identify where your effort moves them forward.

  • Help customers articulate what they actually want, then translate that into clear technical work.

  • Use analyst skills to run down your own analytical leads when needed.

  • Document findings, code, and design decisions so the rest of the team can build on them.

Skills Requirements

  • Solid reverse engineering skills across at least one platform family (Linux, Windows, embedded, or mobile).

  • Strong software development skills in at least one systems language (C, C++, Python, Go, or Rust).

  • Familiarity with network protocols and analysis of network traffic.

  • Comfort working independently as well as collaboratively on a small team.

  • Familiarity with Git and Atlassian tooling (Jira, Confluence).

  • Clear written and verbal communication.

Nice to Haves

  • Experience discovering novel software vulnerabilities.

  • Experience with exploit development.

  • Background reverse-engineering firmware, embedded devices, or mobile platforms.

  • Familiarity with Ghidra, IDA Pro, radare2, or similar RE tooling.

  • Experience with vulnerability research methodologies (fuzzing, static analysis, symbolic execution).

Compensation Employment Policy

Salary is determined by multiple factors, including location, education, experience, skills, and organizational requirements. The projected compensation range for this position is $150,000 – $250,000 (annualized USD).

Benefits Overview

At Intezra, Inc., we offer a comprehensive benefits package designed to support long-term career growth and work-life balance:

  • Three CareFirst medical plans available; Intezra pays up to 100% of healthcare premiums and up to 100% of deductibles (based on plan selection) for employees and dependents

  • Intezra pays 100% for CareFirst Dental and Vision plans for employees and dependents

  • 401(k): 15% company contribution (no match required)

  • PTO: 160 hours, increasing with seniority

  • 12 Floating Holidays

  • 4 Code Red Days

EEO Statement

Intezra, Inc. provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any kind without regard to race, color, religion, age, sex, national origin, disability status, genetics, pregnancy, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

About Us

Intezra Inc. is a small business prime contractor for all realms of cyber and AI/ML development, from tactical-level tools and capabilities to enterprise-level infrastructure and operations. Our leadership team and staff have helped solve the most complex challenges for the intelligence community for over 15 years.

, About Intezra, Inc.

Intezra Inc. is a small business prime contractor for all realms of cyber and AI/ML development, from tactical-level tools and capabilities to enterprise-level infrastructure and operations. Our leadership team and staff have helped solve the most complex challenges for the intelligence community for over 15 years.