1

Vulnerability Researcher Contractor Jobs in Michigan

Vulnerability Researcher Contractor information

What are the key skills and qualifications needed to thrive as a vulnerability researcher contractor?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a vulnerability researcher contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What does a vulnerability researcher contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

What are popular job titles related to Vulnerability Researcher Contractor jobs in Michigan? For Vulnerability Researcher Contractor jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Vulnerability Researcher Contractor jobs in Michigan look for? The top searched job categories for Vulnerability Researcher Contractor jobs in Michigan are:
What cities in Michigan are hiring for Vulnerability Researcher Contractor jobs? Cities in Michigan with the most Vulnerability Researcher Contractor job openings:

Cyber Security Framework Engineer - Remote

micro1 AI

Detroit, MI • Remote

$50 - $90/hr

Part-time

This job post has expired today. Applications are no longer accepted.


Job description

Role Title: Red Team Lead (Offensive Cybersecurity)


Role Type: Contractor


Location: Remote


micro1 is engaging Red Team Leads (Offensive Cybersecurity) to contribute expertise to a customer's critical cybersecurity project. In this role, you'll apply your expertise to help train next-generation AI systems. Your work will shape how models learn, reason, and perform through high-quality, real-world input. No prior experience in AI is required — your domain knowledge is what matters.


Scope of Work

  1. Develop comprehensive taxonomies for cyber-capability tasks and attack stages relevant to modern threat landscapes.
  2. Design and validate evaluation frameworks for offensive security, focusing on real-world scenarios involving exploit chains, malware, cloud/appsec, and social engineering.
  3. Create safe and effective proxy tasks to simulate advanced attack vectors while maintaining strict boundaries and ethical controls.
  4. Formulate robust scoring rubrics to assess attack sophistication, coverage, and impact across diverse domains.
  5. Review, critique, and enhance benchmarks for red team operations to ensure alignment with evolving security risks and best practices.
  6. Produce clear, well-documented methodologies and technical write-ups, communicating complex security concepts to both technical and non-technical audiences.
  7. Collaborate asynchronously with project stakeholders to iterate on frameworks and incorporate feedback into deliverables.


Preferred Qualifications

  1. 5+ years of hands-on experience in offensive cybersecurity, red teaming, exploit development, or vulnerability research (8–20 years preferred for senior contributors).
  2. Track record as a principal security engineer, exploit developer, cloud red-team lead, malware reverse-engineer, or security researcher specializing in attack chains or social engineering.
  3. Deep expertise in cyber attack methodologies, exploit chains, and cloud/application security assessments.
  4. Strong background in malware analysis, reverse engineering, and/or social engineering tactics and defenses.
  5. Demonstrated ability to produce clear, actionable written and verbal communication for a variety of audiences.
  6. Advanced degree, relevant professional security certifications, or equivalent operational experience highly valued.
  7. Experience building benchmarking or evaluation frameworks in cybersecurity is a plus.