1

Vulnerability Researcher Contractor Jobs in Sandy Spring, MD

Android Mobile Reverse Engineer LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a skilled Android Mobile

At NetSage, we are more than a government contractor-we are a mission-focused partner dedicated to advancing national security through exceptional cyber expertise. We believe our success begins with

Job Description iOS Mobile Capability Developer Columbia, MD | Full Time | TS/SCI with Full-Scope Polygraph Required Position: iOS Mobile Capability Developer (Computer Scientist, Level 1) Location:

Showing results 41-60

Vulnerability Researcher Contractor information

See Sandy Spring, MD salary details

$30.5K

$114.9K

$167.1K

How much do vulnerability researcher contractor jobs pay per year?

As of Sep 13, 2026, the average yearly pay for vulnerability researcher contractor in Sandy Spring, MD is $114,889.00, according to ZipRecruiter salary data. Most workers in this role earn between $68,100.00 and $156,400.00 per year, depending on experience, location, and employer.

What does a vulnerability researcher contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What are the key skills and qualifications needed to thrive as a vulnerability researcher contractor?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a vulnerability researcher contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

What cities near Sandy Spring, MD are hiring for Vulnerability Researcher Contractor jobs?

Cities near Sandy Spring, MD with the most Vulnerability Researcher Contractor job openings:

CNO Developer 1 - PRIME Contract - FS Poly

Annapolis Junction, MD • On-site

Full-time

Medical, Retirement, PTO

Re-posted 3 days ago


Job description

Our client is a distinguished Women-Owned Small Business and technical defense contractor providing mission-critical engineering to the IC and DoD. Operating as both a prime and subcontractor, they offer a collaborative environment where hands-on experts serve as trusted advisors across the full SDLC, including cloud-native development, low-level/CNO engineering, and AI/ML integration. They prioritize long-term stability through an industry-leading compensation model featuring 100% company-paid medical premiums, 32 days of PTO, and an 11% non-matching 401(k) contribution with immediate vesting. This package also includes the unique flexibility to trade select benefits for an increased hourly rate, alongside annual stipends for professional development, personal technology, and wellness. If you are seeking a purpose-driven role with a team that values your technical expertise and personal well-being, we invite you to explore the elite opportunities our client has to offer.
They are seeking a CNO Developer to support their PRIME contract.  
Relevant qualifications:
-Bachelor's Degree in Computer Science or similar (or additional experience)
-7+ years of professional experience
-2+ years of experience with coding languages such as C/C++, Python, Java, or C#
-2+ years of experience with DevOps tools and techniques
-1+ year of experience with CNO development, vulnerability research, reverse engineering, or similar
-1+ year of experience with CI/CD pipelines
This role is located in Annapolis Junction, MD and the work requires a TS/SCI + Full-Scope Polygraph. 
Apply @ https://careers.stanleyreid.com/ or contact our team for more info: cwells@stanleyreid.com or abuzzettijohnson@stanleyreid.com