1

Vulnerability Researcher Contractor Jobs (NOW HIRING)

This role serves as the primary point of contact between the Contractor and the Government, with ... vulnerability researchers, and program support staff * Manage all financial and business processes ...

iOS Vulnerability Engineer (Software)

Reston, VA · On-site

$145K/yr

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

iOS Vulnerability Engineer (Software)

Tysons, VA · On-site

$140K/yr

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

iOS Vulnerability Engineer (Software)

Tysons, VA · On-site

$140K/yr

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

... Security Researcher, Software Security Analyst, Mobile App Penetration Tester, Cybersecurity ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

next page

Showing results 1-20

Vulnerability Researcher Contractor information

See salary details

$30K

$113.1K

$164.5K

How much do vulnerability researcher contractor jobs pay per year?

As of Jun 19, 2026, the average yearly pay for vulnerability researcher contractor in the United States is $113,102.00, according to ZipRecruiter salary data. Most workers in this role earn between $67,000.00 and $154,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Researcher Contractor, and why are they important?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a Vulnerability Researcher Contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What does a Vulnerability Researcher Contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

More about Vulnerability Researcher Contractor jobs
What cities are hiring for Vulnerability Researcher Contractor jobs? Cities with the most Vulnerability Researcher Contractor job openings:
What states have the most Vulnerability Researcher Contractor jobs? States with the most job openings for Vulnerability Researcher Contractor jobs include:
What job categories do people searching Vulnerability Researcher Contractor jobs look for? The top searched job categories for Vulnerability Researcher Contractor jobs are:
Infographic showing various Vulnerability Researcher Contractor job openings in the United States as of June 2026, with employment types broken down into 5% Locum Tenens, 3% As Needed, 86% Full Time, 3% Part Time, and 3% Contract. Highlights an 80% Physical, 6% Hybrid, and 14% Remote job distribution, with an average salary of $113,102 per year, or $54.4 per hour.
Senior CANO Developer

Senior CANO Developer

Oak Grove Technologies LLC

Fort Belvoir, VA • On-site

Full-time

Medical, PTO

Posted 17 days ago


Job description

Description:

Oak Grove Technologies, LLC, a dynamic and fast-growing federal contractor, is seeking a highly skilled and motivated Senior CANO Developer to join our team! In this role, you will conduct vulnerability research, exploitation, and perform N-day weaponization against wireless and mobile (Android/iOS) targets.


Oak Grove Technologies is a Service-Disabled Veteran-Owned Business based in Raleigh, NC, with a Test and Training Center located near Fort Bragg and Camp Mackall. With over 20 years of expertise in training, consulting, technology, and operational support, the company provides services to the military, government, and law enforcement. Committed to excellence, innovation, and national security, Oak Grove Technologies fulfills federal defense contracts and actively supports veterans through sponsorships and events. Driven by its mission-focused approach, the company seeks top talent to develop impactful solutions.


Oak Grove Technologies offers a competitive compensation and benefits package.

Requirements:

What You'll Be Doing

  • Offensive capability development.
  • Develop exploits, shellcode, and techniques to bypass mitigations.
  • Perform dynamic analysis, code reviews, troubleshooting, and debugging.
  • Conduct vulnerability research, exploitation, and perform N-day weaponization against wireless and mobile (Android/iOS) targets.

What Desired Skills You'll Bring

  • Development and use of Command-and-Control (C2) frameworks/capabilities, especially Cobalt Strike.
  • Host-based and network-based forensics, cyber incident response, cyber-criminal investigations, intrusion detection/analysis, and designing countermeasures and mitigations for programming language weaknesses and vulnerabilities.
  • Advanced cyber red teaming, network penetration testing, security operations center analysis, defensive and offensive cyber operations.
  • Malware development and analysis, including binary disassembly, binary decomplication, dynamic analysis, and network/communication protocol analysis.
  • Software vulnerability research and exploit development, including exploits, shellcode, and bypass techniques for mitigations such as NX (nonexecutable stack), ASLR, and advanced exploit protections.
  • Development of Windows kernel modules and strong familiarity with Windows Active Directory.
  • Tool development leveraging the Windows API/Win32 modules.
  • Expertise in AV/EDR evasion techniques.
  • 3-5 years development industry experience.

What Required Skills You'll Bring

  • U.S. Citizenship and an active Top Secret clearance with SCI eligibility are required. (Highly qualified candidates with a Secret Clearance may also be considered.)
  • Minimum of 8 years of overall professional experience.
  • 3+ years of experience as a Software Developer.
  • Demonstrated experience in cyber-enabling close access operations.
  • Demonstrated experience in vulnerability research, exploitation, and N-day weaponization against wireless and mobile (Android/IOS) targets.
  • Proficiency in C and C# programming and development of Beacon Object Files (BOFs).
  • 1+ years’ experience in offensive capability development for Windows.
  • 1+ years’ experience working in a Scrum/Agile environment.
  • Ability to pass the DCART Senior Developer Aptitude Test (SDAT) prior to joining DCART as a developer.
  • Willingness and ability to travel 15% (CONUS/OCONUS).

Security Clearance Requirements:

U.S. Citizenship and an active Top Secret clearance with SCI eligibility are required. (Highly qualified candidates with a Secret Clearance may also be considered.)


Compensation and Benefits:

Competitive Pay, PTO, Health Benefits.


If you are a highly motivated Senior Close Access Network Operator (CANO) Developer and ready to apply your expertise in a high-impact role, we encourage you to join our mission.


Oak Grove Technologies is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.

Oak Grove Technologies, LLC participates in E-Verify to determine an individual's identity and employment eligibility to work in the United States. E-Verify is a service of DHS and SSA.