2

Vulnerability Researcher Remote Jobs in Novato, CA

Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their ... Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes ...

... vulnerability classes. More broadly, this is a mandate to rethink traditional security tooling for ... If you're located beyond that distance, the role is fully remote. For location-specific details ...

Vulnerability Researcher Remote information

See Novato, CA salary details

$35.2K

$132.8K

$193.1K

How much do vulnerability researcher remote jobs pay per year?

As of Sep 4, 2026, the average yearly pay for vulnerability researcher remote in Novato, CA is $132,789.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,700.00 and $180,800.00 per year, depending on experience, location, and employer.

What does a vulnerability researcher do, especially in a remote role?

A Vulnerability Researcher is responsible for identifying, analyzing, and reporting security weaknesses in software, hardware, or network systems. Working remotely, they use specialized tools and techniques to discover vulnerabilities, assess potential impacts, and sometimes develop proof-of-concept exploits. Their findings help organizations improve security by patching vulnerabilities before they can be exploited by malicious actors. Effective communication and collaboration with security teams are also important aspects of the role, even when working from afar.

What are the key skills and qualifications needed to thrive as a vulnerability researcher remote, and why are they important?

To thrive as a Vulnerability Researcher (Remote), you need strong expertise in cybersecurity fundamentals, reverse engineering, and exploit development, typically supported by a degree in computer science or related certifications such as OSCP or CEH. Familiarity with technical tools like IDA Pro, Ghidra, fuzzers, debuggers, and scripting languages (e.g., Python) is essential for analyzing vulnerabilities. Analytical thinking, problem-solving, and effective communication are key soft skills that help in documenting findings and collaborating with distributed teams. These skills ensure the accurate identification and mitigation of security risks, which is crucial for protecting organizations against cyber threats.

What are some common challenges faced by remote vulnerability researchers and how can they be addressed?

Remote vulnerability researchers often encounter challenges such as staying current with rapidly evolving threat landscapes, maintaining effective communication with distributed teams, and accessing secure lab environments for testing. To address these, it's important to regularly engage in professional development, participate in virtual security communities, and utilize secure cloud-based lab solutions. Additionally, setting clear communication protocols and using collaboration tools can help ensure smooth teamwork and project progress.

What is the difference between Vulnerability Researcher Remote vs Penetration Tester Remote?

AspectVulnerability Researcher RemotePenetration Tester Remote
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, with emphasis on offensive security skills
Work EnvironmentResearch-focused, analyzing vulnerabilities in software and systemsSimulating attacks to identify security weaknesses
Industry UsageUsed in cybersecurity firms, tech companies, and research labsCommon in consulting firms, security service providers, and internal security teams
Search & Comparison IntentUnderstanding roles in vulnerability discovery and researchComparing offensive security roles and testing approaches

Vulnerability Researcher Remote and Penetration Tester Remote both focus on cybersecurity but differ in approach. Researchers analyze and discover vulnerabilities, while testers simulate attacks to evaluate security. Both roles require similar certifications and are employed in related industries, but their daily tasks and objectives vary.

What job categories do people searching Vulnerability Researcher Remote jobs in Novato, CA look for?

The top searched job categories for Vulnerability Researcher Remote jobs in Novato, CA are:

What cities near Novato, CA are hiring for Vulnerability Researcher Remote jobs?

Cities near Novato, CA with the most Vulnerability Researcher Remote job openings:

Manager, Security Engineering

Cohere

San Francisco, CA • On-site, Remote

$320K - $385K/yr

Full-time

Medical, Dental, Retirement, PTO

Re-posted 9 days ago


Job description

Who are we?

Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.

We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.

We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.

We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!

As a Manager of Security Engineering, your key responsibilities include:

  • Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues

  • Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals.

  • Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements.

  • Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts

  • Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code

  • Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications

  • Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program

  • Security Architecture Review: Collaborate with development teams to review and validate security architecture and design patterns

  • Secure SDLC Integration: Embed security practices throughout the software development lifecycle, working closely with engineering and product teams

  • Team Leadership: Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship

  • Metrics and Reporting: Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders

  • Compliance and Standards: Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements

You may be a good fit if:

  • You have 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs.

  • Proven experience with SAST, DAST, and penetration testing methodologies and tools

  • Proficiency with programming languages (Python, GoLang, etc.) and web technologies

  • Experience with cloud platforms (AWS, GCP, Azure) and container security

  • Excellent communication and interpersonal skills with ability to influence technical and non-technical stakeholders

  • Experience building and managing high-performing security teams

  • You are comfortable with ambiguity and are able to make informed decisions with little data.

  • You employ a flexible and constructive approach when solving problems.

  • You are able to make trade-offs between build vs. buy decisions—help build solutions and be able to review what tools are available.

  • You understand secure engineering best practices, can articulate problem statements, and propose solutions to both technically savvy and non-technical audiences.

  • You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls.

Apply:

If you are passionate about solving complex revenue challenges in a dynamic AI environment and want to join a team that values technical excellence and innovation, we encourage you to apply.

Working Location:

Remote US or Canada

Compensation:

Cohere is committed to fair and transparent pay practices. The salary range listed for this role reflects the expected base compensation. Actual compensation offered will be determined by factors such as location, level, job-related knowledge, skills, education, and experience.

For candidates in the US, the Compensation Range is: $225,000 - $325,000 [USD]

For candidates in Canada, the Compensation Range is: $320,000 - 385,000 [CAD]

Full-Time Employees at Cohere enjoy these Perks:

  • A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.

  • Full health and dental benefits, including a separate budget for mental health.

  • RRSP matching, 401K, Pension Scheme.

  • 100% Parental Leave top-up for up to 6 months, for either parent.

  • Annual enrichment benefits:

    Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.

    Education & learning stipend for conferences, courses, and coaching.

  • 6 weeks of paid vacation (30 working days!)

  • Budget for traveling to other offices if you are remote, plus an annual company offsite.

How and Where We Work:

  • Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.

  • For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.

  • For those not near an office: a co-working benefit so you can work alongside others in your city.

  • Everyone receives a $500 home office stipend to set up your workspace properly.

If any of the above doesn’t line up exactly with your experience, we still encourage you to apply.

We strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form, and we will work together to meet your needs.

We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn't limit the applications our recruiters may review or consider.

Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers page.