Work bounded vulnerability classes against internal targets. What We Need To See: * Bachelor's degree (or equivalent experience) with 12+ years in security research or software engineering.
Work bounded vulnerability classes against internal targets. What We Need To See: * Bachelor's degree (or equivalent experience) with 12+ years in security research or software engineering.
Product Security Research Engineer
San Jose, CA · On-site
$96 - $101/hr
Pay Range: $96.12/hr - $101.12/hr Requirement/Must Have: * 6-9 years of experience in Product Security Engineering, Vulnerability Research, or Offensive Security, with a focus on deconstructing ...
Quick apply
Product Security Research Engineer
San Jose, CA · On-site
$96 - $101/hr
Pay Range: $96.12/hr - $101.12/hr Requirement/Must Have: * 6-9 years of experience in Product Security Engineering, Vulnerability Research, or Offensive Security, with a focus on deconstructing ...
Vulnerability Analysis Engineer
Ridgecrest, CA · On-site
$55K/yr
... the Research, Development, Test, and Evaluation (RDT&E) programs under the cognizance of the ... Duties include performing vulnerability and endgame analysis for Navy aircraft and weapons systems ...
Vulnerability Analysis Engineer
Ridgecrest, CA · On-site
$55K/yr
... the Research, Development, Test, and Evaluation (RDT&E) programs under the cognizance of the ... Duties include performing vulnerability and endgame analysis for Navy aircraft and weapons systems ...
Drive vulnerability research by analyzing systems, dependencies, and emerging threats to uncover exploitable weaknesses. * Operate with an offensive security mindset , proactively identifying and ...
Drive vulnerability research by analyzing systems, dependencies, and emerging threats to uncover exploitable weaknesses. * Operate with an offensive security mindset , proactively identifying and ...
Security Researcher
San Francisco, CA · On-site
The Security Researcher will build technology for vulnerability discovery, collaborate with AI researchers, and contribute to developing advanced detection capabilities. Responsibilities : • Build ...
Security Researcher
San Francisco, CA · On-site
The Security Researcher will build technology for vulnerability discovery, collaborate with AI researchers, and contribute to developing advanced detection capabilities. Responsibilities : • Build ...
Work bounded vulnerability classes against internal targets. What We Need To See: * Bachelor's degree (or equivalent experience) with 12+ years in security research or software engineering.
Work bounded vulnerability classes against internal targets. What We Need To See: * Bachelor's degree (or equivalent experience) with 12+ years in security research or software engineering.
Staff+ Researcher, Cybersecurity Products
San Francisco, CA · On-site
$405K - $485K/yr
Have deep expertise in one or more security domains, such as vulnerability research, exploit development, reverse engineering, malware analysis, incident response, or offensive security * Have built ...
Staff+ Researcher, Cybersecurity Products
San Francisco, CA · On-site
$405K - $485K/yr
Have deep expertise in one or more security domains, such as vulnerability research, exploit development, reverse engineering, malware analysis, incident response, or offensive security * Have built ...
... vulnerability discoveries, research publications, and/or developing security tools Preferred : • Understanding of pre-silicon hardware design and testing • Knowledge of key hardware security ...
... vulnerability discoveries, research publications, and/or developing security tools Preferred : • Understanding of pre-silicon hardware design and testing • Knowledge of key hardware security ...
Senior Reverse Engineer
San Diego, CA · On-site
$134K - $184K/yr
Performing vulnerability weaponization, exploit development, payload development, and exploit mitigation on a variety of challenging targets * Documenting, demonstrating, and presenting research
Senior Reverse Engineer
San Diego, CA · On-site
$134K - $184K/yr
Performing vulnerability weaponization, exploit development, payload development, and exploit mitigation on a variety of challenging targets * Documenting, demonstrating, and presenting research
Security Researcher
San Francisco, CA · On-site
About this role We're seeking an experienced Security Researcher to join our effort in building and training AI agents for vulnerability discovery and exploitation. We are building a technology ...
Security Researcher
San Francisco, CA · On-site
About this role We're seeking an experienced Security Researcher to join our effort in building and training AI agents for vulnerability discovery and exploitation. We are building a technology ...
Sr. Staff Engineer (Product Security Incident Response)
Santa Clara, CA · On-site
$151K - $245K/yr
Engage with customers, security researchers, and industry partners to discuss vulnerability details, mitigation steps, and disclosure timelines. * Maintain deep familiarity with industry ...
Sr. Staff Engineer (Product Security Incident Response)
Santa Clara, CA · On-site
$151K - $245K/yr
Engage with customers, security researchers, and industry partners to discuss vulnerability details, mitigation steps, and disclosure timelines. * Maintain deep familiarity with industry ...
C/C++, Python, etc. • Deep understanding of reverse engineering fundamentals • Experience in Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into ...
C/C++, Python, etc. • Deep understanding of reverse engineering fundamentals • Experience in Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into ...
Senior Reverse Engineer
San Diego, CA · On-site
$110K - $152K/yr
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
Senior Reverse Engineer
San Diego, CA · On-site
$110K - $152K/yr
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
Senior Reverse Engineer
San Diego, CA · On-site
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
Senior Reverse Engineer
San Diego, CA · On-site
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
C/C++, Python, etc. • Deep understanding of reverse engineering fundamentals • Experience in Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into ...
C/C++, Python, etc. • Deep understanding of reverse engineering fundamentals • Experience in Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into ...
Experience with offensive security research, vulnerability research, or exploit development ... Research or professional experience applying LLMs to security problems * Track record in ...
Experience with offensive security research, vulnerability research, or exploit development ... Research or professional experience applying LLMs to security problems * Track record in ...
Senior Reverse Engineer
San Diego, CA · On-site
$110K - $152K/yr
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
Senior Reverse Engineer
San Diego, CA · On-site
$110K - $152K/yr
Preferred : • Vulnerability research and analysis • Knowledge of weaponizing discovered vulnerabilities into exploits • Implant or software patch development • Familiarity with binary ...
Staff Threat Researcher
Sunnyvale, CA · On-site
$194K - $233K/yr
... and vulnerability data. This graph enables essential functions such as breach risk detection ... We're looking for a talented Senior Threat Researcher to provide ongoing guidance on threats ...
Staff Threat Researcher
Sunnyvale, CA · On-site
$194K - $233K/yr
... and vulnerability data. This graph enables essential functions such as breach risk detection ... We're looking for a talented Senior Threat Researcher to provide ongoing guidance on threats ...
Principal Software Reverse Engineer
San Diego, CA · On-site
$204K - $284K/yr
Experience in Vulnerability research and analysis * Knowledge of weaponizing discovered vulnerabilities into exploits Nice to haves: * Implant or software patch development * Familiarity with binary ...
Principal Software Reverse Engineer
San Diego, CA · On-site
$204K - $284K/yr
Experience in Vulnerability research and analysis * Knowledge of weaponizing discovered vulnerabilities into exploits Nice to haves: * Implant or software patch development * Familiarity with binary ...
Senior Threat Researcher, Unit 42
Sacramento, CA · On-site
$139K - $225K/yr
Job Summary As a member of the Unit 42 National Security Team (NATSEC), you will work closely with a globally distributed team of vulnerability researchers, reverse engineers, and threat intelligence ...
Senior Threat Researcher, Unit 42
Sacramento, CA · On-site
$139K - $225K/yr
Job Summary As a member of the Unit 42 National Security Team (NATSEC), you will work closely with a globally distributed team of vulnerability researchers, reverse engineers, and threat intelligence ...
Vulnerability Researcher information
See California salary details
$29.6K - $41.7K
4% of jobs
$41.7K - $53.7K
3% of jobs
$53.7K - $65.8K
18% of jobs
$66.1K is the 25th percentile. Wages below this are outliers.
$65.8K - $77.9K
9% of jobs
$77.9K - $89.9K
8% of jobs
$89.9K - $102K
3% of jobs
$102K - $114.1K
3% of jobs
The median wage is $118.6K / yr.
$114.1K - $126.1K
4% of jobs
$126.1K - $138.2K
3% of jobs
$138.2K - $150.3K
3% of jobs
$155K is the 75th percentile. Wages above this are outliers.
$150.3K - $162.3K
41% of jobs
$29.6K
$111.6K
$162.3K
How much do vulnerability researcher jobs pay per year?
What is a vulnerability researcher?
A Vulnerability Researcher is a cybersecurity professional who identifies, analyzes, and reports security flaws in software, hardware, and networks. They use reverse engineering, fuzzing, and static analysis techniques to discover vulnerabilities before malicious actors can exploit them. Their work helps improve security by collaborating with developers and security teams to implement patches and mitigations. Often, they contribute to responsible disclosure programs or work for organizations focused on threat intelligence and cybersecurity defense.
What does a vulnerability researcher do?
A typical day for a Vulnerability Researcher involves researching the latest security vulnerabilities, analyzing software or hardware for potential weaknesses, and developing proof-of-concept exploits or mitigation techniques. You may spend time reviewing code, using reverse engineering or fuzzing tools, and documenting your findings for technical and non-technical stakeholders. Collaboration with security teams, software engineers, and sometimes external vendors is common to ensure vulnerabilities are addressed properly. The work is dynamic, often requiring you to stay updated on emerging threats and continuously refine your research skills.
What are the key skills and qualifications needed to thrive as a vulnerability researcher?
To thrive as a Vulnerability Researcher, you need a strong background in computer science, proficiency in programming languages like Python or C/C++, and an in-depth understanding of operating systems and networking. Familiarity with penetration testing tools (such as Metasploit or Burp Suite), reverse engineering software, and certifications like OSCP or CEH are commonly sought after. Analytical thinking, attention to detail, and strong problem-solving and communication skills distinguish top performers in this field. These abilities are crucial for identifying and analyzing security weaknesses, communicating findings effectively, and helping organizations proactively manage cybersecurity risks.
What are the most commonly searched types of Vulnerability Researcher jobs in California?
The most popular types of Vulnerability Researcher jobs in California are:
What are popular job titles related to Vulnerability Researcher jobs in California?
For Vulnerability Researcher jobs in California, the most frequently searched job titles are:
What job categories do people searching Vulnerability Researcher jobs in California look for?
The top searched job categories for Vulnerability Researcher jobs in California are:
What cities in California are hiring for Vulnerability Researcher jobs?
Cities in California with the most Vulnerability Researcher job openings:

Security Research Engineer, AI Safety and Security Engineering
Santa Clara, CA • On-site
Full-time
Posted 17 days ago
Nvidia rating
9.6
Based on 17 frontline employees who took The Breakroom Quiz
7th of 244 rated software companies
Job description
Validation here requires meticulous care to confirm reports are real and reachable rather than noise, while patching requires ensuring fixes repair flaws, protect existing behavior, and hold up under strict revalidation. Working alongside harness and evaluation engineers, you will establish high engineering standards, document your reasoning for independent security reviews, and ensure your methods run reliably with fully traceable evidence. AI-assisted workflows are an integral part of this job, but so is maintaining a healthy, disciplined skepticism about their outputs. Beyond immediate fixes, your work will teach the entire program what trustworthy patching looks like while actively helping decide which vulnerability classes the team tackles next. Ultimately, we hold our results to an exceptionally high bar and value specific, verifiable proof of your technical expertise-such as CVEs, advisories, or original security tools-over polished phrasing.
What You'll Be Doing:
- Validation methods: Develop techniques that confirm vulnerabilities are real and reachable.
- Patch methods: Advance approaches for generating and verifying safe fixes.
- Quality standards: Define correctness, regression, and revalidation standards with reviewers.
- Applied research: Work bounded vulnerability classes against internal targets.
What We Need To See:
- Bachelor's degree (or equivalent experience) with 12+ years in security research or software engineering.
- Security foundations: Hands-on vulnerability research, fuzzing, program analysis, or secure development in C, C++, or Python.
- Fix quality: Rigor about what makes a fix correct and safe, including regression and behavior preservation.
- AI-assisted workflows: Comfort using AI-assisted tools for analysis and development.
Ways to Stand Out from the Crowd:
- Public research: CVEs, advisories, or publications in vulnerability research.
- Analysis tooling: Experience building or extending fuzzers, static analyzers, or symbolic-execution tools.
- Agentic ML: Familiarity with LLM-based coding or analysis agents.
With competitive salaries and a generous benefits package, NVIDIA is widely considered to be one of the technology industry's most desirable employers. We have some of the most forward-thinking and versatile people in the world working with us, and our engineering teams are growing fast in some of the most impactful fields of our generation: Confidential Computing and Data. If you're a creative engineer who enjoys autonomy and shares our passion for technology, we want to hear from you.
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 431,250 USD for Level 6.
You will also be eligible for equity and benefits.
Applications for this job will be accepted at least until August 2, 2026.
This posting is for an existing vacancy.
NVIDIA uses AI tools in its recruiting processes.
NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
About Nvidia
Sourced by ZipRecruiter
NVIDIA has been transforming computer graphics, PC gaming, and accelerated computing for more than 25 years. It's a unique legacy of innovation that's fueled by great technology--and amazing people. Today, we're tapping into the unlimited potential of AI to define the next era of computing. An era in which our GPU acts as the brains of computers, robots, and self-driving cars that can understand the world. Doing what's never been done before takes vision, innovation, and the world's best talent.
Industry
Computer and electronic product manufacturing
Company size
10,000+ Employees
Headquarters location
Santa Clara, CA, US
Year founded
1993