1

Vulnerability Researcher Jobs in Oregon (NOW HIRING)

Senior Security Research Engineer

OR ยท On-site +1

$114K - $156K/yr

Reporting to the Director of Global Vulnerability Management, you will serve as a Senior Security Research Engineer and technical lead within SIE's Global Vulnerability Management team. You will lead ...

Serve as the Surgical R&D cybersecurity representative for vulnerability disclosure and incident response activities, supporting investigations, impact assessments, root cause analyses, and ...

Vulnerability Management : Contribute to our vulnerability management program, including triaging ... Contributions to open-source security tooling or active participation in the security research ...

Develop automated systems and low-level tooling to perform vulnerability research and reduce manual security overhead in build, test, and release workflows. Act as a security liaison between OC and ...

Staff Security Engineer - SecOps & Threats

OR ยท On-site +1

$231K - $265K/yr

... vulnerability assessments, and log analysis * Engage vendors, Infrastructure, IT, GRC, Cloud, and ... Research emerging threats, publicly disclosed vulnerabilities or attack vectors, and proactively ...

Field Strategist

OR ยท On-site +1

$121K - $156K/yr

This could look like complex systems research in academia, policy research at a think tank, market ... Software security, vulnerability analysis (or related). * Hardware security or hardware supply ...

Senior Application Security Engineer

OR ยท On-site +1

$180K - $225K/yr

Distributed computing and related vulnerability experience. * Running a Security Champions program ... Security conference talks or published research. Compensation * The estimated pay range for this ...

next page

Showing results 1-20

Vulnerability Researcher information

See Oregon salary details

$31.7K

$119.6K

$173.9K

How much do vulnerability researcher jobs pay per year?

As of Aug 24, 2026, the average yearly pay for vulnerability researcher in Oregon is $119,581.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,800.00 and $162,800.00 per year, depending on experience, location, and employer.

What is a vulnerability researcher?

A Vulnerability Researcher is a cybersecurity professional who identifies, analyzes, and reports security flaws in software, hardware, and networks. They use reverse engineering, fuzzing, and static analysis techniques to discover vulnerabilities before malicious actors can exploit them. Their work helps improve security by collaborating with developers and security teams to implement patches and mitigations. Often, they contribute to responsible disclosure programs or work for organizations focused on threat intelligence and cybersecurity defense.

What does a vulnerability researcher do?

A typical day for a Vulnerability Researcher involves researching the latest security vulnerabilities, analyzing software or hardware for potential weaknesses, and developing proof-of-concept exploits or mitigation techniques. You may spend time reviewing code, using reverse engineering or fuzzing tools, and documenting your findings for technical and non-technical stakeholders. Collaboration with security teams, software engineers, and sometimes external vendors is common to ensure vulnerabilities are addressed properly. The work is dynamic, often requiring you to stay updated on emerging threats and continuously refine your research skills.

What are the key skills and qualifications needed to thrive as a vulnerability researcher?

To thrive as a Vulnerability Researcher, you need a strong background in computer science, proficiency in programming languages like Python or C/C++, and an in-depth understanding of operating systems and networking. Familiarity with penetration testing tools (such as Metasploit or Burp Suite), reverse engineering software, and certifications like OSCP or CEH are commonly sought after. Analytical thinking, attention to detail, and strong problem-solving and communication skills distinguish top performers in this field. These abilities are crucial for identifying and analyzing security weaknesses, communicating findings effectively, and helping organizations proactively manage cybersecurity risks.

What are popular job titles related to Vulnerability Researcher jobs in Oregon?

For Vulnerability Researcher jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Vulnerability Researcher jobs in Oregon look for?

The top searched job categories for Vulnerability Researcher jobs in Oregon are:

Infographic showing various Vulnerability Researcher job openings in Oregon as of August 2026, with employment types broken down into 100% Full Time. Highlights an 35% In-person, and 65% Remote job distribution, with an average salary of $119,581 per year, or $57.5 per hour.

Senior Security Research Engineer

PlayStation Global

OR โ€ข On-site, Remote

$114K - $156K/yr

Full-time

Posted 17 days ago


Job description

Reporting to the Director of Global Vulnerability Management, you will serve as a Senior Security Research Engineer and technical lead within SIE's Global Vulnerability Management team. You will lead complex work that advances our Threat Exposure Management capability and supports our transition to a Continuous Threat Exposure Management operating model, while remaining directly engaged in vulnerability research, analysis, security validation, prioritization, and remediation support.

You will partner across Information Security, engineering, technology, and business teams to improve how SIE discovers, prioritizes, validates, and mobilizes action on security risks. You will translate annual TEM goals into defined workstreams, delivery plans, success measures, and repeatable operating practices that improve visibility, decision-making, remediation outcomes, and program scale.
Responsibilities

  • Lead complex Global Vulnerability Management workstreams that advance SIE's Threat Exposure Management capability and transition toward a Continuous Threat Exposure Management operating model across discovery, prioritization, validation, and mobilization.
  • Translate annual TEM goals into defined delivery plans, milestones, success measures, dependencies, and repeatable operating practices. Monitor progress, identify barriers, and adjust execution to improve outcomes.
  • Lead hands-on vulnerability research and technical analysis to confirm security conditions, eliminate false positives, characterize exploitability and business impact, and provide actionable remediation or mitigation guidance.
  • Improve the discovery and assessment of vulnerabilities across SIE network, cloud, endpoint, application, container, and other technology environments.
  • Develop risk-based prioritization using vulnerability and threat intelligence, exploitation evidence, asset and business context, control effectiveness, and remediation considerations.
  • Lead security validation activities and develop proofs of concept when appropriate to distinguish material risk, evaluate defensive controls, and support informed decisions.
  • Partner with Information Security teams and technology owners to mobilize remediation, clarify ownership, establish effective handoffs, resolve barriers, and measure progress through remediation, mitigation, or accepted disposition.
  • Evolve GVM platforms, integrations, data, analytics, automation, and AI-enabled workflows to improve coverage, data quality, consistency, decision speed, and operational scale.
  • Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences through clear reports and recommendations.
  • Mentor engineers and partner teams, contribute to technical standards and procedures, and improve the quality of vulnerability analysis, validation, documentation, and delivery.
  • Maintain current knowledge of relevant vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices.
  • Some travel may be required.
Qualifications
  • 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial experience in vulnerability management, security research, or exposure management.
  • Bachelor's degree or equivalent in computer science, information security, or a related discipline.
  • Experience leading complex technical workstreams across multiple teams, translating objectives into delivery plans, and achieving measurable outcomes without relying on direct reporting authority.
  • Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
  • Experience assessing vulnerabilities across several technology domains, such as operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure.
  • Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and their supporting integrations.
  • Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK, with the ability to apply that information to vulnerability prioritization.
  • Experience using scripting, programming, APIs, or automation to improve security analysis and operational workflows. Relevant technologies may include Python, SQL, Bash, PowerShell, JavaScript, or comparable languages.
  • Experience analyzing and contextualizing security data to connect technical findings with asset, service, business, threat, control, and remediation information.
  • Familiarity with software engineering practices such as version control, testing, code review, CI/CD, reusable components, and controlled production releases.
  • Ability to communicate complex security conditions, priorities, tradeoffs, and recommendations clearly to technical, operational, and leadership audiences.
  • Experience mentoring engineers or analysts and influencing technical practices across teams.
Desired qualifications
  • Experience helping evolve a traditional vulnerability-management function toward a TEM or CTEM operating model.
  • Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development.
  • Experience securing cloud, container, application, or build-pipeline environments and integrating security capabilities into engineering workflows.
  • Experience with security-data and analytics platforms such as Snowflake, Domo, or comparable technologies.
  • Experience applying automation, advanced analytics, or AI-enabled capabilities to vulnerability analysis, prioritization, validation, or remediation workflows.