
Senior Security Researcher
Primary stack
Nice to have's
Job description
About the Position
Senior Security Researcher
Remote - US (East / Central)
About the Company
Cobalt was founded on the belief of a fundamental human aspiration: the desire to live better and safer. It all started in 2013, when our founders realized that pentesting can be better. Today our diverse, fully remote team is committed to helping organizations of all sizes with seamless, effective, and collaborative Offensive Security Testing that empower organizations to OPERATE FEARLESSLY and INNOVATE SECURELY.
Our customers can start a pentest in as little as 24 hours and integrate with advanced development cycles thanks to the powerful combination of our SaaS platform coupled with an exclusive community of testers known as the Cobalt Core. Accepting just 5% of applicants, the Cobalt Core boasts over 400 closely vetted and highly skilled testers who jointly conduct thousands of tests each year and are at the forefront of identifying and helping remediate risk across a dynamically changing attack surface.
Cobalt is an Equal Opportunity Employer and we strive to build a diverse and inclusive workforce at our company. At Cobalt we aspire to engage with diverse individuals, communities, and organizations in order to continue to nurture our unique rich diverse culture. Join our team, and be your true self to do your best work.
Responsibilities
As a Senior Security Researcher at Cobalt.io, you will:
- Conduct advanced vulnerability research and security assessments across modern application and operating system stacks, cloud infrastructure, and critical enterprise systems.
- Identify impactful security flaws, develop potential exploit techniques, and collaborate with cross-functional teams to strengthen customer security postures.
- Research emerging threat vectors and maintain industry-leading testing guidelines across cloud environments, APIs, mobile platforms, and modern AI/ML technologies.
- Translate research findings into scalable security assessment capabilities, automated testing workflows, and platform intelligence.
- Partner with engineering, product, and operations teams to translate complex security research into actionable customer value and platform improvements.
- Provide technical guidance, benchmarking, and mentorship to junior researchers and community members.
- Represent Cobalt in the security research community through high-impact technical blog posts, advisories, whitepapers, and conference presentations (e.g., DEF CON, Black Hat, BSides).
Requirements
- 7+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering (or 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling).
- Technical Depth across Modern Stacks: Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust), operating system security fundamentals (Linux/Windows/macOS internals), and containerized cloud environments (Docker, Kubernetes, AWS/GCP).
- Exploit Analysis & Crafting: Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation).
- Tooling & Automation Skills: Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities.
- Clear Technical Communication: Ability to document complex technical findings into clear, actionable remediation guidance for engineers, product teams, and executive stakeholders.
- US-Based: Strictly limited to candidates residing in the United States (EST or CST time zone alignment preferred for team).
Nice to Have
- Emerging Technology Security: Familiarity with modern AI/ML security concepts, LLM risk models, and novel software integrations.
- Reverse Engineering Tooling: Hands-on experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB debugging.
- CVE & Research Track Record: Published CVEs, security advisories, or bug bounty hall-of-fame recognitions.
- Industry Certifications: Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist.
- Open-Source Contributions: Active contributions to open-source security tools or research projects.
We Offer
- Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting industry.
- Work directly with experienced senior leaders with ongoing mentorship opportunities.
- Earn competitive compensation and an attractive equity plan.
- Save for the future with a 401(k) program (US) or pension (EU).
- Benefit from medical, dental, vision, and life insurance (US) or statutory healthcare (EU).
- Leverage stipends for various benefits.
- Make the most of our flexible, generous paid time off and paid parental leave.
Pay Range Disclosure (For US openings only)
Cobalt is committed to fair and equitable compensation practices. The OTE salary range for this role is $120,000 - $150,000 per year + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. The salary range may differ in other states and may be impacted by proximity to major metropolitan cities.
Cobalt is an equal opportunity employer, and we want the best available persons for every job. The Company makes employment decisions only based on merit. It is the Company's policy to prohibit discrimination in any employment opportunity (including but not limited to recruitment, employment, promotion, salary increases, benefits, termination, and all other terms and conditions of employment) based on race, color, sex, sexual orientation, gender, gender identity, gender expression, genetic information, pregnancy, religious creed, national origin, ancestry, age, physical/mental disability, medical condition, marital/domestic partner status, military and veteran status, height, weight, or any other such characteristic protected by federal, state, or local law. The Company is committed to complying with all applicable laws and providing equal employment opportunities. This commitment applies to all persons involved in the operations of the Company regardless of where the employee is located and prohibits unlawful discrimination by any employee of the Company.
Cobalt is an E-Verify employer. E-Verify is an Internet-based system operated by the Department of Homeland Security (DHS) in partnership with the Social Security Administration (SSA). It allows participating employers to electronically verify the employment eligibility of their newly hired employees in the United States.
Apply for this job
indicates a required field
© Cobalt. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.
Cobalt (cobalt.io) is a fast growing cybersecurity start-up headquartered in San Francisco. Cobalt is providing a Pentest as a Service platform which leverages the sharing economy to find global security talent to help secure companies and their users. We have Scandinavian roots, an American base and a global outlook. Our offices in San Francisco, Berlin, and remote roles are characterised by a fun, fast-paced and collaborative culture based on individual responsibility and ownership.
More at Cobalt
All 10 roles
Senior Vice President of Global Sales
Cobalt · United States

Enterprise Account Director
Cobalt · United States

Business Development Representative (BDR) Manager
Cobalt · United States

Business Development Representative
Cobalt · United States