What Security Research Jobs are in the United States?
Showing 5000+ Security Research jobs in the United States
Job Description
**Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received** .
Plans, leads, and shares applied security research that defines how AI is built and used securely across Cisco, spanning AI-assisted development, AI features in products, and AI in internal operations.
Sets technical direction at the intersection of AI/ML security and hands-on engineering: leads AI-specific threat modeling, red-team and evaluation strategy, and secure architecture patterns that make AI-developed and AI-assisted software at least as secure as traditionally developed software. Serves as a research and security strategy liaison to engineers, product managers, and partners across Cisco's Security and Trust Organization (S&TO). Partners with teams in the systems and workflows they already use, and influences leadership decisions with evidence. The role enables teams rather than gating them: it defines what secure AI looks like, validates that Cisco meets it, and helps teams get there faster, including by using AI for security itself.
**What You'll Do:**
+ Leads strategic AI security initiatives and roadmaps with manageable-to-significant complexity (e.g., six-month to one-year plans) across the team's three pillars: securing AI-assisted development, securing AI in products, and securing AI in how we run the business.
+ Influences product organizations and partners across S&TO, setting the security bar while partners build and run.
+ Applies deep expertise in AI/ML security and research methods (adversarial machine learning, prompt injection, model extraction/inversion, membership inference, data poisoning, and excessive agency) while weighing ethical and responsible-AI considerations.
+ Sets AI red-team methodology and evaluation strategy; advances eval harnesses, LLM-as-a-judge approaches, and ground-truth/silver-dataset generation so conformance and agent behavior are measured with evidence rather than described manually.
+ Owns secure AI architecture patterns and prohibited design patterns for AI-native features (RAG, tool use, multi-agent workflows, MCP (Model Context Protocol) integrations), including prompts, context, retrieval, model selection, and output handling.
+ Authors and shepherds AI security standards and security requirements; defines clear release criteria for AI systems.
+ Drives the model and data supply-chain security strategy, including model provenance and data protection requirements such as classification, minimization, residency, and sensitive data handling.
+ Defines agent identity, human review, approval, and accountability controls so autonomous agents and AI-assisted outcomes are authenticated, bounded, and accountable.
+ Owns reusable platform contributions and architecture (security tooling and agentic workflows) that scale enablement across engineering rather than blocking it.
+ Monitors and evaluates emerging AI technologies, attacker techniques, and adversarial research; develops hypotheses, designs experiments and prototypes, and turns discovery into shipped controls.
+ Synthesizes findings into triangulated insights and meta-analyses that impact product and security decisions across multiple teams and AI initiatives.
+ Independently develops and delivers presentations; leads cross-functional working sessions with diverse audiences and creates clear ownership models with partner teams.
+ Leads creation of research artifacts (threat research, patterns, proposals, patents) of scientific quality and rigor; shares in company and industry forums.
+ Serves as the AI security technical authority within the team; mentors peers and security champions across engineering through reusable patterns, training, and office hours.
**Minimum Qualifications:**
+ Bachelor's + 7 years of related experience, or Master's + 4 years of related experience, or PhD + 1 year of related experience.
+ Demonstrated depth in AI/ML security and hands-on security engineering, with a track record of leading initiatives and influencing cross-functional teams.
+ Proficiency in Python; ability to read and review code fluently across multiple languages.
**Preferred Qualifications:**
+ Proven leadership of AI red-team engagements and evaluation programs; familiarity with Cisco AI Defense (Cisco's AI security solution) or an open-source framework such as NVIDIA's Garak.
+ Deep command of LLM and agentic-system security: prompt injection (direct and indirect), jailbreaking, insecure output handling, RAG hardening, tool-call governance, and multi-agent trust boundaries.
+ Experience authoring security standards or baselines and embedding them into a secure SDLC and CI/CD.
+ Authority with OWASP LLM/Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act, with the judgment to apply them proportionately by risk tier.
+ Experience shipping or integrating agentic and MCP (Model Context Protocol) systems and AI development tooling (Cursor, Claude Code, Copilot).
+ Experience with Go, Rust, or C/C++ is a plus, with C/C++ valuable for Cisco's embedded and networking products.
+ Recognized external contributions, such as published threat research, conference talks, open-source security tooling, or patents.
**Why Cisco?**
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
**Message to applicants applying to work in the U.S. and/or Canada:**
The starting salary range posted for this position is $167,000.00 to $211,400.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
+ 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
+ 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
+ Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
+ Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
+ 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
+ Additional paid time away may be requested to deal with critical or emergency issues for family members
+ Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
+ .75% of incentive target for each 1% of revenue attainment up to 50% of quota;
+ 1.5% of incentive target for each 1% of attainment between 50% and 75%;
+ 1% of incentive target for each 1% of attainment between 75% and 100%; and
+ Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
The applicable full salary ranges for this position, by specific state, are listed below:
New York City Metro Area:
$199,700.00 - $292,800.00
Non-Metro New York state & Washington state:
$174,500.00 - $260,500.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.
** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.
Is this job a match or a miss?
Senior Researcher - Security - Microsoft Research
Posted today
Job Viewed
Job Description
The Security Research Group at Microsoft Research Redmond is pushing the boundaries of data‑driven security. By leveraging the massive volume and diversity of security‑relevant events observed across Microsoft's platforms and customer environments, our mission is to detect security breaches accurately, quickly, and at an unprecedented scale.
In this role as a **Senior Researcher - Security** **,** you will work alongside leading researchers and engineers to design and build next‑generation intrusion detection systems. Our work combines security expertise with advanced data processing and modeling techniques-including large‑scale streaming analytics and graph‑based representations-to enable near‑real‑time detection of sophisticated attacks.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
**Responsibilities**
+ Analyze large‑scale, heterogeneous security event logs spanning endpoints, identities, cloud services, and networks.
+ Develop and train novel machine learning and statistical models for intrusion detection, anomaly detection, and adversarial behavior discovery.
+ Design and prototype scalable data processing and analytics platforms capable of operating on high‑volume, high‑velocity security data, with a focus on low‑latency detection.
+ Explore and apply advanced techniques such as graph‑based modeling, streaming computation, and representation learning to improve detection accuracy and timeliness.
+ Collaborate closely with other researchers, product teams, and engineering partners to transition research ideas into practical systems with real‑world impact.
+ Publish and present research results in top security, systems, and data management venues, and contribute to Microsoft's broader security strategy.
**Qualifications**
**Required/Minimum Qualifications**
+ Doctorate in relevant field OR Master's Degree in relevant field AND 3+ years related research experience OR Bachelor's Degree in relevant field AND 4+ years related research experience OR equivalent experience.
**Additional or Preferred Qualifications**
+ A PhD (or equivalent experience) in computer science or a related field, with a strong research background in security, machine learning, data mining, systems, or a closely related area.
+ Experience working with large‑scale data, including log analysis, streaming data, or distributed data processing systems.
+ Demonstrated foundations in machine learning or statistical modeling, and interest in applying these techniques to real‑world security problems.
+ The ability to independently drive research projects from problem formulation through implementation, evaluation, and dissemination.
+ A collaborative mindset and interest in bridging foundational research and deployed security systems.
Research Sciences IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations. (
Is this job a match or a miss?
Security Research Engineering Technical Leader
Posted 8 days ago
Job Viewed
Job Description
**Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received** .
This is a fully remote role based in the United States
**Meet The Team**
As a member of Talos, you will support cutting edge detection and mitigation technologies. You will work towards keeping yourself abreast of the latest industry threat creation and defense techniques, and you will develop proof-of-concept solutions, provide domain expertise and guide implementation to facilitate successful security posture in of Cisco's products.
If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this job is for you!
**Your Impact**
+ Security research including development of tools for vulnerability analysis and mitigation.
+ Development of static and run-time analysis tools to figure out root cause and input conditions related toa vulnerability.
+ Vulnerability triage and proof of concept exploit development to support the creation of detection content.
+ Writedetailed technical reports, summaries, and testing methodologies
+ Research emerging technologies, protocols, and testing methodologies
+ Develop proof of concept exploits fortesting vulnerability mitigations
+ Perform patch analysis to find and trigger vulnerabilities.
+ Reverseengineerbinary applications, protocols, and formats.
+ Analyze vulnerabilities and emerging security threats and technologies.
+ Provide critical security focusedexpertiseto engineering organizations
**Minimum Qualifications**
+ 3+ years of experience in vulnerability research or a closely related areasuch asexploitor mitigation developmenton Linux Systems
+ 3+ years' experience with C/C++, and a scripting language (e.g., Python), and assembly (e.g., x86/x64, ARM, etc.)
**Preferred Qualifications**
+ Bachelor's degree or equivalent in Computer Science, Electrical Engineering, Cyber Security, or other tech-related degree
+ Experience withLinux internals
+ Experience with binary auditing and reverse engineering, and with related tools such as IDA Pro, Binary Ninja,Ghidra, etc. and with plugin development.
+ Experience with common vulnerabilities and methods of exploitation, such as memory corruption, web application exploitation, file format vulnerabilities, protocol-based weaknesses, etc.
+ Knowledge of common file formats,network protocol structures, and enterprise networking architecture
+ Ability to work independently with minimum supervision and to tackleadditionaltasks as the need arises.
**Why Cisco?**
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
**Message to applicants applying to work in the U.S. and/or Canada:**
The starting salary range posted for this position is $163,600.00 to $234,600.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
+ 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
+ 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
+ Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
+ Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
+ 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
+ Additional paid time away may be requested to deal with critical or emergency issues for family members
+ Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
+ .75% of incentive target for each 1% of revenue attainment up to 50% of quota;
+ 1.5% of incentive target for each 1% of attainment between 50% and 75%;
+ 1% of incentive target for each 1% of attainment between 75% and 100%; and
+ Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
The applicable full salary ranges for this position, by specific state, are listed below:
New York City Metro Area:
$183,800.00 - $303,100.00
Non-Metro New York state & Washington state:
$163,600.00 - $269,800.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.
** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.
Is this job a match or a miss?
Alternate Special Security Officer - National Security Research Oversight Office
Posted 4 days ago
Job Viewed
Job Description
Alternate Special Security Officer - National Security Research Oversight Office
.
**Location**
CO - Golden
.
**Position Type**
Regular
.
**Hours Per Week**
40
.
**Working at NLR**
NLR is located at the foothills of the Rocky Mountains in Golden, Colorado is the nation's primary laboratory for energy systems research and development.
Join the National Laboratory of the Rockies (NLR), where world-class scientists, engineers, and experts are accelerating energy innovation through breakthrough research and systems integration. From our mission to our collaborative culture, NLR stands out in the research community for its commitment to an affordable and secure energy future. Spanning foundational science to applied systems engineering and analysis, we focus on solving complex challenges to deliver advanced, secure, reliable, and cost-effective energy solutions. Our work helps strengthen U.S. industries, support job creation, and promote national economic growth.
At NLR, you'll find a mission-driven environment supported by state-of-the-art facilities, multidisciplinary research teams, and strong collaborations with industry, academia, and other national laboratories. We offer robust professional development opportunities, and a competitive benefits package designed to support your career and well-being.
**Job Description**
The National Security Research Oversight Office (NSRO) enables and oversees the National Laboratory of the Rockies' (NLR) portfolio of national security work in accordance with the U.S Department of Energy and other governmental agency requirements.
NLR is actively seeking an individual experienced in special security operations to join the NSRO as an Alternate Special Security Officer. This position will report to the NSRO Director, supporting the Special Security Officer (SSO). The position requires a self-motivated professional capable of managing and administering security programs for classified and proprietary operations. You will also initially serve as a Site Security Manager (SSM). As the SSM, you will lead on-site security operations supporting the construction of a SCIF. You will act as the primary liaison between customers, construction teams, and security personnel to ensure strict compliance with ICD 705 requirements, Construction Security Plans (CSPs) and design standards. Upon completion of the project, you will assume the responsibilities of an ASSO supporting secure facilities across the site. In collaboration with the SSO and colleagues in NLR's Office of Laboratory Protection (OLP), you will support day-to-day security operations for NSRO, ensuring compliance with all applicable government regulations and policies.
The selected applicant will support the NSRO and broader national security research team through responsibilities including:
+ Serve as the primary on-site authority for all construction security operations and construction site access controls.
+ Supervise, train and coordinate daily activities of Construction Surveillance Technicians (CSTs) and Access Control Specialists.
+ Review construction drawings, blueprints, and project documentation to verify adherence to approved security requirements.
+ Oversee site audits and ensure all required documentation is properly maintained.
+ Serve asapoint of contact for SCIFs, andrelatedNSRO responsibilities. Provide training and oversight to personnel to ensure adherence to security protocols.
+ Establish andmaintainliaison with government agencies, external customers, NREL managers, employees, and contractors ensure compliance with National Policy.
+ Collaborate with OLP to design, implement, and refine security programs, policies, and procedures for safeguarding classified and proprietary materials.
+ Act as a security specialist for SCIF-related activities including document control, physical security (PHYSEC), information assurance (IA), personnel security (PERSEC), operational security (OPSEC), and communicationssecurity (COMSEC).
+ In coordination with OLP draft andmaintainStandard Operating Procedures (SOPs) and Emergency Action Plans for SCIFs.
+ Support investigation ofsecurity violations, prepare reports,and recommend preventative and corrective measures.
+ Oversee the receipt, processing, distribution, and tracking of classified documentationin physical and electronic forms asrequiredbypolicy.
+ Implement and manage visitor control procedures in compliance with local and national security policy.
+ Work closely with DOE/IN, DOE, OLP andNLRResearch Operations to ensure collaboration and consistency with NSROpolicy in addition to supporting emerging operational needs, including new facility development.
+ Work closely with Research Operations to integrate established NSRO policies and procedures with operations, and to support requirements for new facilities and capabilities.
+ Evaluate complex SCI risks and developappropriatemitigations.
+ Significant experiencetraining and mentoring teams unfamiliar with secure operations and policies.
+ Demonstrated ability to write clear and concise policies, training documents, investigative/formal reports, and operational documents.
+ Background and knowledge related to SCI regulations, facilities, and SCI control systems.
+ Knowledge of SCIF construction requirements.
+ Exceptional organizational skills with attention to detail and the ability to manage concurrent priorities.
+ Strong analytical skills; customer service experience; and the ability to interpret, communicate, and implement complex instructions.
+ Outstanding verbal and written communication skills.
+ PreviousCOMSEC experience.
.
**Basic Qualifications**
Relevant Bachelor's Degree and 9 or more years of experience or equivalent relevant education/experience. Or, relevant Master's Degree and 7 or more years of experience or equivalent relevant education/experience. Or, relevant PhD and 4 or more years of experience or equivalent relevant education/experience. Or, relevant JD and 4 or more years of experience or equivalent relevant education/experience. Applies extensive technical expertise, and has full knowledge of other related disciplines. Contributes to the development of new concepts, techniques and standards. Considered internal subject matter expert. Extensive knowledge of laws, regulations, principles, procedures and practices related to specific field. Excellent leadership, project management and problem solving skills. Ability to use various computer software programs.
*** Must meet educational requirements prior to employment start date.**
**Additional Required Qualifications**
+ Must hold an active DOE Q, DOETS, or other agency TSsecurity clearance with the ability to obtain SCI access. SCI access may require a polygraph examination. _Eligibility requirements: To obtain a clearance, an individual must be at least 18 years of age; U.S. citizenship is_ _required_ _except in_ _very limited_ _circumstances. See_ DOE O 472.2A _for_ _additional_ _information._
+ Ability to pass periodic full-scope polygraph tests.
+ Minimum of 6 years of experience as an SSO/CSSO in DOE, DoD, or other federal agency with oversight of sensitive security operations.
+ Knowledgeof security regulations, including 32 CFR Part 117 (NISPOM Rule), Executive Orders 12333 and 13526, and Intelligence Community Directives (ICDs) such as the 700 series.
+ Broadexpertisein security disciplines, including personnel security, physical security, technical security, COMSEC, and OPSEC.
+ Ability to work collaboratively withNLRmanagers,staffand other partners to form enterprise-level active security strategies, bestpracticesand policies.
+ Experience working in a dynamic environment with shifting priorities.
+ Willingness to travel (up to 10%) during programming and construction of SCIF facilities and for refinement of policies and procedures.
+ Ability to respond to after-hours alarms within requiredtimeframes.
**Preferred Qualifications**
+ Significant experience training and mentoring teams unfamiliar with secure operations and policies.
+ Direct experience in the design and construction of new SCIFs.
+ Demonstrated ability to write clear and concise policies, training documents, investigative/formal reports, and operational documents.
+ Background and knowledge related to SCI regulations, facilities, and SCI control systems.
+ Knowledge of SCIF construction requirements.
+ Exceptional organizational skills with attention to detail and the ability to manage concurrent priorities.
+ Strong analytical skills; customer service experience; and the ability to interpret, communicate, and implement complex instructions.
+ Outstanding verbal and written communication skills.
+ Previous COMSEC experience.
.
**Job Application Submission Window**
The anticipated closing window for application submission is up to 30 days and may be extended as needed.
**Annual Salary Range (based on full-time 40 hours per week)**
Job Profile: Professional IV / Annual Salary Range: $100,400 - $180,700
NLR takes into consideration a candidate's education, training, and experience, expected quality and quantity of work, required travel (if any), external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. In compliance with the Colorado Equal Pay for Equal Work Act, a potential new employee's salary history will not be used in compensation decisions.
**Benefits Summary**
Benefits include medical, dental, and vision insurance; short*- and long-term disability insurance; pension benefits*; 403(b) Employee Savings Plan with employer match*; life and accidental death and dismemberment (AD&D) insurance; personal time off (PTO) and sick leave; paid holidays; and tuition reimbursement*. NLR employees may be eligible for, but are not guaranteed, performance-, merit-, and achievement- based awards that include a monetary component. Some positions may be eligible for relocation expense reimbursement. Limited-term positions are not eligible for long-term disability or tuition reimbursement.
*** Based on eligibility rules
**Badging Requirement**
NLR is subject to Department of Energy (DOE) access restrictions. All employees must also be able to obtain and maintain a federal Personal Identity Verification (PIV) card as required by Homeland Security Presidential Directive 12 (HSPD-12), which includes a favorable background investigation.
**Drug Free Workplace**
NLR is committed to maintaining a drug-free workplace in accordance with the federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug.
If you are offered employment at NLR, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn.
**Submission Guidelines**
Please note that in order to be considered an applicant for any position at NLR you must submit an application form for each position for which you believe you are qualified. Applications are not kept on file for future positions. Please include a cover letter and resume with each position application.
.
**Equal Opportunity Employer**
All qualified applicants will receive consideration for employment without regard basis of age (40 and over), color, disability, gender identity, genetic information, marital status, domestic partner status, military or veteran status, national origin/ancestry, race, religion, creed, sex (including pregnancy, childbirth, breastfeeding), sexual orientation, and any other applicable status protected by federal, state, or local laws.
**Reasonable Accommodations ( **-Verify** ** **For information about right to work, click here ( for English or** **here ( for Spanish.**
E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.
The National Laboratory of the Rockies (NLR) is the U.S. Department of Energy's primary national laboratory for critical minerals, energy innovation, and energy security. With locations in Golden and Boulder, Colorado, Fairbanks, Alaska, and a satellite office in Washington, D.C., NLR bridges foundational research with practical applications to develop and bring to scale new energy materials and technologies that lower energy costs, drive economic growth, and deliver abundant and reliable energy.
NLR is subject to Department of Energy (DOE) access restrictions. All candidates must be authorized to access the facility per DOE rules and guidance within a reasonable time frame for the specified position in order to be considered for an interview and for hiring. DOE rules for site access during the interview process depend on whether the candidate is interviewed on-site, off-site, or via telephone or videoconference. All employees must also be able to obtain and maintain a federal Personal Identity Verification (PIV) card as required by Homeland Security Presidential Directive 12 (HSPD-12), which includes a favorable background investigation. Additionally, DOE contractor employees are prohibited from participating in certain Foreign Government Talent Recruitment Programs (FGTRPs). If a candidate is currently participating in an FGTRP, they will be required to disclose their participation after receiving an offer of employment and may be required to disengage from participation in the FGTRP prior to commencing employment. Any offer of employment is conditional on the ability to obtain work authorization and to be granted access to NLR by the Department of Energy (DOE).
**Drug Free Workplace**
NLR is committed to maintaining a drug-free workplace in accordance with federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug.
If you are offered employment at NLR, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn.
Please review the information on our Hiring Process ( website before you create an account and apply for a job. We also hope you will learn more about NLR ( , visit our Careers site ( , and continue to search for job opportunities ( at the lab.
Is this job a match or a miss?
Security Research Engineer
Posted 2 days ago
Job Viewed
Job Description
We are seeking a Security Research Engineer to operate as a hybrid Forward Deployed Engineer and offensive security researcher. You'll be on the front lines of customer engagements — using our open source tool Apex to run pentests, curate and present findings, and stand up our platform inside customer environments. In parallel, you'll drive original offensive and open source security research, and feed everything you learn in the field back into the product so Pensar keeps getting sharper as a pentesting platform.
This role is customer-facing by design. The ideal candidate is equally comfortable in a terminal popping shells with Apex, on a Zoom with a CISO walking through findings, and in a design review arguing for the next product capability.
Key Responsibilities Customer Engagements & Forward Deployed Work- Run end-to-end pentest engagements for customers using Apex, our open source offensive security tool
- Curate, triage, and contextualize findings for customer audiences ranging from engineers to executives
- Deliver clear, prioritized write-ups and walk customers through results, exploitation paths, and remediation
- Set up and configure the Pensar platform inside customer environments, including integrations and workflows
- Act as a trusted technical partner for customers throughout onboarding, engagements, and ongoing usage
- Travel to customer sites as needed for kickoffs, readouts, and on-site testing
- Conduct original offensive security research across web, cloud, infrastructure, and AI/LLM attack surfaces
- Develop new exploitation techniques, payloads, and tooling that extend Apex's capabilities
- Build automated testing methodologies for emerging vulnerability classes and attacker tradecraft
- Track the evolving threat landscape and translate it into concrete detections and capabilities
- Lead vulnerability research across high-impact open source projects and ecosystems
- Verify findings, build proof‑of‑concept exploits, and coordinate responsible disclosure with maintainers
- Contribute patches, advisories, and tooling back to the open source community
- Grow Pensar's reputation in the security research community through publications, talks, and contributions
- Translate firsthand engagement experience into concrete recommendations for the product roadmap
- Partner with engineering and product on capabilities, UX, and automation that make pentesting faster and more reliable
- Participate in architecture and design reviews with a focus on the pentester's workflow
- Help shape Apex's direction as an open source project alongside the internal platform
- Base salary:$120,000 – $175,000 per year, depending on experience
- Meaningful equity in an early‑stage offensive security company
- Final offers calibrated to depth of offensive security experience, the breadth of your research record, and the level you join at
CEO / CTO
We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.
Requirements- 5+ years of experience in offensive security, pentesting, red teaming, or vulnerability research
- Strong programming skills in multiple languages (Python, Go, JavaScript, C/C++)
- Deep, hands‑on understanding of modern vulnerability classes across web, cloud, and infrastructure
- Proven track record of running pentest engagements end‑to‑end and delivering findings to customers
- Excellent customer‑facing communication skills — comfortable presenting to both engineers and executives
- Experience contributing to or maintaining open source security tooling
- Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience
- Experience with AI/LLM‑assisted offensive security or building security automation on top of LLMs
- Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or developer tools company
- Security certifications (OSCP, OSCE, OSWE, GXPN, or equivalent)
- Public security research, CVEs, conference talks, or notable open source contributions
- Experience with cloud security (AWS, GCP, Azure) and containerized environments
- Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting
- Comprehensive health, dental, and vision insurance
- Direct ownership of customer engagements and offensive research at an early‑stage security company
- Professional development budget for conferences, training, and certifications
- Support for publishing research and presenting at industry conferences
- Direct, visible impact on both our open source tooling and commercial platform
Is this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Security Research Engineer
Posted 2 days ago
Job Viewed
Job Description
We are seeking a Security Research Engineer to operate as a hybrid Forward Deployed Engineer and offensive security researcher. You'll be on the front lines of customer engagements — using our open source tool Apex to run pentests, curate and present findings, and stand up our platform inside customer environments. In parallel, you'll drive original offensive and open source security research, and feed everything you learn in the field back into the product so Pensar keeps getting sharper as a pentesting platform.
This role is customer-facing by design. The ideal candidate is equally comfortable in a terminal popping shells with Apex, on a Zoom with a CISO walking through findings, and in a design review arguing for the next product capability.
Customer Engagements & Forward Deployed Work- Run end-to-end pentest engagements for customers using Apex, our open source offensive security tool
- Curate, triage, and contextualize findings for customer audiences ranging from engineers to executives
- Deliver clear, prioritized write-ups and walk customers through results, exploitation paths, and remediation
- Set up and configure the Pensar platform inside customer environments, including integrations and workflows
- Act as a trusted technical partner for customers throughout onboarding, engagements, and ongoing usage
- Travel to customer sites as needed for kickoffs, readouts, and on-site testing
- Conduct original offensive security research across web, cloud, infrastructure, and AI/LLM attack surfaces
- Develop new exploitation techniques, payloads, and tooling that extend Apex's capabilities
- Build automated testing methodologies for emerging vulnerability classes and attacker tradecraft
- Track the evolving threat landscape and translate it into concrete detections and capabilities
- Lead vulnerability research across high-impact open source projects and ecosystems
- Verify findings, build proof-of-concept exploits, and coordinate responsible disclosure with maintainers
- Contribute patches, advisories, and tooling back to the open source community
- Grow Pensar's reputation in the security research community through publications, talks, and contributions
- Translate firsthand engagement experience into concrete recommendations for the product roadmap
- Partner with engineering and product on capabilities, UX, and automation that make pentesting faster and more reliable
- Participate in architecture and design reviews with a focus on the pentester's workflow
- Help shape Apex's direction as an open source project alongside the internal platform
- Base salary: $120,000 – $175,000 per year, depending on experience
- Meaningful equity in an early-stage offensive security company
- Final offers calibrated to depth of offensive security experience, the breadth of your research record, and the level you join at
CEO / CTO
We are an equal opportunity employer committed to diversity and inclusion. We welcome applications from all qualified candidates regardless of race, gender, age, religion, sexual orientation, or disability status.
Qualifications- 5+ years of experience in offensive security, pentesting, red teaming, or vulnerability research
- Strong programming skills in multiple languages (Python, Go, JavaScript, C/C++)
- Deep, hands‑on understanding of modern vulnerability classes across web, cloud, and infrastructure
- Proven track record of running pentest engagements end‑to‑end and delivering findings to customers
- Excellent customer‑facing communication skills — comfortable presenting to both engineers and executives
- Experience contributing to or maintaining open source security tooling
- Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent experience
- Experience with AI/LLM-assisted offensive security or building security automation on top of LLMs
- Prior Forward Deployed Engineer, solutions engineering, or consulting experience at a security or developer tools company
- Security certifications (OSCP, OSCE, OSWE, GXPN, or equivalent)
- Public security research, CVEs, conference talks, or notable open source contributions
- Experience with cloud security (AWS, GCP, Azure) and containerized environments
- Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting
- Comprehensive health, dental, and vision insurance
- Direct ownership of customer engagements and offensive research at an early‑stage security company
- Professional development budget for conferences, training, and certifications
- Support for publishing research and presenting at industry conferences
- Direct, visible impact on both our open source tooling and commercial platform
Is this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Senior Product Manager, Security Research
Posted today
Job Viewed
Job Description
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! Senior Product Manager, Security Research Location: US West/Foster City
About the Qualys Threat Research Unit (TRU)You will be joining the heartbeat of Qualys—a world-renowned team of over 120 "white hat" experts dedicated to staying ahead of the adversary. We don't just track threats; we define the defense. We are four-time Pwnie Award winners (the "Oscars" of hacking), recognized for Epic Achievement and discovering critical zero-day vulnerabilities in software such as OpenSSH and glibc.
The MissionWe are seeking a Senior Product Manager to serve as the strategic bridge between the Threat Research Unit (TRU), Engineering, and our customers. Your goal is to translate the raw, high-velocity threat landscape requirements into a concrete, executable product roadmap.
Key Responsibilities- Strategic Roadmap & Data-Driven Prioritization – Utilize your hands-on fluency in data analytics (Salesforce, Jira, SQL) to analyze feature impact and prioritize the roadmap based on empirical evidence rather than opinion. Manage the delicate balance of adding/removing roadmap items through collaboration with Engineering, Marketing, and Product leadership. Transform high-level vision into precise technical requirements and prioritized backlogs. Collaborate with PMM and Sales to ensure features provide a competitive advantage and are positioned correctly in the market.
- Customer Discovery & Solution Design – Lead discovery sessions to identify root pain points. Move beyond solving single-customer issues to designing scalable solutions that benefit the entire user base. Manage incoming requests and new cases with a systematic approach to review, validation, and communication with stakeholders. Serve as a technical resource by writing impactful blog posts, leading webinars, and defining best practices that help organizations reduce risk, independent of specific product features. Empower the Sales team and Strategic Accounts with compelling product pitches, demos, and deep-dive explanations of complex security capabilities.
- 5+ years in Product Management with at least 3 years specifically in Cybersecurity (VM, EDR, or Threat Intel). Alternatively, 8+ years in technical leadership/security engineering with a pivot to Product.
- Deep understanding of the threat landscape (Zero-days, CVEs, Exploits). Familiar with the distinction between a CVE and an exploit and how SOC/IT teams function.
- Bachelor's degree in computer science, Engineering, or related field (MBA is a plus).
- Proficiency in Python and SQL (or similar scripting languages) is required.
- Exceptional ability to communicate across multiple time zones and effectively engage stakeholders from field sales to executive leadership.
- Preferred & Bonus: Researcher-to-Product Transition – Highly prefer candidates with a background in Threat Research looking to pivot into Product Management while leveraging deep security expertise. Domain Expertise: Strong background in Vulnerability Management (VM), Exposure Management, or Risk Management.
The salary range for this position is $145,000 - $175,000 per year. Final compensation will be determined based on several factors, including but not limited to skills, relevant experience, and work location. Please note this range reflects base salary and does not include incentive compensation or potential equity grants. We also offer a comprehensive and highly competitive benefits package.
Qualys is an Equal Opportunity Employer, please see our EEO policy.
#J-18808-LjbffrIs this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Senior Specialist, Security Research Engineer
Posted 15 days ago
Job Viewed
Job Description
L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security.
Job Title: Senior Specialist, Security Software Research Engineer
Job Code: 38328
Job Location: Remote
Job Schedule: 9/80: Employees work 9 out of every 14 days - totaling 80 hours worked and have every other Friday off.
Job Description:
Working at Trenchant means working alongside the best security researchers and product engineers from across the security research and intelligence communities. You will be engaged on the most challenging problems in the toughest environments and delivering solutions supporting the cutting edge of cyber security research. We are looking for team members across a range of roles and disciplines demonstrating an eye for security, to serve as key contributors on the Global Engineering team. The candidate must possess first-class System Engineering, Networking, and infosec skills and an eye for organization.
Trenchant is an elite global team of engineers and security researchers charged with building world-class computer security products. Trenchant's expertise is the by-product of the L3Harris acquisition of two highly-regarded information security businesses - Azimuth Security and Linchpin Labs. United under Trenchant, we are a key component of L3Harris' Cyber Division. We are a trusted, discrete partner furnishing security products, consultancy, training and integration services to allied security, defense, and law enforcement agencies.
Essential Functions:
+ Collaborate with security researchers to adopt working research output into commercial products.
+ Transform vulnerability writeups and proof of concept code into mature capabilities.
+ Effectively communicate status and technical challenges using language that is appropriate to your audience.
+ Participate in planning and prioritization activities with members of the commercial arm of the organization.
+ Provide engineering support to customer reported issues.
+ Provide guidance to less experienced engineers in technical fields relevant to the platform and the domains of cyber security and software engineering.
+ Monitor industry trends and publicly disclosed techniques for incorporation into our products.
+ Ability to obtain and maintain security clearance.
Qualifications:
+ Bachelor's Degree and minimum 6 years of prior relevant experience. Graduate Degree and a minimum of 4 years of prior related experience. In lieu of a degree, minimum of 10 years of prior related experience.
Preferred Additional Skills:
+ Working knowledge of OS and application vulnerability classes.
+ Proven experience analyzing malware samples, producing vulnerability proofs of concept, and understanding mitigations provided by software patches.
+ Comfortable with C programming, memory management concepts, assembly languages, and private (undocumented) APIs.
+ Demonstrated proficiency in all aspects of a mobile platform (Android or iOS) including OS internals, mobile ecosystem languages (Objective-C, Swift, Java, and/or Kotlin), and system security mechanisms.
+ Demonstrated proficiency using reverse engineering tools such as IDA Pro, Ghidra, or Hopper and dynamic tools such as Frida or ADB.
+ Demonstrated proficiency using common software development tools such as git, gitlab CI, and cmake.
+ Advanced degree in Computer Science, Cybersecurity or a related field.
+ Demonstrated ability to take ambiguous or incompletely defined problems and resolve them through consultation with appropriate stakeholders.
+ Demonstrated a collaborative and team-oriented mindset for accomplishing goals and a bias to action.
+ Substantial experience in CNO development/offensive cyber security.
+ Has/had a TS clearance with ability to obtain SCI access.
+ Experience working in an air-gapped development environment.
In compliance with pay transparency requirements, the salary range for this role in California, Massachusetts, New Jersey, Washington, and the Greater D.C, Denver, or NYC areas is $111,500 - $207,500. The salary range for this role in Colorado state, Hawaii, Illinois, Maryland, Minnesota, New York state, and Vermont is $97,000 - $180,000. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements.
#LI-FS1
L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law.
Please be aware many of our positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information.
By submitting your resume for this position, you understand and agree that L3Harris Technologies may share your resume, as well as any other related personal information or documentation you provide, with its subsidiaries and affiliated companies for the purpose of considering you for other available positions.
L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English ( or Spanish ( . For information regarding your Right To Work, please click here for English ( or Spanish ( .
Is this job a match or a miss?
Head of Blockchain Security & Research
Posted 2 days ago
Job Viewed
Job Description
Framework Ventures is seeking a hands-on, security-focused leader to head our Blockchain Security Research Team in the United States. You will drive exploit discovery, design security tooling, and mentor researchers while advancing proactive security measures across dApps, smart contracts, and networks.
As a team lead, you will collaborate with product, development, and security teams to elevate our security posture and align with industry best practices.
#J-18808-LjbffrIs this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Explore exciting opportunities in security research, a field dedicated to identifying and mitigating vulnerabilities in software, hardware, and networks. Security researchers play a crucial role in protecting digital assets from cyber threats, employing techniques like penetration testing, reverse engineering, and vulnerability analysis. This career path demands a strong understanding of computer science principles, security protocols, and ethical hacking practices.