Cobalt (cobalt.io)

Senior Security Researcher

Cobalt (cobalt.io)$120K — $150K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in offensive security, vulnerability research, or related area (3+ years with notable publications or CVE disclosures)
  • Expertise in modern application stacks (Node.js, Go, Python) and OS fundamentals (Linux/Windows)
  • Proven experience crafting PoC exploits for complex vulnerabilities
  • Strong skills in Python, Go, Bash, or Rust for automation and tooling
  • Ability to clearly document technical findings for diverse audiences
  • US-based candidates only (preferably EST or CST)

Responsibilities

  • Conduct in-depth vulnerability research and threat analysis across various platforms
  • Develop and validate PoC exploit techniques for high-impact vulnerabilities
  • Research new threat vectors and create industry-leading security testing methodologies
  • Collaborate on building scalable security assessment tools and automated workflows
  • Translate complex security research into actionable insights for product and engineering teams
  • Mentor junior researchers and provide technical guidance on research efforts
  • Represent the company in the security community through technical publications and presentations

Benefits

  • Grow within a rapidly expanding pentesting industry
  • Receive mentorship directly from experienced senior leaders
  • Enjoy competitive compensation with equity options
  • Participate in a 401(k) program or equivalent pension plan
  • Access medical, dental, vision, and life insurance plans
  • Get stipends for wellness, equipment, and learning development
  • Benefit from flexible paid time off and parental leave
Full Job Description
Description

At Cobalt.io, as a Senior Security Researcher, you will conduct advanced vulnerability research and security assessments across modern application and operating system stacks, cloud infrastructure, and critical enterprise systems.

Your role focuses on identifying impactful security flaws, developing potential exploit techniques, and collaborating with cross-functional teams to strengthen customer security postures. Operating within Cobalt's Offensive Security Research team, you will bridge the gap between cutting-edge adversary tradecraft, platform-driven security testing, and actionable remediation guidance.
What You'll Do
  • Advanced Vulnerability Research: Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, cloud infrastructures (GCP/AWS/Azure/K8s), and critical enterprise software systems.
  • Exploit Crafting & Proof-of-Concept Validation: Identify high-impact vulnerabilities and novel attack surfaces; develop proof-of-concept (PoC) exploit techniques to demonstrate real-world risk cleanly and accurately.
  • Methodology & Tradecraft Innovation: Research emerging threat vectors and maintain industry-leading testing guidelines across cloud environments, APIs, mobile platforms, and modern AI/ML technologies.
  • Platform & Tooling Enhancements: Collaborate with Product and Engineering teams to translate research findings into scalable security assessment capabilities, automated testing workflows, and platform intelligence.
  • Cross-Functional Collaboration: Partner with engineering, product, and operations teams to translate complex security research into actionable customer value and platform improvements.
  • Community Enablement & Mentorship: Provide technical guidance, benchmarking, and mentorship to junior researchers and community members; assist in technical quality assurance for complex research initiatives.
  • Thought Leadership & Public Outreach: Represent Cobalt in the security research community through high-impact technical blog posts, advisories, whitepapers, and conference presentations (e.g., DEF CON, Black Hat, BSides).
You Must Have
  • 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering (or 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling).
  • Technical Depth across Modern Stacks: Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust), operating system security fundamentals (Linux/Windows/macOS internals), and containerized cloud environments (Docker, Kubernetes, AWS/GCP).
  • Exploit Analysis & Crafting: Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation).
  • Tooling & Automation Skills: Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities.
  • Clear Technical Communication: Ability to document complex technical findings into clear, actionable remediation guidance for engineers, product teams, and executive stakeholders.
  • US-Based: Strictly limited to candidates residing in the United States (EST or CST time zone alignment preferred for team
Nice To Have
  • Emerging Technology Security: Familiarity with modern AI/ML security concepts, LLM risk models, and novel software integrations.
  • Reverse Engineering Tooling: Hands-on experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB debugging.
  • CVE & Research Track Record: Published CVEs, security advisories, or bug bounty hall-of-fame recognitions.
  • Industry Certifications: Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist.
  • Open-Source Contributions: Active contributions to open-source security tools or research projects.
Why You Should Join Us
  • Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting industry
  • Work directly with experienced senior leaders with ongoing mentorship opportunities
  • Earn competitive compensation and an attractive equity plan
  • Save for the future with a 401(k) program (US) or pension (EU)
  • Benefit from medical, dental, vision and life insurance (US) or statutory healthcare (EU)
  • Leverage stipends for:
    • Wellness
    • Work-from-home equipment & wifi
    • Learning & development
  • Make the most of our flexible, generous paid time off and paid parental leave
Pay Range Disclosure (For US openings only)

Cobalt is committed to fair and equitable compensation practices. The OTE salary range for this role is $120,000 - $150,000 per year + equity + benefits. A candidate's salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. The salary range may differ in other states and may be impacted by proximity to major metropolitan cities.

About Cobalt (cobalt.io)

Cobalt is a cybersecurity company that provides a platform for managing and testing application security. The company's platform combines a global network of security experts with artificial intelligence to help organizations identify and remediate vulnerabilities in their software. Cobalt is headquartered in San Francisco, California and was founded in 2013.
Learn more about Cobalt (cobalt.io)
Size
200 employees
Industry
Founded
2013

Similar Jobs

More Jobs at Cobalt (cobalt.io)

More Information Technology Jobs

Find similar Senior Security Researcher jobs: