Senior Security Researcher
CobaltAbout the role
Who We Are
Cobalt was founded on the belief of a fundamental human aspiration: the desire to live better and safer. It all started in 2013, when our founders realized that pentesting can be better. Today our diverse, fully remote team is committed to helping organizations of all sizes with seamless, effective and collaborative Offensive Security Testing that empower organizations to OPERATE FEARLESSLY and INNOVATE SECURELY.
Our customers can start a pentest in as little as 24 hours and integrate with advanced development cycles thanks to the powerful combination of our SaaS platform coupled with an exclusive community of testers known as the Cobalt Core. Accepting just 5% of applicants, the Cobalt Core boasts over 400 closely vetted and highly skilled testers who jointly conduct thousands of tests each year and are at the forefront of identifying and helping remediate risk across a dynamically changing attack surface.
Cobalt is an Equal Opportunity Employer and we strive to build a diverse and inclusive workforce at our company. At Cobalt we aspire to engage with diverse individuals, communities, and organizations in order to continue to nurture our unique rich diverse culture. Join our team, and be your true self to do your best work.
Description
At Cobalt.io, as a Senior Security Researcher, you will conduct advanced vulnerability research and security assessments across modern application and operating system stacks, cloud infrastructure, and critical enterprise systems.
Your role focuses on identifying impactful security flaws, developing potential exploit techniques, and collaborating with cross-functional teams to strengthen customer security postures. Operating within Cobalt’s Offensive Security Research team, you will bridge the gap between cutting-edge adversary tradecraft, platform-driven security testing, and actionable remediation guidance.
What You’ll Do
- Advanced Vulnerability Research: Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, cloud infrastructures (GCP/AWS/Azure/K8s), and critical enterprise software systems.
- Exploit Crafting & Proof-of-Concept Validation: Identify high-impact vulnerabilities and novel attack surfaces; develop proof-of-concept (PoC) exploit techniques to demonstrate real-world risk cleanly and accurately.
- Methodology & Tradecraft Innovation: Research emerging threat vectors and maintain industry-leading testing guidelines across cloud environments, APIs, mobile platforms, and modern AI/ML technologies.
- Platform & Tooling Enhancements: Collaborate with Product and Engineering teams to translate research findings into scalable security assessment capabilities, automated testing workflows, and platform intelligence.
- Cross-Functional Collaboration: Partner with engineering, product, and operations teams to translate complex security research into actionable customer value and platform improvements.
- Community Enablement & Mentorship: Provide technical guidance, benchmarking, and mentorship to junior researchers and community members; assist in technical quality assurance for complex research initiatives.
- Thought Leadership & Public Outreach: Represent Cobalt in the security research community through high-impact technical blog posts, advisories, whitepapers, and conference presentations (e.g., DEF CON, Black Hat, BSides).
You Must Have
- 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering (or 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling).
- Technical Depth across Modern Stacks: Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust), operating system security fundamentals (Linux/Windows/macOS internals), and containerized cloud environments (Docker, Kubernetes, AWS/GCP).
- Exploit Analysis & Crafting: Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation).
- Tooling & Automation Skills: Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities.
- Clear Technical Communication: Ability to document complex technical findings into clear, actionable remediation guidance for engineers
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s