Skip to main content
Cobalt

Senior Security Researcher

RemoteUnited States only
Published
Role
Fullstack
Experience
Senior
Employment
Full-time
$120k–$150k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

As a Senior Security Researcher at Cobalt, you conduct advanced vulnerability research and security assessments across modern application and operating system stacks, cloud infrastructure, and critical enterprise systems.

Core skills

Offensive SecurityVulnerability ResearchPenetration Testing

Required skills

PythonGoBashRustNode.jsJavaKubernetesDockerAWSGCPLinuxWindowsmacOSProgramming Languages/Python, Go, Bash, Rust, Node.js, JavaCloud and Containers/AWS, GCP, Azure, Kubernetes, DockerOperating Systems/Linux, Windows, macOS

Optional skills

GhidraIDA ProBinary NinjaGDB/LLDBOSCPOSEPOSWEOSEE

Required languages

English native_or_bilingual

What you'll do

  • Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, cloud infrastructures (GCP/AWS/Azure/K8s) and critical enterprise software systems.
  • Identify high-impact vulnerabilities and novel attack surfaces; develop proof-of-concept (PoC) exploit techniques to demonstrate real-world environment.
  • Research emerging threat vectors and maintain industry-leading testing guidelines across cloud environments, APIs, mobile platforms, and modern AI/ML technologies.
  • Collaborate with Product and Engineering teams to translate research findings into scalable security assessment and automated testing workflows.
  • Partner with engineering, product, and operations teams to translate complex security research into actionable customer value and platform improvements.
  • Provide technical guidance, training, and mentoring to junior security personnel and community members; assist in technical quality assurance for complex research initiatives.
  • Represent Cobalt in the security research community through research reports, advisories, whitepapers, and conference presentations.

What they require

  • Safety: 7+ years of research dedicated experience.
  • Deep technical depth across modern stacks, including but not limited to Node.js, Go, Python, Java, Rust and OS internals.
  • Ability to analyze binary, source code, or bytecode to construct reliable Proof of Concept (PoC) or exploit exploits for complex vulnerability classes.
  • Active knowledge of containerized and cloud architectures (Docker, Kubernetes, AWS/GCP)
  • Excellent communication skills in clear, actionable deliverables for technical stakeholders.

Benefits

  • Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting
  • Work directly with experienced senior leaders and ongoing mentorship opportunities
  • Earn competitive compensation and an attractive equity plan
  • Save for the future with a 401(k) program (US) or company 'other' (EU)
  • Benefit from medical, dental, vision and life insurance (US) or statutory healthcare (EU)
  • For refinements for wellness, remote work equipment, internet, learning & development
  • Make the most of our flexible, generous paid time off and paid parental leave

2016 side-scrolling video game by Mojang

CybersecurityStartupplaycobalt.com
$120k–$150k/yr