Senior Security Researcher

Cobalt
$120,000 - $150,000Remote

About The Position

At Cobalt.io, as a Senior Security Researcher, you will conduct advanced vulnerability research and security assessments across modern application and operating system stacks, cloud infrastructure, and critical enterprise systems. Your role focuses on identifying impactful security flaws, developing potential exploit techniques, and collaborating with cross-functional teams to strengthen customer security postures. Operating within Cobalt’s Offensive Security Research team, you will bridge the gap between cutting-edge adversary tradecraft, platform-driven security testing, and actionable remediation guidance.

Requirements

  • 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering (or 3+ years with a proven track record of published research, CVE disclosures, or open-source security tooling).
  • Demonstrated expertise in modern application stacks (Node.js, Go, Python, Java, Rust), operating system security fundamentals (Linux/Windows/macOS internals), and containerized cloud environments (Docker, Kubernetes, AWS/GCP).
  • Proven ability to analyze binary, source code, or bytecode to construct reliable PoC exploits for complex vulnerability classes (e.g., memory corruption, deserialization, auth bypass, SSRF/RCE, cloud privilege escalation).
  • Strong proficiency in Python, Go, Bash, or Rust for building custom research tools, scripts, and testing utilities.
  • Ability to document complex technical findings into clear, actionable remediation guidance for engineers, product teams, and executive stakeholders.
  • Strictly limited to candidates residing in the United States (EST or CST time zone alignment preferred for team).

Nice To Haves

  • Familiarity with modern AI/ML security concepts, LLM risk models, and novel software integrations.
  • Hands-on experience with Ghidra, IDA Pro, Binary Ninja, or GDB/LLDB debugging.
  • Published CVEs, security advisories, or bug bounty hall-of-fame recognitions.
  • Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist.
  • Active contributions to open-source security tools or research projects.

Responsibilities

  • Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across modern Web/API platforms, mobile operating systems, low-level OS stacks, cloud infrastructures (GCP/AWS/Azure/K8s), and critical enterprise software systems.
  • Identify high-impact vulnerabilities and novel attack surfaces; develop proof-of-concept (PoC) exploit techniques to demonstrate real-world risk cleanly and accurately.
  • Research emerging threat vectors and maintain industry-leading testing guidelines across cloud environments, APIs, mobile platforms, and modern AI/ML technologies.
  • Collaborate with Product and Engineering teams to translate research findings into scalable security assessment capabilities, automated testing workflows, and platform intelligence.
  • Partner with engineering, product, and operations teams to translate complex security research into actionable customer value and platform improvements.
  • Provide technical guidance, benchmarking, and mentorship to junior researchers and community members; assist in technical quality assurance for complex research initiatives.
  • Represent Cobalt in the security research community through high-impact technical blog posts, advisories, whitepapers, and conference presentations (e.g., DEF CON, Black Hat, BSides).

Benefits

  • Competitive compensation
  • Attractive equity plan
  • 401(k) program (US)
  • Medical, dental, vision and life insurance (US)
  • Stipends for wellness
  • Stipends for work-from-home equipment & wifi
  • Stipends for learning & development
  • Flexible, generous paid time off
  • Paid parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service