Senior Security Researcher
Lead end-to-end security research in vulnerability detection, remediation, and prioritization. Analyze security data, automate threat research, and collaborate with product/engineering to build platform features. Directly influence how organizations identify and mitigate their most critical security exposures.
Responsibilities
- Lead end-to-end security research projects focusing on vulnerability detection, risk prioritization, and exposure management logic.
- Utilize Python, SQL, and AI/LLM tools to build data analysis pipelines, automate threat research, and prototype research tools.
- Research and define remediation strategies, compensating controls, and configuration-based mitigations beyond standard patching.
- Partner weekly with Product and Engineering teams to transform technical research into production-ready product capabilities.
Requirements
- 4+ years of professional experience in security research, vulnerability analysis, or penetration testing.
- Demonstrated proficiency with Python for scripting/automation and SQL for querying complex security data sets.
- Hands-on experience integrating AI/LLMs into technical workflows to accelerate data analysis, parsing, or research output.
- Practical understanding of security frameworks and metrics including CVSS, EPSS, and MITRE ATT&CK.
Nice to have
- Prior experience in B2B SaaS or enterprise cybersecurity product environments.
- Experience in exposure management, attack surface management (ASM), or enterprise risk prioritization.
- Experience creating custom prioritization and scoring algorithms combining vulnerability telemetry with asset criticality.
- Deep knowledge of non-patching mitigation strategies, including registry tweaks, network policy shifts, and configuration hardening.
- Proven track record of framing open-ended security problems into scalable software feature requirements.