Skip to content
CensysCensysUnited States

Senior Security Researcher

Senior Security Researcher driving offensive security insights at Censys using large-scale Internet scan data. Conduct original research on attack techniques and agentic AI, publish at top conferences, translate findings into product scanning/fingerprinting capabilities, and collaborate cross-functionally. Requires 5+ years hands-on pentesting/red teaming experience plus agentic AI tooling expertise.

202k – 278k/yr
Remote5+ YOESecurity Engineering

About the role

What you’ll do

  • Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data. Identify gaps in detection logic, protocol coverage, and vulnerability signals.
  • Conduct original research on emerging attack techniques, exploitation trends, C2 infrastructure, and adversary tradecraft using Internet-wide scan data.
  • Publish research reports, technical blog posts, and conference material (e.g. DEF CON, Black Hat) to establish authority in offensive security.
  • Collaborate with Engineering and Product to translate findings into new scanning modules, fingerprints, risk indicators, and detection features.
  • Lead agentic AI threat research: build, deploy, and evaluate autonomous penetration testing agents, LLM-powered vulnerability research tools, and multi-agent swarms for both tradecraft research and product detection capabilities.
  • Track adversary infrastructure using red team and pentest knowledge to encode detection logic.
  • Mentor and inform as an internal subject-matter expert on offensive techniques.
  • Demonstrate curiosity, willingness to learn, and sound judgment in applying AI.

Skills and experience you’ll have

  • 5+ years of hands-on penetration testing, red teaming, or adversary emulation experience against enterprise, cloud, or Internet-facing environments.
  • Demonstrated ability to independently identify and characterize vulnerabilities, misconfigurations, or exploitation techniques.
  • Strong understanding of network protocols, service fingerprinting, and Internet-scale scanning concepts (or fast ability to learn).
  • Hands-on experience with agentic systems for offensive security, including building/evaluating LLM-powered attack agents using frameworks such as HackSynth, RedTeamLLM, CAI, PentAG; AI-assisted vulnerability research pipelines; or multi-agent adversary emulation tooling. Demonstrated understanding of their failure modes.
  • Proficiency in scripting or coding (Python, Go, or similar) to build tooling, automate testing, or analyze large datasets.
  • Familiarity with red team frameworks and tradecraft (C2 frameworks, initial access techniques, living-off-the-land methods, evasion).
  • Comfort working with large-scale Internet scan data or strong interest in learning.

Preferred skills/experience

  • Relevant certifications (OSCP, OSCE, OSEP, GXPN, or equivalent).
  • Experience with IoT, OT/ICS, or embedded device security research.
  • Prior work as a researcher at a security vendor.
  • Evidence of research/tooling contributions to the agentic offensive space (benchmarks, PoCs, AI-assisted vulnerability discoveries) and agentic AI red teaming work (e.g. Microsoft's PyRIT, Cloud Security Alliance's Agentic AI Red Teaming Guide).
  • Track record of public research output — CVEs, conference talks, technical blog posts, or tool releases.
  • Familiarity with compliance-adjacent security testing (e.g. mapping pentest findings to SOC 2, ISO 27001, or CMMC).

Compensation

For high cost of living areas in the US (San Francisco / Seattle / NYC): $220,000 - $278,000 USD base + bonus eligibility + equity.
For all other US locations: $202,000 - $254,000 USD base + bonus eligibility + equity.
Compensation also includes competitive benefits: equity, health/dental/vision, retirement contribution, parental leave, mental health benefits, flexible PTO, professional development stipend, and annual bonus eligibility.

Skills

Penetration Testingred teamingadversary emulationAgentic AIllm-powered attack agentsPythonGoc2 frameworksnetwork protocolsservice fingerprintinginternet-scale scanningoffensive securityvulnerability research
Fluidstack

Security Site Lead

FluidstackBuffalo, NY +2

Lead on-site security posture for high-value AI compute infrastructure at data centers. Own all security systems, policies, vendor accountability, incident response, and represent security in site planning and operations.

200k – 250k/yrOn-site7+ YOESecurity Engineering
Snowflake

Senior Software Engineer

SnowflakeBellevue, WA +1

Senior Software Engineer building Snowflake's core identity, access management, and AI-native security infrastructure for the Data Cloud. Design secure agent workflows, IAM systems, encryption, and policy enforcement tooling at massive scale.

200k – 288k/yrHybrid5+ YOESecurity Engineering
Snowflake

Senior Software Engineer, Security Foundations

SnowflakeBellevue, WA

Senior Software Engineer building real-time security detection, prevention, and intelligence systems to protect Snowflake's multi-cloud platform from abuse, account takeovers, data exfiltration, and AI threats using AI/ML and risk scoring. Requires 5+ years software engineering experience with security focus.

200k – 288k/yrOn-site5+ YOESecurity Engineering
Wiz

Threat Detection Researcher

WizNew York, NY

Threat Detection Researcher developing detections and tools to protect customers from cloud, AI, and malware threats. Requires 6+ years in security/threat research, deep OS internals knowledge (Windows/Linux/macOS), Python proficiency, and cloud familiarity.

200k – 250k/yrOn-site6+ YOESecurity Engineering
Snowflake

Senior Software Engineer

SnowflakeBellevue, WA

Senior Software Engineer building critical Identity & Access Management features and AI security capabilities (agent workflows, authentication, authorization, RBAC) for Snowflake's cloud data platform. Requires 7+ years building large-scale distributed systems, IAM expertise, and strong CS fundamentals.

200k – 288k/yrOn-site7+ YOESecurity Engineering