# Senior Security Researcher

**Company:** [Censys](https://hotfix.jobs/companies/censys)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $202k – $278k/yr
**Experience:** 5+ years
**Skills:** Penetration Testing, red teaming, adversary emulation, Agentic AI, llm-powered attack agents, Python, Go, c2 frameworks, network protocols, service fingerprinting, internet-scale scanning, offensive security, vulnerability research
**Posted:** 2026-07-23

> Senior Security Researcher driving offensive security insights at Censys using large-scale Internet scan data. Conduct original research on attack techniques and agentic AI, publish at top conferences, translate findings into product scanning/fingerprinting capabilities, and collaborate cross-functionally. Requires 5+ years hands-on pentesting/red teaming experience plus agentic AI tooling expertise.

## Job Description

## What you’ll do

- Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data. Identify gaps in detection logic, protocol coverage, and vulnerability signals.
- Conduct original research on emerging attack techniques, exploitation trends, C2 infrastructure, and adversary tradecraft using Internet-wide scan data.
- Publish research reports, technical blog posts, and conference material (e.g. DEF CON, Black Hat) to establish authority in offensive security.
- Collaborate with Engineering and Product to translate findings into new scanning modules, fingerprints, risk indicators, and detection features.
- Lead agentic AI threat research: build, deploy, and evaluate autonomous penetration testing agents, LLM-powered vulnerability research tools, and multi-agent swarms for both tradecraft research and product detection capabilities.
- Track adversary infrastructure using red team and pentest knowledge to encode detection logic.
- Mentor and inform as an internal subject-matter expert on offensive techniques.
- Demonstrate curiosity, willingness to learn, and sound judgment in applying AI.

## Skills and experience you’ll have

- 5+ years of hands-on penetration testing, red teaming, or adversary emulation experience against enterprise, cloud, or Internet-facing environments.
- Demonstrated ability to independently identify and characterize vulnerabilities, misconfigurations, or exploitation techniques.
- Strong understanding of network protocols, service fingerprinting, and Internet-scale scanning concepts (or fast ability to learn).
- Hands-on experience with agentic systems for offensive security, including building/evaluating LLM-powered attack agents using frameworks such as HackSynth, RedTeamLLM, CAI, PentAG; AI-assisted vulnerability research pipelines; or multi-agent adversary emulation tooling. Demonstrated understanding of their failure modes.
- Proficiency in scripting or coding (Python, Go, or similar) to build tooling, automate testing, or analyze large datasets.
- Familiarity with red team frameworks and tradecraft (C2 frameworks, initial access techniques, living-off-the-land methods, evasion).
- Comfort working with large-scale Internet scan data or strong interest in learning.

## Preferred skills/experience

- Relevant certifications (OSCP, OSCE, OSEP, GXPN, or equivalent).
- Experience with IoT, OT/ICS, or embedded device security research.
- Prior work as a researcher at a security vendor.
- Evidence of research/tooling contributions to the agentic offensive space (benchmarks, PoCs, AI-assisted vulnerability discoveries) and agentic AI red teaming work (e.g. Microsoft's PyRIT, Cloud Security Alliance's Agentic AI Red Teaming Guide).
- Track record of public research output — CVEs, conference talks, technical blog posts, or tool releases.
- Familiarity with compliance-adjacent security testing (e.g. mapping pentest findings to SOC 2, ISO 27001, or CMMC).

## Compensation

For high cost of living areas in the US (San Francisco / Seattle / NYC): $220,000 - $278,000 USD base + bonus eligibility + equity.  
For all other US locations: $202,000 - $254,000 USD base + bonus eligibility + equity.  
Compensation also includes competitive benefits: equity, health/dental/vision, retirement contribution, parental leave, mental health benefits, flexible PTO, professional development stipend, and annual bonus eligibility.

## Similar roles

- [Security Site Lead](https://hotfix.jobs/jobs/5e0f5191-55de-4147-b028-dfa92ffd519d) - Fluidstack - Buffalo, NY - $200k – $250k/yr
- [Senior Software Engineer](https://hotfix.jobs/jobs/2ad28874-4486-42ff-949a-ec54985c2762) - Snowflake - Bellevue, WA - $200k – $288k/yr
- [Senior Software Engineer, Security Foundations](https://hotfix.jobs/jobs/8c688ac7-38e0-46a2-b2ba-354f76225dd9) - Snowflake - Bellevue, WA - $200k – $288k/yr
- [Threat Detection Researcher](https://hotfix.jobs/jobs/60492183-92a6-41ba-871a-dbb16f8bec0a) - Wiz - New York, NY - $200k – $250k/yr
- [Senior Software Engineer](https://hotfix.jobs/jobs/433780b4-d2fd-4bcc-9ee2-fcd1bd108c8b) - Snowflake - Bellevue, WA - $200k – $288k/yr

**Apply:** https://hotfix.jobs/jobs/6434f7ee-206d-45db-963a-9448ae2841e9
**Canonical:** https://hotfix.jobs/jobs/6434f7ee-206d-45db-963a-9448ae2841e9