Senior Security Researcher
Job description
About the role
This position provides an exciting opportunity to engage in innovative research that merges large-scale internet data analysis with threat assessment and real-world cybersecurity issues. Your contributions will play a vital role in safeguarding organizations and enhancing national security, while also influencing the development of Censys's products and its reputation in the cybersecurity landscape.
Key facts
What you'll do
- Improve product functionalities by leveraging an offensive security perspective on Censys's internet scanning, fingerprinting, and attack surface data.
- Explore emerging attack techniques, exploitation patterns, command and control frameworks, and adversary strategies through the analysis of internet-wide scan data and tailored testing.
- Generate impactful research outputs, including detailed reports, technical articles, and presentations for conferences.
- Collaborate closely with engineering and product teams to incorporate research insights into new scanning modules, fingerprints, risk indicators, and detection capabilities.
- Spearhead research initiatives focused on agentic AI for threat intelligence, developing and evaluating AI-driven penetration testing agents and LLM-powered tools for vulnerability research.
- Identify and document the methods used by threat actors to establish and obscure their infrastructures, translating these insights into actionable detection logic.
- Act as an internal authority on offensive security methodologies, providing guidance to fellow researchers and engineers.
- Engage in continuous learning and adaptation to stay ahead of evolving cybersecurity threats and trends.
Requirements
- At least 5 years of hands-on experience in penetration testing, red teaming, or adversary emulation, specifically targeting enterprise, cloud, or internet-facing systems.
- Demonstrated ability to independently identify and articulate vulnerabilities, misconfigurations, or exploitation techniques.
- Strong foundational knowledge of network protocols, service fingerprinting, and concepts related to internet-scale scanning, or a willingness to quickly acquire this knowledge.
- Practical experience with agentic systems in offensive security, including the construction, evaluation, or operation of LLM-powered attack agents utilizing frameworks such as HackSynth, RedTeamLLM, CAI, PentAG, or similar, along with an understanding of their limitations.
- Proficiency in programming or scripting languages like Python or Go for the development of tools, automation of tests, or analysis of data.
- Familiarity with red team methodologies and tools, including command and control frameworks, initial access techniques, living-off-the-land strategies, and evasion tactics.
- Comfort with handling large-scale internet scan data or a strong desire to develop this capability.
Nice to have
- Relevant security certifications such as OSCP, OSCE, OSEP, GXPN, or equivalent demonstrated expertise.
- Experience in security research related to IoT, OT/ICS, or embedded devices.
- Prior experience as a researcher within a security vendor environment.
- Contributions to the field of agentic offensive security, including benchmarks, proof-of-concept work, AI-assisted vulnerability discoveries, or agentic AI red teaming initiatives.
- A track record of public research contributions, such as CVEs, conference presentations, technical blog posts, or tool releases.
Skills & tools
- Python
- Go
- Agentic AI frameworks (e.g., HackSynth, RedTeamLLM, CAI, PentAG)
- Command and control frameworks
- Network protocols
- Internet-scale scanning
Practical notes
- The salary range for positions in high-cost living areas of the US (such as San Francisco, Seattle, and New York City) is between $220,000 and $278,000 USD, in addition to bonuses and equity.
- For other locations within the US, the salary range is between $202,000 and $254,000 USD, also accompanied by bonuses and equity.
- Compensation for roles outside the US will be determined based on local market conditions.
- Employees based in the US are entitled to benefits that include equity, health insurance, dental and vision coverage, retirement contributions, parental leave, wellness programs, flexible paid time off, and stipends for professional development.
- Quarterly travel is anticipated for industry events and team gatherings.
- Candidates may be required to meet with a Censys employee and will be invited to Ann Arbor, Michigan for in-person onboarding.
- All candidates must keep their cameras on during video interviews.
About the company
A security service delivers internet intelligence through continuous scanning of the online environment. Originating in 2015 from University of Michigan work, the company supports exploration and data gathering. By 2023, user numbers reached 350,000. Teams rely on findings for visibility. Roles often focus on analysis, improvement, and support within this scanning driven environment. Understanding digital exposure requires constant observation. Professionals join to strengthen insight, working with datasets that inform decisions across security operations and client requirements.