Senior Security Researcher
CensysRemote1w ago
Securityremotecurated-jd
Job description
Senior Security Researcher at Censys
About the role
This position offers the chance to conduct groundbreaking research at the intersection of internet-scale data, threat analysis, and real-world cybersecurity challenges. Your work will directly contribute to protecting organizations and national security, while also shaping Censys's product capabilities and public perception.
Key facts
What you'll do
- Enhance product features by applying an offensive security viewpoint to Censys's internet scanning, fingerprinting, and attack surface data.
- Investigate new attack methods, exploitation trends, command and control infrastructure, and adversary tactics using internet-wide scan data and custom testing.
- Produce influential research in the form of reports, technical articles, and conference presentations.
- Collaborate with engineering and product teams to integrate research findings into new scanning modules, fingerprints, risk signals, and detection features.
- Lead research into agentic AI for threat intelligence, building and assessing AI-driven penetration testing agents and LLM-powered vulnerability research tools.
- Identify and document how threat actors establish and conceal their infrastructure, translating this knowledge into repeatable detection logic.
- Serve as an internal expert on offensive security techniques, guiding other researchers and engineers.
Requirements
- A minimum of 5 years of practical experience in penetration testing, red teaming, or adversary emulation targeting enterprise, cloud, or internet-facing systems.
- Proven ability to independently discover and describe vulnerabilities, misconfigurations, or exploitation techniques.
- Solid understanding of network protocols, service fingerprinting, and internet-scale scanning concepts, or the capacity to learn them quickly.
- Hands-on experience with agentic systems for offensive security, including building, evaluating, or operating LLM-powered attack agents using frameworks like HackSynth, RedTeamLLM, CAI, PentAG, or similar, and understanding their limitations.
- Proficiency in scripting or programming languages such as Python or Go for tool development, test automation, or data analysis.
- Familiarity with red team methodologies and tools, including C2 frameworks, initial access methods, living-off-the-land techniques, and evasion strategies.
- Comfort working with large-scale internet scan data or a strong desire to develop this skill.
Nice to have
- Relevant security certifications such as OSCP, OSCE, OSEP, GXPN, or equivalent demonstrated expertise.
- Experience in IoT, OT/ICS, or embedded device security research.
- Previous experience as a researcher in a security vendor environment.
- Contributions to the agentic offensive security space, such as benchmarks, proof-of-concepts, AI-assisted vulnerability discoveries, or agentic AI red teaming work.
- A history of public research contributions, including CVEs, conference talks, technical blog posts, or tool releases.
Skills & tools
- Python
- Go
- Agentic AI frameworks (e.g., HackSynth, RedTeamLLM, CAI, PentAG)
- C2 frameworks
- Network protocols
- Internet-scale scanning
Practical notes
- Salary range for high cost of living US areas (San Francisco, Seattle, NYC): $220,000 - $278,000 USD, plus bonus and equity.
- Salary range for other US locations: $202,000 - $254,000 USD, plus bonus and equity.
- Compensation outside the US will be based on local market data.
- US employees receive benefits including equity, health, dental, vision, retirement contributions, parental leave, wellness programs, flexible PTO, and professional development stipends.
- Travel is expected quarterly for industry events and team meetings.
- Candidates may be required to meet a Censys employee and will be invited to Ann Arbor, Michigan for in-person onboarding.
- All candidates must keep cameras on during video interviews.