Senior Security Researcher

Censys

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

About the Company

Censys’ mission is to be the one place to understand everything on the internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.

Responsibilities

  • Drive product capability by bringing an offensive practitioner's perspective to scanning, fingerprinting, and attack surface data
  • Conduct original research into emerging attack techniques, exploitation trends, and C2 infrastructure
  • Publish seminal work including research reports, technical blog posts, and conference-caliber material
  • Collaborate with Engineering and Product to translate research findings into new scanning modules and detection features
  • Lead agentic AI threat research, building and evaluating autonomous penetration testing agents and LLM-powered tools
  • Track adversary infrastructure and encode knowledge into repeatable detection logic
  • Mentor and act as an internal subject-matter expert on offensive techniques

Requirements

  • 5+ years of hands-on penetration testing, red teaming, or adversary emulation experience
  • Demonstrated ability to independently identify and characterize vulnerabilities and exploitation techniques
  • Strong understanding of network protocols and service fingerprinting
  • Hands-on experience with agentic systems for offensive security (e.g., HackSynth, RedTeamLLM, CAI, PentAG)
  • Proficiency in scripting or coding with Python, Go, or similar
  • Familiarity with red team frameworks and tradecraft
  • Comfort working with large-scale Internet scan data

Preferred Qualifications

  • Relevant certifications such as OSCP, OSCE, OSEP, or GXPN
  • Experience with IoT, OT/ICS, or embedded device security research
  • Prior work as a researcher at a security vendor
  • Track record of public research output including CVEs, conference talks, or tool releases
  • Familiarity with compliance-adjacent security testing (SOC 2, ISO 27001, or CMMC)

Skills & tools

Penetration TestingRed TeamingPython

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 015+ years penetration testing or red teaming experience
  2. 02Experience with agentic AI offensive security systems
  3. 03Proficiency in Python or Go
  4. 04Understanding of network protocols and fingerprinting
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches