Security ResearchCareer GuideOffensive Security

How to Become a Security Researcher in 2026 (Vulnerability Research, Malware Analysis & Offensive R&D)

IJB

InfoSec Job Board

July 31, 2026 · 10 min read

Security research is the track where cybersecurity stops being about operating defenses and starts being about discovering things nobody knew: new vulnerabilities, novel exploitation techniques, malware behavior, detection gaps. It is the most portfolio-driven discipline in the field - the interview is largely your public work - and it is bigger than most people assume: we track 105 live researcher roles right now (security researcher, vulnerability researcher, malware researcher, threat researcher), the largest title cluster on our board.

What security researchers actually do

"Researcher" covers four overlapping jobs, and knowing which one you are aiming at changes everything about how you prepare:

  • Vulnerability research and exploit development. Finding flaws in software, firmware, and hardware - fuzzing, reverse engineering, memory-corruption work - and proving exploitability. The deepest technical bar in the industry.
  • Malware analysis and reverse engineering. Taking apart real attacker tooling to understand capability and build detection. The bridge role between research and threat intelligence.
  • Detection and defensive research. Studying attacker techniques to build the signatures, analytics, and product features that catch them - most security-vendor "researcher" seats are this.
  • Offensive R&D and AI security research. Building attack tooling and techniques (adjacent to red team work), and - the fastest-growing corner - probing AI systems: model jailbreaks, LLM attack research, agentic-security work at frontier labs and AI-security startups.

Who hires researchers

Four employer families dominate the 105 live roles we track. Security-product vendors are the volume hirers - endpoint, network, and cloud security companies staff research teams to feed their detection engines and publish the threat research that markets the product. Platform and product companies (browsers, operating systems, cloud providers, payment platforms) hire researchers to attack their own products before others do. Specialist firms - digital forensics, mobile security, offensive tooling - hire deep iOS, Android, and embedded expertise: some of the most advanced vulnerability-research seats on our board are at digital-intelligence companies hiring iOS and Android researchers and exploit engineers. And the newest family: AI-security labs and autonomous-offensive-security startups, hiring researchers to break and harden AI systems (start with the AI security board and the AI security career guide).

The proof-of-work ladder (this IS the resume)

No other security role weighs public evidence so heavily. The ladder, in the order most working researchers actually climbed it:

  1. CTFs. Capture-the-flag competitions (pwn and reversing categories especially) are where the core skills get built. Team results and write-ups are legible to every hiring manager in this field.
  2. Write-ups. Publish your analysis: a CTF challenge, an N-day you re-derived from a patch, a malware sample you unpacked. Clear technical writing is half the researcher job - vendors publish research as marketing, so they hire people who can write it.
  3. A first CVE. Pick soft targets first: smaller open-source projects, plugins, IoT firmware, less-audited enterprise software. One real CVE with a clean advisory outweighs any certification on a researcher resume.
  4. Bug bounty. A paid-bounty track record is verifiable evidence of finding real vulnerabilities in hardened targets. It is also a viable income bridge while you build toward employment - though grinding duplicates on saturated programs teaches less than deep work on one product family.
  5. Tooling and talks. A published fuzzer harness, Ghidra script, or conference talk (local BSides count) compounds all of the above.

Skills by track

  • Vulnerability research: C and C++ internals, memory corruption, fuzzing (AFL++, libFuzzer), a disassembler (Ghidra is free and standard now, IDA in many shops), one platform deep (Windows internals, Linux kernel, iOS, Android, or embedded).
  • Malware analysis: x86/ARM assembly, unpacking, dynamic analysis and sandboxing, Python for automation - GREM is the one certification this track genuinely respects.
  • Detection research: attacker tradecraft (MITRE ATT&CK fluency), log and telemetry analysis, plus enough engineering to ship a detection - a natural move up from detection engineering.
  • AI security research: LLM internals and failure modes, prompt- and model-level attacks, and classic AppSec instincts applied to model pipelines.

Certifications, honestly

This is the least certification-driven track in security. OSCP signals offensive fundamentals, OSED covers exploit development, GREM carries real weight for malware roles - but every hiring manager in research will trade all three for one good CVE and a well-written analysis. Budget your time accordingly: portfolio first, certificates only where a posting you want names one.

What it pays

Honesty note: researcher-titled postings almost never disclose pay, so we do not publish a researcher salary table - but the market context is clear. Research seats price at or above the senior engineering bands at the same employers (US senior security engineering runs $170,000 - $260,000 in our benchmarks), specialist vulnerability-research and exploit-development skills price above that, and top AI-lab and offensive-research seats are among the highest IC packages in the industry. Cross-check the live disclosed data in the salary report and add your own anonymous data point to the community salary dataset - research comp is exactly where transparency is thinnest.

Landing the first role

Almost nobody is hired into research from zero. The working on-ramps: SOC and detection work into malware analysis (you already triage samples - start publishing the analysis); penetration testing into vulnerability research (you already find bugs - go deeper on fewer targets); software engineering into fuzzing and product security (you understand the code being attacked - the product security track is the natural bridge); and academia into industry labs. Apply to "associate researcher" and "junior analyst, research team" titles, filter the researcher board weekly, and remember the field's one reliable rule: the work you publish before anyone pays you for it is what gets someone to pay you for it.

Live security research roles

Browse security researcher jobs

Get weekly alerts for Get weekly alerts for new security researcher jobs:

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.