Security research is the track where cybersecurity stops being about operating defenses and starts being about discovering things nobody knew: new vulnerabilities, novel exploitation techniques, malware behavior, detection gaps. It is the most portfolio-driven discipline in the field - the interview is largely your public work - and it is bigger than most people assume: we track 105 live researcher roles right now (security researcher, vulnerability researcher, malware researcher, threat researcher), the largest title cluster on our board.
What security researchers actually do
"Researcher" covers four overlapping jobs, and knowing which one you are aiming at changes everything about how you prepare:
- Vulnerability research and exploit development. Finding flaws in software, firmware, and hardware - fuzzing, reverse engineering, memory-corruption work - and proving exploitability. The deepest technical bar in the industry.
- Malware analysis and reverse engineering. Taking apart real attacker tooling to understand capability and build detection. The bridge role between research and threat intelligence.
- Detection and defensive research. Studying attacker techniques to build the signatures, analytics, and product features that catch them - most security-vendor "researcher" seats are this.
- Offensive R&D and AI security research. Building attack tooling and techniques (adjacent to red team work), and - the fastest-growing corner - probing AI systems: model jailbreaks, LLM attack research, agentic-security work at frontier labs and AI-security startups.
Who hires researchers
Four employer families dominate the 105 live roles we track. Security-product vendors are the volume hirers - endpoint, network, and cloud security companies staff research teams to feed their detection engines and publish the threat research that markets the product. Platform and product companies (browsers, operating systems, cloud providers, payment platforms) hire researchers to attack their own products before others do. Specialist firms - digital forensics, mobile security, offensive tooling - hire deep iOS, Android, and embedded expertise: some of the most advanced vulnerability-research seats on our board are at digital-intelligence companies hiring iOS and Android researchers and exploit engineers. And the newest family: AI-security labs and autonomous-offensive-security startups, hiring researchers to break and harden AI systems (start with the AI security board and the AI security career guide).
The proof-of-work ladder (this IS the resume)
No other security role weighs public evidence so heavily. The ladder, in the order most working researchers actually climbed it:
- CTFs. Capture-the-flag competitions (pwn and reversing categories especially) are where the core skills get built. Team results and write-ups are legible to every hiring manager in this field.
- Write-ups. Publish your analysis: a CTF challenge, an N-day you re-derived from a patch, a malware sample you unpacked. Clear technical writing is half the researcher job - vendors publish research as marketing, so they hire people who can write it.
- A first CVE. Pick soft targets first: smaller open-source projects, plugins, IoT firmware, less-audited enterprise software. One real CVE with a clean advisory outweighs any certification on a researcher resume.
- Bug bounty. A paid-bounty track record is verifiable evidence of finding real vulnerabilities in hardened targets. It is also a viable income bridge while you build toward employment - though grinding duplicates on saturated programs teaches less than deep work on one product family.
- Tooling and talks. A published fuzzer harness, Ghidra script, or conference talk (local BSides count) compounds all of the above.
Skills by track
- Vulnerability research: C and C++ internals, memory corruption, fuzzing (AFL++, libFuzzer), a disassembler (Ghidra is free and standard now, IDA in many shops), one platform deep (Windows internals, Linux kernel, iOS, Android, or embedded).
- Malware analysis: x86/ARM assembly, unpacking, dynamic analysis and sandboxing, Python for automation - GREM is the one certification this track genuinely respects.
- Detection research: attacker tradecraft (MITRE ATT&CK fluency), log and telemetry analysis, plus enough engineering to ship a detection - a natural move up from detection engineering.
- AI security research: LLM internals and failure modes, prompt- and model-level attacks, and classic AppSec instincts applied to model pipelines.
Certifications, honestly
This is the least certification-driven track in security. OSCP signals offensive fundamentals, OSED covers exploit development, GREM carries real weight for malware roles - but every hiring manager in research will trade all three for one good CVE and a well-written analysis. Budget your time accordingly: portfolio first, certificates only where a posting you want names one.
What it pays
Honesty note: researcher-titled postings almost never disclose pay, so we do not publish a researcher salary table - but the market context is clear. Research seats price at or above the senior engineering bands at the same employers (US senior security engineering runs $170,000 - $260,000 in our benchmarks), specialist vulnerability-research and exploit-development skills price above that, and top AI-lab and offensive-research seats are among the highest IC packages in the industry. Cross-check the live disclosed data in the salary report and add your own anonymous data point to the community salary dataset - research comp is exactly where transparency is thinnest.
Landing the first role
Almost nobody is hired into research from zero. The working on-ramps: SOC and detection work into malware analysis (you already triage samples - start publishing the analysis); penetration testing into vulnerability research (you already find bugs - go deeper on fewer targets); software engineering into fuzzing and product security (you understand the code being attacked - the product security track is the natural bridge); and academia into industry labs. Apply to "associate researcher" and "junior analyst, research team" titles, filter the researcher board weekly, and remember the field's one reliable rule: the work you publish before anyone pays you for it is what gets someone to pay you for it.
Live security research roles
Related guides
CISO Salary in 2026: $200k-$350k in the US, Benchmarks for 21 Countries & What Moves the Number
What CISOs really earn in 2026: $200,000-$350,000 base in the US, tax-free packages in the Gulf that beat it o…
9 min read
How to Become a CISO in 2026: the Three Paths, the Deputy Route & the First 90 Days
The realistic routes to Chief Information Security Officer: the operator path, the GRC path, and the consultin…
10 min read
Cybersecurity Hiring Pulse - August 2026: 1,029 Open Roles, AWS Overtakes Python, AI Security Goes Mainstream
The August 2026 cybersecurity hiring snapshot, measured from live postings across 246 security companies: 1,02…
6 min read