Vulnerability and Exploitation Researcher
Quick Summary
What we do At runZero, we're a team of dreamers and creative thinkers who aren't afraid to shake up the status quo. Fixing what’s broken with legacy vulnerability management and overcoming persistent,
At runZero, we're a team of dreamers and creative thinkers who aren't afraid to shake up the status quo. Fixing what’s broken with legacy vulnerability management and overcoming persistent, decades-old problems requires a new approach.
Our platform provides a single source of truth for exposure management across the total attack surface. Without requiring agents, authentication, or appliances, runZero delivers the most complete and accurate visibility into every asset and exposure across internal, external, IT, OT, IoT, mobile, and cloud environments — including uncovering unknown and unmanageable devices and broad classes of exposures that evade traditional tools.
Founded by HD Moore (creator of Metasploit), runZero is trusted by more than 500 companies and 30,000 users worldwide to find and mitigate risks faster, meet compliance requirements, and improve overall security. See for yourself with a free trial!
As a Vulnerability Researcher, you'll play a critical role in uncovering and analyzing vulnerabilities to strengthen runZero’s detection and intelligence capabilities. From researching and monitoring security threats, to collaborating with engineers on developing detection rules and vulnerability checks, to leading short-term original vulnerability research projects, you'll help drive impact by proactively identifying risks and surfacing insights for our customers.
Responsibilities
~1 min read- →Research current vulnerabilities and exploits using trusted sources, and stay up to date with threat intelligence
- →Write root cause analyses and technical reports, as needed, clearly communicating findings to technical audiences
- →Proactively monitor security-related information sources to discover new vulnerabilities and attack vectors
- →Apply analytical expertise to investigate malware, phishing, mobile, and brand threats, delivering actionable vulnerability intelligence
- →Assess the impact of vulnerabilities on critical systems and advise stakeholders on remediation strategies
- →Build custom detection rules, identify unique attack attributes, and surface vulnerable internet-connected assets
- →Assess in-the-wild exploitation readiness
- →Research and develop new exploits and attack techniques
- →Work with product and research engineers to develop vulnerability checks, fingerprints, queries, and detections
- →Collaborate with the engineering team to add findings to the codebase, ideally in Golang
Requirements
~1 min read- Hands-on experience with common vulnerability classes and exploitation techniques
- Familiarity with CVE (Common Vulnerabilities and Exposures), CWE (Common Weakness Enumeration), CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System).
- Experience using vulnerability and compliance scanning tools (Tenable, Rapid7, Qualys, Rockwell, and many other options)
- Solid grasp of security advisories, vulnerability exploitation, and threat impact
- Experience collaborating with engineers on automated tooling and detection rules
- Familiarity with Git, GitHub, CI/CD processes
- Familiarity with at least one programming language and the ability to use it to automate tasks (e.g. Go, Python, or Ruby)
- Knowledge of regular expressions (regex) and SQL for querying large databases is a big plus
- Experience coding in Go is a big plus
- Presentation skills at hacker conferences is a big plus
What We Offer
~1 min readListing Details
- Posted
- March 28, 2026
- First seen
- April 3, 2026
- Last seen
- April 27, 2026
Posting Health
- Days active
- 23
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- April 27, 2026
Signal breakdown
Please let runZero know you found this job on Jobera.
3 other jobs at runZero
View all →Explore open roles at runZero.
Similar Researcher jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.