Censys

Senior Security Researcher

Censys
Apply
2 months ago
Remote, United StatesSenior

Base Salary

$202k - $254k/yr

Responsibilities

  • Use offensive security expertise to identify gaps in Censys scanning, fingerprinting, protocol coverage, vulnerability signals, and attack-surface data.
  • Investigate emerging attack techniques, exploitation trends, C2 infrastructure, and adversary tradecraft using Internet-wide scan data and testing methodologies.
  • Build, deploy, and evaluate autonomous penetration-testing agents, LLM-powered vulnerability research tools, and multi-agent adversary-emulation systems.
  • Research how attackers create, configure, conceal, and operate infrastructure, then encode findings into repeatable detection logic.
  • Translate research into scanning modules, fingerprints, risk indicators, detection features, and other product capabilities with Engineering and Product teams.
  • Produce research reports, technical blog posts, conference-caliber material, and other public security research.
  • Mentor researchers and engineers as an internal subject-matter expert on offensive techniques and attacker behavior.

Requirements

  • At least five years of hands-on penetration testing, red teaming, or adversary emulation experience against enterprise, cloud, or Internet-facing environments.
  • Ability to independently identify and characterize vulnerabilities, misconfigurations, or exploitation techniques.
  • Strong understanding of network protocols, service fingerprinting, and Internet-scale scanning concepts, or ability to learn them quickly.
  • Hands-on experience building, evaluating, or operating LLM-powered offensive security agents and agentic systems, including understanding their failure modes.
  • Proficiency in Python, Go, or similar scripting or programming languages for tooling, testing automation, or large-dataset analysis.
  • Familiarity with C2 frameworks, initial access techniques, living-off-the-land methods, and evasion tradecraft.
  • Comfort working with large-scale Internet scan data or strong interest in learning to do so.
  • Preferred certifications include OSCP, OSCE, OSEP, GXPN, or equivalent demonstrated skill.
  • Preferred experience includes IoT, OT/ICS, or embedded device security research; security-vendor research; public research such as CVEs, conference talks, technical blog posts, or tool releases; and agentic AI red-teaming contributions.
  • Familiarity with compliance-adjacent security testing involving SOC 2, ISO 27001, or CMMC controls is a plus.

Benefits

  • Remote position with no expectation to work from a Censys office
  • Expected travel once per quarter for industry events and team onsites
  • US benefits include equity, health, dental and vision coverage, retirement contribution, parental leave, mental health and wellness benefits, flexible PTO, and a professional development stipend
  • Eligible non-sales employees may participate in an annual bonus plan
  • Hired employees will be invited to visit Ann Arbor, Michigan for in-person onboarding

Tech Stack

Censys

About Censys

51-200 employees

Censys is the authority in Internet intelligence and insights. Delivering the most comprehensive, accurate, and up-to-date global map of Internet infrastructure, Censys provides the real-time external visibility organizations need to accelerate security operations, investigate threats, and understand Internet exposure. Global governments, Fortune 500 companies, and security providers trust Censys to uncover risks faster and respond more effectively.

Contact me