66 security researcher jobs at 49 companies in Santa Rosa, CA
1mo
Save
Mark Applied
Hide
1mo
Security Researcher
San Francisco or Israel
OnsiteFull Time
Pi Security: Private cybersecurity startup providing an agentic product security platform that helps organizations detect, fix, and prevent vulnerabilities.
8+ YOE8+ years in security research or applied security engineering, startup/0→1 experience, research-to-product track record, strong programming (Python/Go/TypeScript), LLM fluency, experiment and benchmark design, and US or Israel work authorization.
Strix: Private U.S. cybersecurity providing autonomous AI penetration testing for applications, APIs, code, cloud, and infrastructure.
3+ YOE3+ years of hands-on offensive security experience, deep web application security and exploitation expertise, and Python or similar programming experience. CVEs, research, CTFs, or bug bounty experience preferred.
Palo Alto NetworksNASDAQ: PANW: Global cybersecurity platform providing network, cloud, and AI-driven security solutions.
Deep hands-on vulnerability research, exploit analysis, IPS/IDS detection, network protocol expertise, strong programming/scripting for research automation, technical leadership, and BS/MS in CS/CE/Cybersecurity or equivalent experience.
Apollo Research: AI safety organization evaluating frontier models for AI labs and developing tools to detect and mitigate scheming.
5+ YOERequires 5+ years of hands-on security experience, offensive security, threat modeling, code and infrastructure literacy, engineering mindset, strong writing, and comfort with ambiguity; AI/ML security experience is preferred.
GoogleNASDAQ: GOOG, GOOGL: Global technology specializing in internet-related services and products.
1+ YOEBachelor's degree or equivalent practical experience, 1+ year of UX research design experience, and experience with usability studies, contextual inquiries, interviews, surveys, or unmoderated research.
Anthropic: AI research developing safe and steerable AI systems.
7+ YOEDeep cybersecurity expertise, experience building AI-powered security tools, rigorous evaluation skills, clear technical communication, and 7+ years in security research, engineering, or a related field.
GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, Learning from Human Preferences
Security Level 5: Nonprofit developing AI security standards for frontier labs against nation-state threats.
Security research or standards experience; ability to read NIST, ICD 705, and vendor documentation, synthesize primary sources, and write clearly and precisely under editorial pressure.
Resolution: Nonprofit AI safety research organization using theory and automation to improve alignment of artificial superintelligence.
Build and own corporate IT security for a distributed research org; hands-on experience with endpoint management, IAM/Zero-Trust, email security, compliance (SOC 2/ISO 27001), and translating security requirements for researchers. Bachelor's degree or equivalent required.
MDM/EDR, CI/CD, Zero-Trust, multi-cloud, SOC 2, ISO 27001
North America or Washington, D.C. or San Francisco
$220k-$330k/yrRemoteFull Time
AI Verification and Evaluation Research Institute: U.S. nonprofit research institute helping companies, policymakers, and the public verify frontier AI safety and security claims.
Production systems experience; ability to build novel systems; familiarity with language-model safety and security research; cybersecurity communication skills; and high integrity and discretion.
OktaNASDAQ: OKTA: Identity management and access control software provider.
7+ YOE7+ years in information security with deep application/offensive research or AI/ML security, hands-on assessment of LLM-integrated and agentic systems, proficiency in multiple programming languages, threat modeling, manual code review, and strong communication.
Boston or Austin or Washington or Seattle or San Francisco
$120k-$155k/yrRemoteFull Time
HackerOne: Private cybersecurity providing continuous threat exposure management and ethical-hacker security services to enterprises.
3+ YOE3+ years security testing/vulnerability research on web/mobile apps, strong OWASP Top 10 knowledge, experience with Burp Suite and CVSS, ability to reproduce/validate findings and communicate technical impact in English.
Burp Suite, Common Vulnerability Scoring System (CVSS)
Washington or Pittsburgh or Santa Monica or Boston or San Francisco or United States
$90k-$177k/yrHybridFull Time, Temporary
RAND Corporation: Nonprofit, nonpartisan policy research institution helping governments and other leaders improve decisions through evidence-based analysis.
1+ YOETechnical experience in security/software/firmware/hardware engineering, project leadership and management, proficiency in Python/Java/C/C++, threat modeling skills, MS Office fluency, strong written and verbal communication.
Python, Java, C/C++, Microsoft Office, CUDA, PyTorch, TensorFlow, Ray
ProGuard Security Services: Private California security-services provider supplying contract officers, patrol, monitoring, assessments, and event security to businesses.
High school diploma or equivalent, prior security experience, basic computer and wireless communication skills, physical ability to patrol, and strong oral communication. Security training and first aid/CPR are preferred.
access control systems, wireless communication technology, radios
Security Software Engineer, Open Source Frameworks
San Francisco or New York City or London or Berlin
$208k-$312k/yrHybridFull Time
Vercel: Software providing developer infrastructure for teams building web applications and AI agents.
4+ YOE4+ years security engineering with hands-on open source contributions; deep JavaScript/TypeScript and Node framework knowledge; vulnerability research, coordinated disclosure, and CVE experience; strong communication.
Research Security Cybersecurity Specialist (5271C) The Office of Research Administration & Compliance #88458
Berkeley, California, United States
$112k-$163k/yrRemoteFull Time
University of California, Berkeley: Public research university dedicated to academic and research excellence.
3+ YOEBachelor's degree or equivalent experience, 3+ years of cybersecurity experience, and expertise assessing NIST frameworks, CMMC, FISMA, data security regulations, and research compliance.
Chicago or Los Angeles or New York City or San Francisco or Seattle or Washington, D.C.
$194k-$262k/yrOnsiteFull Time
West Monroe: Business and technology consulting firm.
7+ YOE7+ years in security architecture/SOC modernization; experience with SIEM/SOAR, detection engineering, AI-enabled SOCs, platform modernization, and executive advisory; willingness to travel; must be eligible to work in the US without sponsorship.
Code Metal: AI software translating, verifying, and optimizing code for mission-critical industries deploying software on specialized hardware.
3+ YOEBachelor's or Master's in a technical field (or equivalent), 3+ years building AI/ML or applied research systems, strong Python and PyTorch skills, experience with LLM tooling, fine-tuning, retrieval, agentic systems, and experiment design; eligible to obtain U.S. security clearance.
Cambridge or New York City or Washington or Atlanta or San Francisco
$119k-$193k/yrOnsiteFull Time
Forrester ResearchNasdaq: FORR: Public research and advisory firm serving business and technology leaders with research, consulting, and events.
5+ YOERequires 5+ years of security and risk experience, BA/BS or equivalent, strong research, critical thinking, writing, presentation, and business skills; must be a US citizen and travel 30%-50%.
Managed Detection and Response (MDR), Managed Security Services (MSS), Zero Trust