66 security researcher jobs at 49 companies in Santa Rosa, CA

1mo
Save
Mark Applied
Hide
Security Researcher
San Francisco or Israel
OnsiteFull Time
Pi Security
Pi Security: Private cybersecurity startup providing an agentic product security platform that helps organizations detect, fix, and prevent vulnerabilities.
8+ YOE8+ years in security research or applied security engineering, startup/0→1 experience, research-to-product track record, strong programming (Python/Go/TypeScript), LLM fluency, experiment and benchmark design, and US or Israel work authorization.
Python, Go, TypeScript, LLMs, AWS, GCP
1w
Save
Mark Applied
Hide
Security Researcher
New York City or San Francisco
OnsiteFull Time
Strix
Strix: Private U.S. cybersecurity providing autonomous AI penetration testing for applications, APIs, code, cloud, and infrastructure.
3+ YOE3+ years of hands-on offensive security experience, deep web application security and exploitation expertise, and Python or similar programming experience. CVEs, research, CTFs, or bug bounty experience preferred.
Python
2mo
Save
Mark Applied
Hide
Principal Security Researcher
Santa Clara or San Francisco or San Jose
$163k-$263k/yr OnsiteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Global cybersecurity platform providing network, cloud, and AI-driven security solutions.
Deep hands-on vulnerability research, exploit analysis, IPS/IDS detection, network protocol expertise, strong programming/scripting for research automation, technical leadership, and BS/MS in CS/CE/Cybersecurity or equivalent experience.
4d
Save
Mark Applied
Hide
AI Security Researcher
London or San Francisco
$214k-$280k/yr HybridFull Time
Apollo Research
Apollo Research: AI safety organization evaluating frontier models for AI labs and developing tools to detect and mitigate scheming.
5+ YOERequires 5+ years of hands-on security experience, offensive security, threat modeling, code and infrastructure literacy, engineering mindset, strong writing, and comfort with ambiguity; AI/ML security experience is preferred.
AI agents, Watcher, LLM
4d
Save
Mark Applied
Hide
UX Researcher, Privacy, Safety and Security
New York City or San Francisco
$109k-$155k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOG, GOOGL: Global technology specializing in internet-related services and products.
1+ YOEBachelor's degree or equivalent practical experience, 1+ year of UX research design experience, and experience with usability studies, contextual inquiries, interviews, surveys, or unmoderated research.
2w
Save
Mark Applied
Hide
Staff+ Researcher, Cybersecurity Products
San Francisco, California, United States
$405k-$485k/yr HybridFull Time
Anthropic
Anthropic: AI research developing safe and steerable AI systems.
7+ YOEDeep cybersecurity expertise, experience building AI-powered security tools, rigorous evaluation skills, clear technical communication, and 7+ years in security research, engineering, or a related field.
GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, Learning from Human Preferences
2w
Save
Mark Applied
Hide
Standards Researcher
San Francisco, California, United States
$140k-$200k/yr OnsiteFull Time
Security Level 5
Security Level 5: Nonprofit developing AI security standards for frontier labs against nation-state threats.
Security research or standards experience; ability to read NIST, ICD 705, and vendor documentation, synthesize primary sources, and write clearly and precisely under editorial pressure.
NIST, ICD 705
2mo
Save
Mark Applied
Hide
Security Engineer (Corporate IT)
Berkeley or London or United States
$346k-$930k/yr OnsiteFull Time
Resolution
Resolution: Nonprofit AI safety research organization using theory and automation to improve alignment of artificial superintelligence.
Build and own corporate IT security for a distributed research org; hands-on experience with endpoint management, IAM/Zero-Trust, email security, compliance (SOC 2/ISO 27001), and translating security requirements for researchers. Bachelor's degree or equivalent required.
MDM/EDR, CI/CD, Zero-Trust, multi-cloud, SOC 2, ISO 27001
5d
Save
Mark Applied
Hide
Security Research Engineer
North America or Washington, D.C. or San Francisco
$220k-$330k/yr RemoteFull Time
AI Verification and Evaluation Research Institute
AI Verification and Evaluation Research Institute: U.S. nonprofit research institute helping companies, policymakers, and the public verify frontier AI safety and security claims.
Production systems experience; ability to build novel systems; familiarity with language-model safety and security research; cybersecurity communication skills; and high integrity and discretion.
privacy-enhancing technologies (PETs), cryptography
5d
Save
Mark Applied
Hide
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
United States or Washington or Los Angeles or California or San Francisco or New York City
$133k-$211k/yr RemoteFull Time
Elastic
ElasticNYSE: ESTC: Search AI platform for search, observability, and security.
6+ YOERequires 6+ years reverse engineering malware and researching adversary tradecraft, Python, C/C++ literacy, YARA, Windows/Linux internals, networking, cryptography, technical writing, and AI-assisted development experience.
Python, C, C++, YARA, HTTP, TLS, Rust, Go, NodeJS, MISP, OpenCTI, Elasticsearch, Kibana, Elastic Security, GitHub, AI
2mo
Save
Mark Applied
Hide
Staff Product Security Engineer
San Francisco, California, United States
$180k-$248k/yr HybridFull Time
Okta
OktaNASDAQ: OKTA: Identity management and access control software provider.
7+ YOE7+ years in information security with deep application/offensive research or AI/ML security, hands-on assessment of LLM-integrated and agentic systems, proficiency in multiple programming languages, threat modeling, manual code review, and strong communication.
Python, Go, Java, TypeScript, C, C++, SAST, DAST, SCA, fuzzing, OIDC, OAuth 2.0, SAML, CI/CD, LLM, MCP
2mo
Save
Mark Applied
Hide
Product Security Analyst
Boston or Austin or Washington or Seattle or San Francisco
$120k-$155k/yr RemoteFull Time
HackerOne
HackerOne: Private cybersecurity providing continuous threat exposure management and ethical-hacker security services to enterprises.
3+ YOE3+ years security testing/vulnerability research on web/mobile apps, strong OWASP Top 10 knowledge, experience with Burp Suite and CVSS, ability to reproduce/validate findings and communicate technical impact in English.
Burp Suite, Common Vulnerability Scoring System (CVSS)
2mo
Save
Mark Applied
Hide
Associate AI Security Resident
Washington or Pittsburgh or Santa Monica or Boston or San Francisco or United States
$90k-$177k/yr HybridFull Time, Temporary
RAND Corporation
RAND Corporation: Nonprofit, nonpartisan policy research institution helping governments and other leaders improve decisions through evidence-based analysis.
1+ YOETechnical experience in security/software/firmware/hardware engineering, project leadership and management, proficiency in Python/Java/C/C++, threat modeling skills, MS Office fluency, strong written and verbal communication.
Python, Java, C/C++, Microsoft Office, CUDA, PyTorch, TensorFlow, Ray
1w
Save
Mark Applied
Hide
Security Officer / Research Hall $24.90
San Francisco, California, United States
$25/hr OnsiteFull Time
ProGuard Security Services
ProGuard Security Services: Private California security-services provider supplying contract officers, patrol, monitoring, assessments, and event security to businesses.
High school diploma or equivalent, prior security experience, basic computer and wireless communication skills, physical ability to patrol, and strong oral communication. Security training and first aid/CPR are preferred.
access control systems, wireless communication technology, radios
1mo
Save
Mark Applied
Hide
Security Software Engineer, Open Source Frameworks
San Francisco or New York City or London or Berlin
$208k-$312k/yr HybridFull Time
Vercel
Vercel: Software providing developer infrastructure for teams building web applications and AI agents.
4+ YOE4+ years security engineering with hands-on open source contributions; deep JavaScript/TypeScript and Node framework knowledge; vulnerability research, coordinated disclosure, and CVE experience; strong communication.
Turborepo, Nuxt, Svelte, SvelteKit, SWR, Workflow, Nitro, JavaScript, TypeScript, Node, Sigstore, SLSA
2w
Save
Mark Applied
Hide
Security Solutions Engineer (Pre-Sales) - Remote/SF Bay Area
San Francisco or United States
$150k-$200k/yr RemoteFull Time
EVOTEK
EVOTEK: IT services and systems integration firm helping businesses modernize data-center, network, cloud, and cybersecurity environments.
Requires enterprise cybersecurity knowledge, cybersecurity solution sales, pipeline management, solution design, presentation skills, client communication, and market research experience; technical certifications preferred.
6d
Save
Mark Applied
Hide
Research Security Cybersecurity Specialist (5271C) The Office of Research Administration & Compliance #88458
Berkeley, California, United States
$112k-$163k/yr RemoteFull Time
University of California, Berkeley
University of California, Berkeley: Public research university dedicated to academic and research excellence.
3+ YOEBachelor's degree or equivalent experience, 3+ years of cybersecurity experience, and expertise assessing NIST frameworks, CMMC, FISMA, data security regulations, and research compliance.
NIST 800-171, NIST 800-53, CMMC, FISMA, NSPM-33, DFARS 252.204-7012, NIST 800-172, HIPAA, FERPA
2mo
Save
Mark Applied
Hide
Senior Cybersecurity Architect, Agentic SOC Modernization & AI-Enabled Security Operations
Chicago or Los Angeles or New York City or San Francisco or Seattle or Washington, D.C.
$194k-$262k/yr OnsiteFull Time
West Monroe
West Monroe: Business and technology consulting firm.
7+ YOE7+ years in security architecture/SOC modernization; experience with SIEM/SOAR, detection engineering, AI-enabled SOCs, platform modernization, and executive advisory; willingness to travel; must be eligible to work in the US without sponsorship.
Splunk, Microsoft Sentinel, Google Security Operations, Google SecOps, Chronicle SIEM, Chronicle SOAR, Palo Alto Cortex, ServiceNow SecOps, CrowdStrike, BigQuery, Google Cloud, ChatGPT, MITRE ATT&CK, YARA-L, Sigma, VirusTotal, Wiz, Prisma Cloud, Okta, SailPoint, Mandiant, EDR, XDR, IAM, PAM, DLP, ITSM, SIEM, SOAR
2mo
Save
Mark Applied
Hide
Applied AI Research Engineer
Boston or San Francisco or United States
HybridFull Time
Code Metal
Code Metal: AI software translating, verifying, and optimizing code for mission-critical industries deploying software on specialized hardware.
3+ YOEBachelor's or Master's in a technical field (or equivalent), 3+ years building AI/ML or applied research systems, strong Python and PyTorch skills, experience with LLM tooling, fine-tuning, retrieval, agentic systems, and experiment design; eligible to obtain U.S. security clearance.
Python, PyTorch, Transformers, vLLM, Hugging Face
2w
Save
Mark Applied
Hide
Senior Analyst
Cambridge or New York City or Washington or Atlanta or San Francisco
$119k-$193k/yr OnsiteFull Time
Forrester Research
Forrester ResearchNasdaq: FORR: Public research and advisory firm serving business and technology leaders with research, consulting, and events.
5+ YOERequires 5+ years of security and risk experience, BA/BS or equivalent, strong research, critical thinking, writing, presentation, and business skills; must be a US citizen and travel 30%-50%.
Managed Detection and Response (MDR), Managed Security Services (MSS), Zero Trust