Senior Security Researcher
17 hours ago
The Senior Security Researcher will drive vulnerability discovery and analysis within Rapid7's Vulnerability Intelligence team. You'll research zero-day and n-day threats, develop exploits, publish root cause analyses, and collaborate across teams to provide defenders with actionable insights.
About the Team
Rapid7's Vulnerability Intelligence team leads industry research to uncover and prioritize risks for organizations worldwide. Our researchers discover and disclose zero-day vulnerabilities, analyze n-day threats, develop Metasploit modules, and identify patterns in emerging attack surfaces. Beyond driving coordinated responses to major incidents, the team provides actionable insights that help defenders stay ahead of evolving threats—proactively shaping understanding of today's risks and tomorrow's attack vectors.
About the Role
In this role, you will:
Work with the broader Vulnerability Intelligence team to support day-to-day research operations, including coordinated vulnerability disclosures and rapid responses to major security incidents (Note: there is no on-call requirement for this role).
Perform and publish root cause analyses of high-priority vulnerabilities and potential threats that highlight Rapid7's attacker-focused approach to vulnerability intelligence.
Develop and publish new exploits and attack techniques, working alongside the Metasploit team to incorporate them into Metasploit Framework as needed. We believe strongly that defenders benefit from having democratic access to offensive security capabilities in order to understand attacks and test their controls
Conduct zero-day vulnerability research against popular enterprise technologies (e.g., network appliances, VPN gateways, CI/CD servers, file transfer and backup solutions, etc).
Advise our security and threat detection engineers as they develop vulnerability checks, fingerprints, and detections; contextualize risk and explain attack patterns to cross-team technical stakeholders.
The skills you'll bring include:
Hands-on experience with common vulnerability classes and exploitation techniques (e.g., command injection, deserialization, etc). We don't expect you to know everything, but you should be comfortable digging in to both learn and apply new or unfamiliar techniques when needed.
Experience producing vulnerability root cause analyses (or other technical writing on vulnerabilities and exploits).
Hands-on experience reverse engineering, patch diffing, and developing exploits. Prior experience developing Metasploit modules is a plus. Prior experience reverse engineering at least one common enterprise software development language (e.g. Java, .NET, C/C++) is also a plus.
Familiarity with common security research tooling (e.g., IDA, Ghidra, Binary Ninja, Burpsuite, etc).
An instinct for where and how to obtain or emulate vulnerable software. We can't perform hands-on analysis without targets - sometimes we have lab targets, sometimes there are AMIs available, and sometimes we have to get creative.
Deep empathy for the challenges that security teams and global organizations face in today's threat climate; willingness to listen, mentor, and collaborate across teams.
Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-SIM #LI-Remote
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
-
Senior Security Researcher
5 days ago
United Kingdom Rapid7 Full timeThe Senior Security Researcher will drive vulnerability discovery and analysis within Rapid7’s Vulnerability Intelligence team. You’ll research zero-day and n-day threats, develop exploits, publish root cause analyses, and collaborate across teams to provide defenders with actionable insights. About The Team Rapid7’s Vulnerability Intelligence team...
-
Senior Security Research Architect
2 weeks ago
United Kingdom NVIDIA Full timeNVIDIA is a leader in accelerated computing, driving innovation across industries with groundbreaking technologies in AI, graphics, and high-performance computing. Our networking products, including InfiniBand and Ethernet solutions, power some of the world’s largest data centers, enabling unparalleled scalability and efficiency for AI and scientific...
-
Senior UX Researcher
2 weeks ago
Remote, United Kingdom Consortia Full timeAre you looking for a role of Senior UX Researcher, where you will be working on a SaaS product, for a fast growing scale up that has recently received incredible funding? Consortia is looking for a Senior UX Researcher with experience in quantitative research. You will be working with our client within the IT tech space, they have millions of users of...
-
Appsec Researcher
1 week ago
Remote, United Kingdom Checkmarx Full timeIf you are as passionate about AppSec as we are, we invite you to be part of the AppSec Research Group in Checkmarx, a leading company in the field of Application Security Testing. As an Application Security Researcher, you will be a part of the Checkmarx Application Security Research Group. You will be researching different languages, technologies, and...
-
Senior Security Research Engineer
2 days ago
Bristol, Avon, United Kingdom Hewlett Packard Enterprise Full timeSenior Security Research EngineerThis role has been designed as ''Onsite' with an expectation that you will primarily work from an HPE office Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live,...
-
Senior Research Impact Officer
4 days ago
Remote, United Kingdom Prostate Cancer UK Full time**Region** Home based - UK-wide **Vacancy Type** Permanent/Full Time **Job Summary** **Senior Research Impact Officer** **£33,000 to £35,500 per annum** **Permanent, full-time (37.5 hours per week)** **Hybrid working with regular travel to our London Bridge Office; occasional UK regional travel** **What the job involves** Funding research that will...
-
Principal Security Researcher
7 days ago
United Kingdom GitHub Full timeAbout GitHub GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot. Locations In this role you can...
-
Senior Game User Researcher
7 hours ago
Remote, United Kingdom Skillsearch Limited Full timeSenior Game User Researcher - 13335 If you are enthusiastic about user research and the game industry and are looking for your next career move, Skillsearch has an exciting opportunity for you. We are recruiting a full-time Senior Game User Researcher in Singapore to conduct and supervise user research for at least one game title in collaboration with...
-
Knowledge Management Senior Researcher
2 weeks ago
Remote, United Kingdom Irwin Mitchell Full time**3766** We’re a national law firm with a local reach. Our philosophy is ‘Expert Hand, Human Touch’ - something you’ll find in the way we work with our clients and how we support our teams. But, we’re more than just a law firm - we’re a team, working together to help individuals and businesses navigate life’s ups and downs. Whichever team you...
-
Senior Researcher
5 days ago
United Kingdom Rapid7 Full timeThe Senior Security Researcher will drive vulnerability discovery and analysis within Rapid7’s Vulnerability Intelligence team. You’ll research zero-day and n-day threats, develop exploits, publish root cause analyses, and collaborate across teams to provide defenders with actionable insights. Rapid7’s Vulnerability Intelligence team leads industry...