Cobalt

Cobalt

Cobalt modernizes traditional pentesting with a global talent pool and SaaS platform, delivering actionable results to pinpoint and remediate software vulnerabilities.

Internet Software & Services
251-1K
Founded 2013
$37M raised

Description

  • Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across web/API platforms, mobile operating systems, OS stacks, cloud infrastructure, and enterprise systems.
  • Identify high-impact vulnerabilities and develop proof-of-concept exploit techniques to validate real-world risk.
  • Research emerging threat vectors and help maintain testing guidelines across cloud, API, mobile, and AI/ML environments.
  • Collaborate with Product and Engineering to turn research findings into scalable assessment capabilities, automated workflows, and platform intelligence.
  • Partner with engineering, product, and operations teams to translate security research into customer value and platform improvements.
  • Provide technical guidance, benchmarking, mentorship, and quality assurance support to junior researchers and community members.
  • Represent Cobalt in the security community through technical blog posts, advisories, whitepapers, and conference presentations.
  • Document complex technical findings into clear remediation guidance for engineers, product teams, and executive stakeholders.

Requirements

  • 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering, or 3+ years with published research, CVEs, or open-source security tooling.
  • Demonstrated expertise in modern application stacks including Node.js, Go, Python, Java, and Rust.
  • Strong knowledge of operating system security fundamentals, including Linux, Windows, and macOS internals.
  • Experience with containerized cloud environments such as Docker, Kubernetes, AWS, and GCP.
  • Proven ability to analyze binary, source code, or bytecode and build reliable PoC exploits for complex vulnerability classes.
  • Strong proficiency in Python, Go, Bash, or Rust for building research tools, scripts, and testing utilities.
  • Ability to communicate technical findings clearly and create actionable remediation guidance.
  • Must be based in the United States; EST or CST alignment is preferred.
  • Familiarity with AI/ML security concepts and LLM risk models is preferred.
  • Hands-on experience with Ghidra, IDA Pro, Binary Ninja, GDB, or LLDB is preferred.
  • Published CVEs, security advisories, bug bounty recognition, or open-source security contributions are preferred.
  • Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist are preferred.

Benefits

  • Competitive compensation with an attractive equity plan.
  • US OTE salary range of $120,000 - $150,000 per year, plus equity and benefits.
  • 401(k) program in the US or pension in the EU.
  • Medical, dental, vision, and life insurance in the US, or statutory healthcare in the EU.
  • Wellness stipend.
  • Work-from-home equipment and Wi-Fi stipend.
  • Learning and development stipend.
  • Flexible, generous paid time off and paid parental leave.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Consultant - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring a Principal, Consultant to lead complex multi-discipline project delivery, provide technical leadership, and strengthen discipline standards and client relationships.

Agile Asana GitHub
5 hours, 10 minutes ago

Offensive Security Engineer

ClickHouse 51-250 IT Services

ClickHouse is hiring an experienced Security practitioner to strengthen the security posture of its cloud data platform, products, and services through offensive security, incident response, and security automation.

AWS Azure GCP Kubernetes Penetration Testing
2 days, 4 hours ago

Security Expert

Flix SE 1001-5000 Travel tech

Flix is hiring a Security Expert in the United States to lead North American security operations, manage external partners, and use data-driven risk analysis to strengthen safety and incident response.

2 days, 4 hours ago

ISO Senior Consultant

A-LIGN 251-1K Professional Services

A-LIGN is hiring an ISO Senior Consultant to execute ISO 27001 assessment, certification readiness, compliance, and advisory engagements for client information security programs.

Cybersecurity
2 days, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers