Cobalt

Cobalt

Cobalt modernizes traditional pentesting with a global talent pool and SaaS platform, delivering actionable results to pinpoint and remediate software vulnerabilities.

Internet Software & Services
251-1K
Founded 2013
$37M raised

Description

  • Conduct deep-dive vulnerability research, reverse engineering, and threat analysis across web/API platforms, mobile operating systems, OS stacks, cloud infrastructure, and enterprise systems.
  • Identify high-impact vulnerabilities and develop proof-of-concept exploit techniques to validate real-world risk.
  • Research emerging threat vectors and help maintain testing guidelines across cloud, API, mobile, and AI/ML environments.
  • Collaborate with Product and Engineering to turn research findings into scalable assessment capabilities, automated workflows, and platform intelligence.
  • Partner with engineering, product, and operations teams to translate security research into customer value and platform improvements.
  • Provide technical guidance, benchmarking, mentorship, and quality assurance support to junior researchers and community members.
  • Represent Cobalt in the security community through technical blog posts, advisories, whitepapers, and conference presentations.
  • Document complex technical findings into clear remediation guidance for engineers, product teams, and executive stakeholders.

Requirements

  • 5+ years of dedicated experience in offensive security, vulnerability research, penetration testing, red teaming, or reverse engineering, or 3+ years with published research, CVEs, or open-source security tooling.
  • Demonstrated expertise in modern application stacks including Node.js, Go, Python, Java, and Rust.
  • Strong knowledge of operating system security fundamentals, including Linux, Windows, and macOS internals.
  • Experience with containerized cloud environments such as Docker, Kubernetes, AWS, and GCP.
  • Proven ability to analyze binary, source code, or bytecode and build reliable PoC exploits for complex vulnerability classes.
  • Strong proficiency in Python, Go, Bash, or Rust for building research tools, scripts, and testing utilities.
  • Ability to communicate technical findings clearly and create actionable remediation guidance.
  • Must be based in the United States; EST or CST alignment is preferred.
  • Familiarity with AI/ML security concepts and LLM risk models is preferred.
  • Hands-on experience with Ghidra, IDA Pro, Binary Ninja, GDB, or LLDB is preferred.
  • Published CVEs, security advisories, bug bounty recognition, or open-source security contributions are preferred.
  • Active certifications such as OSCP, OSEP, OSWE, OSEE, GXPN, or AWS Certified Security Specialist are preferred.

Benefits

  • Competitive compensation with an attractive equity plan.
  • US OTE salary range of $120,000 - $150,000 per year, plus equity and benefits.
  • 401(k) program in the US or pension in the EU.
  • Medical, dental, vision, and life insurance in the US, or statutory healthcare in the EU.
  • Wellness stipend.
  • Work-from-home equipment and Wi-Fi stipend.
  • Learning and development stipend.
  • Flexible, generous paid time off and paid parental leave.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Vendor Security & Standards Manager

Nebius 51-250 Internet Software & Services

Nebius is seeking a Vendor Security & Standards Manager to globally enforce security compliance across its external supply chain partners, including carriers, 3PLs, freight forwarders, guarding companies, and last-mile providers.

2 days ago

Research Security Consultant

Attain Partners 251-1K Media

Attain Partners is seeking a Research Security Officer to manage university research security and export controls compliance programs within a higher-education and research environment.

4 days, 1 hour ago

Global Safety and Security Lead, Workplace and Facilities

Gong 251-1K Internet Software & Services

Gong is hiring a Global Safety and Security Lead to build and run worldwide safety, security, and business continuity programs that keep employees and offices safe, compliant, and resilient as the company scales globally.

5 days ago

Red & Purple Team Operator

SIXGEN 51-250 Professional Services

SIXGEN is hiring a Senior Red & Purple Team Operator to independently run advanced offensive security assessments and collaborative detection-validation exercises for government and critical infrastructure clients.

Active Directory AWS Azure Cybersecurity Linux Penetration Testing
1 week ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers