Sr. Cybersecurity Researcher, Cobalt Strike

Fortra

España

Presencial

EUR 60.000 - 90.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Fortra is seeking a Senior Cybersecurity Researcher to join the Cobalt Strike team. This hands-on R&D role focuses on attacker tradecraft, Windows internals, and offensive security, turning findings into practical product capabilities for authorized security teams.

You will research adversary tactics, collaborate with engineers, prototype new techniques in lab environments, document results, and contribute to the product roadmap, ensuring safe, responsible, and effective threat emulation.

Formación

  • Extensive experience in cybersecurity research and offensive security.
  • Working knowledge of Windows internals and attacker tradecraft.
  • Ability to translate research into practical product features for security teams.
  • Experience with malware analysis, reverse engineering, or red teaming.
  • Strong written and verbal communication skills.

Responsabilidades

  • Research adversary tactics and post-exploitation tradecraft for product improvements.
  • Analyze security research, malware reports, and PoC techniques for enhancements.
  • Collaborate with engineers, PMs, QA, and researchers to implement findings.
  • Prototype and validate new techniques in controlled lab environments.
  • Document results and recommendations for engineering and product teams.
  • Contribute to the product roadmap by identifying trends and needs.
  • Communicate research outcomes through technical content and talks.
  • Participate in planning, reviews, and cross-functional discussions.

Conocimientos

Cybersecurity research
Offensive security
Threat research
Red teaming
Penetration testing
Malware analysis
Reverse engineering
Detection engineering
Technical writing
Independent work

Herramientas

WinDbg
x64dbg
Ghidra
IDA Pro
Process Monitor
Process Explorer
Sysmon

Descripción del empleo

Whether you're an experienced professional or just getting started, your contributions matter at Fortra. If you're passionate about tackling meaningful challenges alongside talented team members committed to helping each other succeed, all while having lots of fun, we want to hear from you. We offer competitive benefits and salaries, personal and professional development opportunities, flexibility, and much more!

Cobalt Strike is Fortra’s adversary simulation and red team operations platform, used by security teams to emulate advanced threat actor behaviors in controlled, authorized environments. The product helps organizations strengthen security operations and incident response by enabling realistic attack simulation, post-exploitation tradecraft, and collaborative red team engagements.

We are looking for a Senior Cybersecurity Researcher to join the Cobalt Strike team. This is a hands‑on applied R&D role focused on understanding modern attacker tradecraft, operating system internals, offensive security techniques, and defensive controls, then turning that research into practical product capabilities. You should be curious about how attacks work under the hood and excited to collaborate with engineers to design, validate, and deliver bleeding‑edge Cobalt Strike features that are safe, responsible, and useful to authorized security teams.

What You'll Do
  • Research modern adversary tactics, techniques, and procedures, with a focus on post‑exploitation tradecraft, endpoint defenses, and attacker behavior.
  • Analyze security research, malware reports, proof‑of‑concept techniques, and developments in security controls to identify opportunities for Cobalt Strike product improvements.
  • Work closely with software engineers, product managers, QA, support, and other researchers to turn research findings into practical, maintainable product capabilities.
  • Prototype, document, and validate new techniques or product ideas in controlled, authorized lab environments.
  • Help evaluate how offensive security techniques interact with modern Windows security features, endpoint controls, logging, detection engineering, and enterprise hardening practices.
  • Produce clear technical write‑ups, design notes, research summaries, and recommendations for engineering and product teams.
  • Contribute to the Cobalt Strike roadmap by identifying emerging trends, customer needs, technical gaps, and opportunities for responsible adversary simulation.
  • Collaborate with engineering teams during design discussions, implementation planning, testing, and validation.
  • Communicate research findings to technical and non‑technical audiences through internal and external presentations, documentation, blog posts, white papers, webinars, or conference‑style talks.
  • Participate in team planning, roadmap discussions, research reviews, and cross‑functional technical discussions.
Qualifications
  • Strong experience in cybersecurity research, offensive security, threat research, red teaming, penetration testing, malware analysis, reverse engineering, detection engineering, or related discipline.
  • Deep curiosity about how adversaries operate and how security teams can safely emulate, detect, and respond to those behaviors.
  • Working knowledge of Windows internals
  • Understanding common post‑exploitation concepts, attacker tradecraft, and enterprise security controls.
  • Ability to analyze technical research, threat intelligence, proof‑of‑concept code, malware reports, or detection logic and translate findings into clear product recommendations.
  • Experience working in controlled lab environments to test techniques, validate assumptions, and reproduce technical behaviors.
  • Strong analytical reasoning, problem‑solving, and decision‑making skills.
  • Ability to write clear, accurate technical documentation for engineering, product, and customer‑facing audiences.
  • Ability to work independently on ambiguous research problems while communicating progress, tradeoffs, and findings clearly.
  • Strong verbal and written communication skills.
  • High ethical standards and sound judgment, especially when working with offensive security technology.
Preferred Qualifications
  • Experience using or developing with Cobalt Strike, or experience with similar adversary simulation, red team, command‑and‑control, or threat emulation tools.
  • Experience with Windows debugging, reverse engineering, or analysis tools such as WinDbg, x64dbg, Ghidra, IDA Pro, Process Monitor, Process Explorer, Sysmon, ETW, or similar tools.
  • Experience with scripting or programming languages such as Python, PowerShell, C, Java, Go, Rust, or similar.
  • Experience applying AI/ML tools, including LLMs or agent‑based workflows, to automate, accelerate, or augment security research, reverse engineering, detection analysis, or threat emulation workflows.
  • Experience analyzing malware, loaders, implants, shellcode, process injection techniques, evasion techniques, persistence mechanisms, credential access techniques, or lateral movement behaviors in authorized research contexts.
  • Experience with endpoint detection and response products
  • Experience producing public‑facing security research, conference talks, technical blogs, whitepapers, webinars, or customer‑facing technical content, with personal write‑ups, public talks, publications, or other verifiable contributions.
  • Background in military, government, or public‑sector cyber operations, with an established professional network in those communities.

At Fortra, we're breaking the attack chain. Ready to join us? Visit our website to learn more about why employees choose to work for Fortra. Remember to connect with us on LinkedIn.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, veteran or disability status.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Cybersecurity Researcher - Adversary Emulation & R&D
Senior Cybersecurity Researcher - Adversary Emulation & R&D

Fortra • España

Presencial
EUR 60.000 - 90.000
Global Security - Red Team Operator - X-Force Red
Global Security - Red Team Operator - X-Force Red

IBM • Barcelona

Presencial
EUR 90.000 - 130.000
Cybersecurity Specialist
Cybersecurity Specialist

Randstad España • Madrid

Presencial
EUR 60.000 - 95.000
Remote Security Software Engineer — Build Next-Gen Defenses
Remote Security Software Engineer — Build Next-Gen Defenses

Internetwork Expert • Madrid

A distancia
EUR 60.000 - 80.000
Flexible working hours
Inspiring team of colleagues worldwide
Modern development workflows
+1
Cyber Security Specialist - Red Team
Cyber Security Specialist - Red Team

HBX Group • Valencia

Presencial
EUR 90.000 - 130.000
Sr. Manager, Data Science (Remote, GBR)
Sr. Manager, Data Science (Remote, GBR)

CrowdStrike • España

Presencial
EUR 140.000 - 190.000
Competitive compensation
Wellness programs
Generous vacation
+4
Remote Enterprise Account Executive - Cybersecurity (Spain)
Remote Enterprise Account Executive - Cybersecurity (Spain)

Nextron Systems • España

A distancia
EUR 60.000 - 98.000
Annual learning budget
Uncapped commission
Flexible work environment
+1
Application Security Engineer (relocation to Barcelona)
Application Security Engineer (relocation to Barcelona)

Commit • Barcelona

Presencial
EUR 65.000 - 100.000
Cybersecurity Engineer for Edge Network Security
Cybersecurity Engineer for Edge Network Security

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 90.000
Lead IT Security AI-Redteamer
Lead IT Security AI-Redteamer

Dkbcodefactory • España

Presencial
EUR 90.000 - 150.000
Benefits package