Sr. Cybersecurity Researcher, Cobalt Strike

fortra

United States

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Fortra is seeking a Senior Cybersecurity Researcher to join the Cobalt Strike team. This hands-on role focuses on understanding attacker tradecraft, OS internals, and defensive controls, turning research into practical product capabilities for authorized security teams.

You'll work with engineers across disciplines to prototype and validate techniques in lab environments, write clear analyses, and help shape the roadmap by identifying emerging threats and opportunities for safe adversary

Qualifications

  • Strong experience in cybersecurity research, offensive security, threat research, red teaming, or related discipline.
  • Deep curiosity about how adversaries operate and how security teams can safely emulate, detect, and respond to those behaviors.
  • Working knowledge of Windows internals.
  • Understanding common post-exploitation concepts, attacker tradecraft, and enterprise security controls.
  • Ability to analyze technical research, threat intelligence, proof-of-concept code, malware reports, or detection logic and translate findings into clear product recommendations.
  • Experience working in controlled lab environments to test techniques, validate assumptions, and reproduce technical behaviors.
  • Strong analytical reasoning, problem-solving, and decision-making skills.
  • Ability to write clear, accurate technical documentation for engineering, product, and customer-facing audiences.
  • Ability to work independently on ambiguous research problems while communicating progress, tradeoffs, and findings clearly.
  • Strong verbal and written communication skills.
  • High ethical standards and sound judgment, especially when working with offensive security technology.

Responsibilities

  • Research adversary tactics, techniques, and procedures focusing on post-exploitation tradecraft and attacker behavior.
  • Analyze security research, malware reports, PoC techniques, and security controls to identify opportunities for product improvements.
  • Collaborate with engineers, PMs, QA, and support to turn research into practical capabilities.
  • Prototype, document, and validate new techniques in controlled lab environments.
  • Evaluate how offensive techniques interact with Windows security features, endpoint controls, logging, and enterprise hardening.
  • Produce technical write-ups, design notes, research summaries, and recommendations.
  • Contribute to the roadmap by identifying trends and customer needs.
  • Communicate findings to technical and non-technical audiences via presentations, docs, blogs, webinars.

Skills

Cybersecurity research
Offensive security
Threat research
Red teaming
Penetration testing
Malware analysis
Reverse engineering
Detection engineering
Windows internals
Post-exploitation
Analytical thinking
Technical writing
Independent work
Communication skills

Tools

WinDbg
x64dbg
Ghidra
IDA Pro
Process Monitor
Process Explorer
Sysmon
ETW

Job description

Whether you're an experienced professional or just getting started, your contributions matter at Fortra. If you're passionate about tackling meaningful challenges alongside talented team members committed to helping each other succeed, all while having lots of fun, we want to hear from you. We offer competitive benefits and salaries, personal and professional development opportunities, flexibility, and much more!

Cobalt Strike is Fortra's adversary simulation and red team operations platform, used by security teams to emulate advanced threat actor behaviors in controlled, authorized environments. The product helps organizations strengthen security operations and incident response by enabling realistic attack simulation, post-exploitation tradecraft, and collaborative red team engagements.

We are looking for a Senior Cybersecurity Researcher to join the Cobalt Strike team. This is a hands-on applied R&D role focused on understanding modern attacker tradecraft, operating system internals, offensive security techniques, and defensive controls, then turning that research into practical product capabilities. You should be curious about how attacks work under the hood and excited to collaborate with engineers to design, validate, and deliver bleeding-edge Cobalt Strike features that are safe, responsible, and useful to authorized security teams.

WHAT YOU'LL DO
  • Research modern adversary tactics, techniques, and procedures, with a focus on post-exploitation tradecraft, endpoint defenses, and attacker behavior.
  • Analyze security research, malware reports, proof-of-concept techniques, and developments in security controls to identify opportunities for Cobalt Strike product improvements.
  • Work closely with software engineers, product managers, QA, support, and other researchers to turn research findings into practical, maintainable product capabilities.
  • Prototype, document, and validate new techniques or product ideas in controlled, authorized lab environments.
  • Help evaluate how offensive security techniques interact with modern Windows security features, endpoint controls, logging, detection engineering, and enterprise hardening practices.
  • Produce clear technical write-ups, design notes, research summaries, and recommendations for engineering and product teams.
  • Contribute to the Cobalt Strike roadmap by identifying emerging trends, customer needs, technical gaps, and opportunities for responsible adversary simulation.
  • Collaborate with engineering teams during design discussions, implementation planning, testing, and validation.
  • Communicate research findings to technical and non-technical audiences through internal and external presentations, documentation, blog posts, white papers, webinars, or conference-style talks.
  • Participate in team planning, roadmap discussions, research reviews, and cross-functional technical discussions.
QUALIFICATIONS
  • Strong experience in cybersecurity research, offensive security, threat research, red teaming, penetration testing, malware analysis, reverse engineering, detection engineering, or related discipline.
  • Deep curiosity about how adversaries operate and how security teams can safely emulate, detect, and respond to those behaviors.
  • Working knowledge of Windows internals
  • Understanding common post-exploitation concepts, attacker tradecraft, and enterprise security controls.
  • Ability to analyze technical research, threat intelligence, proof-of-concept code, malware reports, or detection logic and translate findings into clear product recommendations.
  • Experience working in controlled lab environments to test techniques, validate assumptions, and reproduce technical behaviors.
  • Strong analytical reasoning, problem-solving, and decision-making skills.
  • Ability to write clear, accurate technical documentation for engineering, product, and customer-facing audiences.
  • Ability to work independently on ambiguous research problems while communicating progress, tradeoffs, and findings clearly.
  • Strong verbal and written communication skills.
  • High ethical standards and sound judgment, especially when working with offensive security technology.
PREFERRED QUALIFICATIONS
  • Experience using or developing with Cobalt Strike, or experience with similar adversary simulation, red team, command-and-control, or threat emulation tools.
  • Experience with Windows debugging, reverse engineering, or analysis tools such as WinDbg, x64dbg, Ghidra, IDA Pro, Process Monitor, Process Explorer, Sysmon, ETW, or similar tools.
  • Experience with scripting or programming languages such as Python, PowerShell, C, Java, Go, Rust, or similar.
  • Experience applying AI/ML tools, including LLMs or agent-based workflows, to automate, accelerate, or augment security research, reverse engineering, detection analysis, or threat emulation workflows.
  • Experience analyzing malware, loaders, implants, shellcode, process injection techniques, evasion techniques, persistence mechanisms, credential access techniques, or lateral movement behaviors in
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Researcher — Adversary Emulation
Senior Cybersecurity Researcher — Adversary Emulation

fortra • United States

On-site
USD 120,000 - 180,000
Offensive Security Training Content Developer
Offensive Security Training Content Developer

Fortra • United States

On-site
USD 115,000 - 140,000
Health, dental, and vision coverage
401(k) enrollment
HSA and FSA plans
+4
Offensive Security Training Content Developer
Offensive Security Training Content Developer

Fortra • Northern (KY)

Hybrid
USD 115,000 - 140,000
Health, dental, and vision coverage
401(k), HSA, and FSA plans
Flexible PTO
Security Researcher - Offensive Security
Security Researcher - Offensive Security

GhostEye • New York (NY)

On-site
USD 180,000 - 260,000
X-Day Offensive Research (XOR) Vulnerability Researcher
X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 150,000 - 230,000
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic • United States

On-site
USD 140,000 - 200,000
Cyber Security Analyst
Cyber Security Analyst

Trinity Cyber • Washington

On-site
USD 120,000 - 160,000
Sr. Security Researcher (Remote).
Sr. Security Researcher (Remote).

CrowdStrike • Utah

On-site
USD 85,000 - 120,000
Market-leading compensation
Wellness programs
Generous vacation & holidays
+4
Sr. Staff Security Researcher (PhD)
Sr. Staff Security Researcher (PhD)

RippleMatch Inc. • Santa Clara (CA)

On-site
USD 185,000 - 285,000
Sr. Security Researcher (Remote).
Sr. Security Researcher (Remote).

CrowdStrike • Colorado

On-site
USD 85,000 - 120,000
Market-leading compensation
Wellness programs
Generous vacation and holidays
+3