Senior Security Researcher

  • R10678
  • United Kingdom

The Senior Security Researcher will drive vulnerability discovery and analysis within Rapid7’s Vulnerability Intelligence team. You’ll research zero-day and n-day threats, develop exploits, publish root cause analyses, and collaborate across teams to provide defenders with actionable insights.

About the Team

Rapid7’s Vulnerability Intelligence team leads industry research to uncover and prioritize risks for organizations worldwide. Our researchers discover and disclose zero-day vulnerabilities, analyze n-day threats, develop Metasploit modules, and identify patterns in emerging attack surfaces. Beyond driving coordinated responses to major incidents, the team provides actionable insights that help defenders stay ahead of evolving threats—proactively shaping understanding of today’s risks and tomorrow’s attack vectors.

About the Role

In this role, you will:

  • Work with the broader Vulnerability Intelligence team to support day-to-day research operations, including coordinated vulnerability disclosures and rapid responses to major security incidents (Note: there is no on-call requirement for this role).

  • Perform and publish root cause analyses of high-priority vulnerabilities and potential threats that highlight Rapid7’s attacker-focused approach to vulnerability intelligence.

  • Develop and publish new exploits and attack techniques, working alongside the Metasploit team to incorporate them into Metasploit Framework as needed. We believe strongly that defenders benefit from having democratic access to offensive security capabilities in order to understand attacks and test their controls!

  • Conduct zero-day vulnerability research against popular enterprise technologies (e.g., network appliances, VPN gateways, CI/CD servers, file transfer and backup solutions, etc).

  • Advise our security and threat detection engineers as they develop vulnerability checks, fingerprints, and detections; contextualize risk and explain attack patterns to cross-team technical stakeholders.

The skills you’ll bring include:

  • Hands-on experience with common vulnerability classes and exploitation techniques (e.g., command injection, deserialization, etc). We don't expect you to know everything, but you should be comfortable digging in to both learn and apply new or unfamiliar techniques when needed.

  • Experience producing vulnerability root cause analyses (or other technical writing on vulnerabilities and exploits).

  • Hands-on experience reverse engineering, patch diffing, and developing exploits. Prior experience developing Metasploit modules is a plus. Prior experience reverse engineering at least one common enterprise software development language (e.g. Java, .NET, C/C++) is also a plus.

  • Familiarity with common security research tooling (e.g., IDA, Ghidra, Binary Ninja, Burpsuite, etc).

  • An instinct for where and how to obtain or emulate vulnerable software. We can’t perform hands-on analysis without targets - sometimes we have lab targets, sometimes there are AMIs available, and sometimes we have to get creative.

  • Deep empathy for the challenges that security teams and global organizations face in today's threat climate; willingness to listen, mentor, and collaborate across teams.

  • Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. 

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

About Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. 

Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us. 

#LI-SIM #LI-Remote 

Security and Compliance
Rapid7 is committed to keeping customers secure. As a first line of defense, all employees are expected to uphold the highest standards of security and privacy, ensuring the protection of sensitive information and compliance with relevant regulations.

Apply Now

Not You?

Application loading...

Sign Up for Job Alerts

Finalize your job alert by selecting criteria from the dropdowns below. You can select multiple options from each dropdown by returning to the combobox and re-entering the list of options. Submit at the end to create your job alert.

Not You?

Thank you

Jobs you may be interested in

Associate Renewal Account Manager

Boston, MA, United States
*Rapid7 is a hybrid work environment. The expectation is three (3) days in the office, two (2) days remote. Our Boston office is located at North Station. About the role: We are seeking a proactive and results-driven Associate Renewal Account Ma...

Cybersecurity Advisor II

Prague, Czechia
Rapid7 Cybersecurity Advisors partner with customers on vulnerability management, application security, and threat detection and incident response. You will work with customers to increase their resilience against threats through tailored mitigati...

Senior Director of Engineering & Site Lead

Prague, Czechia
We are looking for an experienced leader to take on a unique and high-impact role: guiding our Threat Intelligence engineering teams while also serving as the Site Leader for our Prague office. In this position, you’ll have the opportunity to shap...

Talent Acquisition Partner

Pune, India
Talent Acquisition Partner  The Talent Acquisition Partner is a critical driver of Rapid7’s ability to attract and hire exceptional talent that fuels our business success. In this role, you will support our hiring teams in Pune. The right candida...

Apply Now

Not You?

Application loading...