Senior Security Researcher
As a Senior Security Researcher for the Axonius Exposures team, you will conduct research into vulnerability detection, remediation, and prioritization to enhance our asset intelligence platform. You will lead end-to-end research projects, collaborating directly with Product and Development teams to convert technical research into product features. You will analyze large-scale security data, automate workflows, and prototype logic to address enterprise attack surfaces. This is a high-impact role where your research directly shapes how our customers identify and mitigate their most critical security gaps.
Responsibilities
Lead end-to-end security research projects focusing on vulnerability detection, risk prioritization, and exposure management logic.
Utilize Python, SQL, and AI/LLM tools to build data analysis pipelines, automate threat research, and prototype research tools.
Research and define remediation strategies, compensating controls, and configuration-based mitigations beyond standard patching.
Partner weekly with Product and Engineering teams to transform technical research into production-ready product capabilities.
Minimum Qualifications
4+ years of professional experience in security research, vulnerability analysis, or penetration testing.
Demonstrated proficiency with Python for scripting/automation and SQL for querying complex security data sets.
Hands-on experience integrating AI/LLMs into technical workflows to accelerate data analysis, parsing, or research output.
Practical understanding of security frameworks and metrics including CVSS, EPSS, and MITRE ATT&CK.
Preferred Qualifications
Prior experience in B2B SaaS or enterprise cybersecurity product environments.
Experience in exposure management, attack surface management (ASM), or enterprise risk prioritization.
Experience creating custom prioritization and scoring algorithms combining vulnerability telemetry with asset criticality.
Deep knowledge of non-patching mitigation strategies, including registry tweaks, network policy shifts, and configuration hardening.
Proven track record of framing open-ended security problems into scalable software feature requirements.
#LI-HYBRID, #LI-ZR1