Contrast Security is looking for a Sr Application Security Researcher to conduct vulnerability and threat research that directly impacts the world's software ecosystem. You will maintain our security intelligence platform and collaborate closely with product and engineering teams to solve complex application security problems for our runtime products.
What You'll Do
- Conduct basic and applied research on important and challenging problems in application security to creatively improve and innovate runtime products.
- Help define and drive research projects, either on your own or in collaboration with others on the team.
- Engage with Contrast’s product teams and customers to promote and seek out new research initiatives.
- Support the gathering of language, library, license, and application security research.
- Process emerging threats, such as evaluating externally found CVEs and risks.
- Develop and present content associated with security research through conference speaking and/or blogging.
- Provide tier-3 support for reported incidents and escalation of security findings review.
- Provide mentorship and direction to the team.
What We're Looking For
- A software background in Java and .NET.
- Ability to develop purposefully vulnerable applications and exploit them.
- Understanding of the OWASP Top 10 and SANS/CWE Top 25.
- Experience with ethical hacking and vulnerability management reporting.
- Knowledge of cloud hosting environments like AWS, Azure, GCP, and OCI.
- Strong communication skills.
- You ask questions, let others know when you need help, and tell others what you need.
- 5+ years of experience in industry application security research, pen-testing, consulting, or direct application.
- You have a hacker’s curiosity blended with an engineer’s problem-solving.
Nice to Have
- Experience with NodeJS, Python, and Ruby.
Technical Stack
- Languages: Java, .NET, NodeJS, Python, Ruby
- Cloud: AWS, Azure, GCP, OCI
Team & Environment
You will join the Application Security Research team at Contrast Security. We are passionate about building smarter, faster, more effective security. We look for sharp minds, fearless builders, and problem-solvers who thrive on turning complex challenges into innovative solutions in a fast-paced environment.





