Jobs · Information Technology

Security Researcher

Netwrix Corporation · United States · Yesterday
RemoteRemoteInformation TechnologyFull-time

Netwrix is seeking a Security Researcher with expertise in Active Directory and Entra ID to join our security research team. This role focuses on hands-on research into Active Directory and Entra ID security: finding misconfigurations, privilege escalation paths, and attack techniques. You'll build and validate proof-of-concept exploits, work closely with product teams, and grow your research and public speaking profile as part of the team.

Key Responsibilities

  • Conduct hands-on research into Active Directory, Windows and Entra ID, identifying misconfigurations, privilege escalation paths, and attack techniques.
  • Build and validate proof-of-concept exploits and testing methodologies to validate research findings.
  • Using AI tools to speed up research and prototyping (vibe coding a POC, automating repetitive analysis, etc.) is welcome and encouraged.
  • Work with engineering and product teams to help translate research into product improvements.
  • Contribute to the Netwrix Blog and Attack Catalog with technical write-ups of findings.
  • Contribute to our open source GitHub repository, including tools such as the free version of PingCastle.
  • Opportunity to co-present or present research at industry conferences (BlackHat, Defcon, RSA, etc.) as your experience grows.

Required Qualifications

  • 1 to 3 years of hands-on experience in security research, red teaming, penetration testing, or a closely related identity security role, with a focus on Active Directory, Entra ID, Windows, or related identity platforms.
  • Working knowledge of common AD/Entra ID misconfigurations, privilege escalation paths, and attack techniques, or a strong foundation and a track record of picking these up fast.
  • Strong problem-solving skills, with the ability to take an unfamiliar system or attack surface and break it down into testable hypotheses.
  • Comfortable using AI tools to speed up research work, whether that's automating repetitive analysis, scripting tooling, or quickly putting together a proof of concept.
  • Able to work cross-functionally with engineering and product teams.
  • Good verbal and written communication skills in English.
  • Able to proficiently use at least one programming or scripting language (C#, PowerShell, Python, etc.).

Preferred Qualifications

  • Some experience discovering or analyzing vulnerabilities, misconfigurations, or attack paths, whether in identity systems specifically or security research more broadly.
  • A tool, script, or side project you've built to solve a security problem, even a small one. We're interested in how you think, not just what you've published.
  • Interest in or early experience presenting technical work, whether that's internal talks, meetups, local conferences, or writing technical blog posts.
  • Familiarity with hybrid identity security concepts, including AD to Entra ID synchronization.
  • Understanding of authentication protocols (Kerberos, NTLM, OAuth, OpenID Connect) and directory replication mechanisms.
  • Prior contributions to open source security tooling.

Similar jobs

Security Researcher

Pi SecuritySan Francisco, CA· Today
Information Technologyapply on jobs.ashbyhq.com

Security Researcher

RecoWilmington, DE· 3 wk ago
RemoteInformation Technologyapply on comeet.com

Security Researcher

depthfirstSan Francisco, CA· 1 mo ago
Information Technologyapply on jobs.ashbyhq.com

Security Researcher

CorgeaSan Mateo, CA· 9 mo ago
Information Technologyapply on ycombinator.com

Security Researcher

CylakeSunnyvale, CA· 3 wk ago
Information Technology$150k–$250k/yrapply on jobs.ashbyhq.com