Skip to main content
RoleCybersecurity

Vulnerability Researcher

Bug hunting at scale, fuzzing, CVE drops, conference talks if you're lucky.

POST verdict

Elite, niche, and almost impossible to enter without serious prior craft. Pick it as a long-term direction, not a job you can apply for next week.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You've shipped public research, advisories or CVEs already
  • You can read assembly and source in the same investigation
  • You're prepared for months of work that may not produce a finding
  • You're motivated by the work itself, the public credit is intermittent at best
Skip this if
  • You've never reversed anything seriously outside coursework
  • You need regular wins and external validation to stay motivated
  • You expect bug bounty income to substitute for a salary, it usually won't
  • Your findings are reproducible from your writeup alone
  • Vendors take your disclosures seriously the first time
  • You contribute to the toolchain other researchers use
  • You can explain a vulnerability class clearly to a non-researcher
The bit you're probably underestimating

The market in the UK is tiny, the seats are usually offensive vendors, dedicated research teams or government, and the people who hold them tend to stay. Most who chase the role end up doing pentest with a side of research, which is honest work but not the same career. Decide whether you want the title or the practice, and be honest about which one you're actually chasing.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

High. Staff researcher comp at security product companies is excellent.

  • +Pentester with depth
  • +Malware analyst
  • +Self-taught hacker
  • That bug bounty income is reliable, it isn't, for most.
  • Offensive R&D
  • Exploit Development
  • Tooling Engineering

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.