Vulnerability Researcher
Bug hunting at scale, fuzzing, CVE drops, conference talks if you're lucky.
Elite, niche, and almost impossible to enter without serious prior craft. Pick it as a long-term direction, not a job you can apply for next week.
- Domain
- Cybersecurity
- Entry
- £32–52k
- Senior
- £95–135k
- You've shipped public research, advisories or CVEs already
- You can read assembly and source in the same investigation
- You're prepared for months of work that may not produce a finding
- You're motivated by the work itself, the public credit is intermittent at best
- You've never reversed anything seriously outside coursework
- You need regular wins and external validation to stay motivated
- You expect bug bounty income to substitute for a salary, it usually won't
What "doing well" looks like in the seat
- Your findings are reproducible from your writeup alone
- Vendors take your disclosures seriously the first time
- You contribute to the toolchain other researchers use
- You can explain a vulnerability class clearly to a non-researcher
The market in the UK is tiny, the seats are usually offensive vendors, dedicated research teams or government, and the people who hold them tend to stay. Most who chase the role end up doing pentest with a side of research, which is honest work but not the same career. Decide whether you want the title or the practice, and be honest about which one you're actually chasing.
Tradeoffs at a glance
Hover any chip for the calibrated meaning. Ratings are directional, not absolute.
Promotion ceiling
High. Staff researcher comp at security product companies is excellent.
Who actually gets in
- +Pentester with depth
- +Malware analyst
- +Self-taught hacker
Common misconceptions
- −That bug bounty income is reliable, it isn't, for most.
Where this leads
- Offensive R&D
- Exploit Development
- Tooling Engineering
Certifications people pair with this
Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.
Pathways that pass through here
What this is based on
Practitioner judgement. External evidence review pending.
Last reviewed: not yet reviewed · UK market
The next step
You've read about the role. The harder question is whether it's the right one for you.
A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.
A route shows what is possible. A Career Verdict makes the call.
Career Verdict
Helpdesk → Security Architect
- 01The callA clear judgement on whether your route is realistic, and under what conditions.
- 02Where the route breaksThe most likely point to stall, and why it happens in practice.
- 03What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Career Verdict
- The callA single written judgement on whether the route is realistic for you.
- Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
- Where you standThe strongest and weakest parts of your current position, named.
- Salary realityWhat this route actually pays, set against what you've been told it pays.
Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.
Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.