Senior Security Research Engineer
Job role insights
-
Date posted
May 26, 2026
-
Closing date
June 23, 2026
-
Offered salary
$70,000 - $170,000/year
-
Career level
Middle Senior
Description
Company: Automattic
Job Category: Cybersecurity / Security Research
Contract Type: Full-Time, Permanent
Location Eligibility: Remote — Worldwide
Salary: $70,000 – $170,000 USD/year (pay reflects skills and experience; global pay in local currency)
Application Link: https://job-boards.greenhouse.io/automatticcareers/jobs/7847202
Application Email: N/A Closing Date: Open until filled
About the Company: Automattic is the company behind WordPress.com, WooCommerce, Tumblr, Jetpack, Beeper, Pocket Casts, Day One, and more. With 1,500+ employees (called Automatticians) distributed across the globe, they believe in open source and in making the web a better place. Fully remote with open vacation policy.
Job Description: WP Cloud powers WordPress at scale and Automattic is expanding its security team. As a Senior Security Research Engineer, you will analyze vulnerable and malicious code, track emerging threats, and build tools and processes that detect, prevent, and remediate malware and other security issues across the WordPress ecosystem.
Key Responsibilities:
- Analyze vulnerable and malicious PHP code across the WordPress ecosystem
- Track emerging threats and help build automated detection and remediation tooling
- Contribute to WPScan and Jetpack Protect security intelligence
- Participate in code reviews and architecture discussions
- Use AI tools effectively to accelerate analysis and improve quality
Requirements:
- At least 3 years of experience as a security researcher, or equivalent experience investigating vulnerabilities, malware, or threats
- Familiarity with threat models, XSS, injection, hijacking, social engineering, and their mitigations
- Experience with PHP and exposure to software engineering
- Highly collaborative; comfortable with code reviews and architectural discussions
- Ability to incorporate AI tools into security research workflows
- Willingness to travel 2–3 weeks per year for in-person team meetups
Nice to Have: Experience with penetration testing, malware detection systems, past vulnerability disclosures, WordPress file/database structure knowledge
Skills Required: PHP, security research, vulnerability analysis, malware detection, threat intelligence, AI tooling, WordPress
Benefits: Open vacation policy, fully distributed work environment, personal development budget, competitive pay
Interested in this job?
25 days left to apply