Simplify Logo
Tenable

Tenable

Vulnerability management for IT and OT

Senior Research Engineer

Full-Time
€79.5k - €106.2k/yr

+ Bonus

Mid
Bachelor's
Dublin, Ireland
Hybrid

The posting is tagged hybrid; specific required office days are not stated.

About the job

Requirements
  • Demonstrably strong programming skills in one or more languages, specifically C and/or Python.
  • Ability and experience in showcasing original research externally through blogs, white papers, or similar publications.
  • Experience working with multiple operating systems, with proficiency in Linux required.
  • A B.S. degree in Computer Science or a related field, or equivalent work experience.
  • At least 3–5 years of development or research and development experience.
  • Ability to work independently as a researcher and as part of a larger team.
Responsibilities
  • Work on complex research and development initiatives.
  • Implement advanced detection logic while minimizing false positives and false negatives.
  • Participate in detection logic discussions and research new methods for detection.
  • Interface with stakeholders to externalize research outcomes.
  • Keep abreast of advancements and developments in the security industry and perform original research to keep customers secure.
  • Develop detection scripts for Tenable sensors, including the Nessus vulnerability scanner, based on research findings.
  • Research and develop detection methods for additional services and products from different vendors.
  • Help and train other researchers when needed.
Desired Qualifications
  • Solid understanding of networking and the TCP/IP stack.
  • In-depth understanding of common security vulnerabilities, CVSS scoring, vulnerability classification, detection techniques, and exploitation techniques.
  • In-depth protocol analysis and interaction, with expert-level knowledge of common protocols such as HTTP, DNS, SSH, and SMB.
  • Experience with penetration testing, researching, discovering, or publishing vulnerabilities.
  • One or more security-related certifications, such as OSCP.
  • Experience with systems administration and comfort working at the command line.
  • Exposure to continuous integration and continuous delivery pipeline technologies and concepts.
  • Proficiency with SQL and Snowflake.
  • Experience rigorously testing software.
  • Experience developing tools and test plans for complicated software.
  • Experience with Tenable products such as Nessus, Tenable.io, and Security Center.

About the company

Tenable specializes in vulnerability management for IT and OT environments. Its products include Nessus for vulnerability scanning, Tenable.io a cloud-based platform that inventory assets and prioritize risks, and Tenable.ot which protects industrial control systems and other operational technology. The company operates on a subscription model with additional services like professional support and PCI ASV compliance to help customers manage cyber risk. Its goal is to help organizations identify, investigate, and remediate vulnerabilities to reduce cyber risk across diverse environments.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Columbia, Maryland

Founded

2002

Get referred to Tenable

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue hit $268.5 million, and management raised full-year guidance.
  • Tenable One drove half of new sales in Q2 2026, signaling platform adoption.
  • September 2026 OpenAI collaboration and GISEC 2026 demos expand Tenable's AI-security narrative.

What critics are saying

  • CrowdStrike, Palo Alto Networks, and Microsoft compress Tenable pricing in vulnerability management.
  • Tenable issued $725 million convertible notes on September 10, 2026, inviting dilution and leverage.
  • If AI security stalls, Tenable One commoditizes and growth reverts to low-single digits by 2027.

What makes Tenable unique

  • Nessus and Tenable One anchor a broad exposure-management install base across 40,000 customers.
  • Tenable.ot covers operational technology, a harder niche than standard IT vulnerability management.
  • September 2026 OpenAI partnership extends Tenable into AI-agent inspection before deployment.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Employee Stock Purchase Plan

Flexible Work Hours

Paid Vacation

Paid Holidays

Parental Leave

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Business Wire
Sep 15th, 2026
Elite Roster of Cybersecurity Investors Backs Lineaje to Deliver Industry-first Supply Chain Security Solution

Lineaje has closed a $7 million seed funding round as it announces SBBOM360, a first-of-a-kind software supply chain management solution.

MarketScreener
Sep 11th, 2026
Tenable prices upsized $725M convertible notes offering to repay debt and buy back shares

Tenable Holdings announced the pricing of $725 million in convertible senior notes due 2031, up from the initially planned $650 million. The cybersecurity company's notes carry a 0.25% interest rate and are convertible at $44.84 per share, representing a 40% premium over its $32.03 stock price on 10 September 2026. The offering includes an option for initial purchasers to buy an additional $75 million in notes. Tenable expects net proceeds of approximately $705.6 million, which it plans to use for capped call transactions costing $58.1 million, repurchasing $170.5 million of its common stock, repaying term loans under its credit facility, and general corporate purposes. The sale is expected to close on 15 September 2026. The notes mature on 15 September 2031, unless converted, redeemed, or repurchased earlier.

CXO Insight Middle East
Sep 10th, 2026
GISEC 2026: Tenable to highlight Agentic AI-driven exposure management.

GISEC 2026: Tenable to highlight Agentic AI-driven exposure management. At the event, Tenable will showcase its Tenable One Exposure Management Platform. Tenable announced its participation at GISEC Global 2026, taking place at the Dubai Exhibition Centre (DEC), Expo City Dubai from 16-18 September. At the event, Tenable will showcase its Tenable One Exposure Management Platform, which unifies visibility across an organisation's entire attack surface. Building on this foundation, the company will highlight how its AI capabilities, including Hexa AI and AI Exposure, help close critical security gaps before attackers can exploit them. As organisations across the Middle East continue their digital transformation journey and integrate generative AI into enterprise operations, security teams are facing an influx of expanding attack surfaces and rapid threat cycles. At GISEC Global 2026, Tenable will demonstrate how these AI capabilities bridge the gap between exposure discovery and automated remediation. "AI and cloud adoption are moving faster across the Middle East than most organisations' security controls can keep pace with," said Maher Jadallah, Vice President, Middle East and Africa at Tenable. "Attackers are already using AI to find vulnerabilities faster than defenders can patch them. As initiatives like the UAE National Cybersecurity Strategy push organisations toward more resilient infrastructure, security teams need a clear, prioritised view of where they're exposed, not another disconnected tool." Visitors to GISEC can schedule briefings with Tenable security experts and experience live demonstrations of the Tenable One platform, including Tenable Hexa AI and AI Exposure, throughout the event at booth number H7-B130 in Hall 7. Tenable One brings together two distinct AI capabilities. Tenable AI Exposure helps organisations discover, assess and secure how AI is being used across their environments. Tenable Hexa AI is the platform's agentic engine, using AI to coordinate agents, automate security tasks and accelerate remediation. Put simply, AI Exposure helps organisations secure their use of AI, while Hexa helps them use AI to improve security operations. Together, they advance Tenable's preemptive security strategy by helping organisations reduce AI-related risk and act on cyber exposure more efficiently.

TechDay
Sep 8th, 2026
Tenable & OpenAI launch AI inspector for cyber agents.

Tenable & OpenAI launch AI inspector for cyber agents. Tue, 8th Sep 2026 (Today) Tenable is working with OpenAI to launch CyberAgents Exchange AI Inspector, a review process intended to assess AI agents and related components before deployment. The move reflects a joint effort by the cybersecurity company and OpenAI as businesses increase their use of agentic AI tools in enterprise environments. CyberAgents Exchange AI Inspector is designed to review AI agents, skills, MCP servers and multi-agent playbooks listed on the CyberAgents Exchange, operated by Tenable. The process combines OpenAI GPT cyber models, inspection through Tenable One AI Exposure and review by Tenable researchers. The aim is to help security teams identify and prioritise risks before community-built AI components are introduced into corporate systems. Tenable framed the initiative as a response to a growing market for shared AI tools built for cyber defence use cases. The collaboration grew out of Tenable's involvement in the OpenAI Daybreak Defence Network, a programme that brings cybersecurity companies into OpenAI's ecosystem. CyberAgents Exchange AI Inspector is expected to become available in September. The exchange The CyberAgents Exchange launched as an open-source registry focused on cybersecurity applications for AI agents and related tools. It now contains more than 100 community-submitted AI components following a recent SWARM build event hosted by Tenable. That growth points to a broader shift in the security market, as vendors and practitioner communities experiment with AI systems that can carry out multi-step tasks, connect to external services and coordinate with other agents. For security teams, the challenge is that such tools can also introduce new risks through software flaws, unsafe permissions, data handling issues or weak oversight. By introducing a formal inspection process, Tenable is seeking to add more structure to how those components are assessed before use. Its existing AI exposure technology is intended to support that process by examining risks associated with AI systems and their surrounding infrastructure. Security concerns The announcement comes as companies face pressure to adopt generative and agent-based AI while also addressing concerns from security and governance teams. In practice, that has created demand for products and review methods that can test not only models, but also the tools, workflows and connectors built around them. MCP servers, one of the component types covered by the new process, connect AI systems with outside resources and applications. Multi-agent playbooks are structured workflows in which several AI agents perform separate roles to complete a larger task. Security specialists have increasingly warned that these systems may expand an organisation's attack surface if deployed without proper vetting. Community-built components can broaden access to innovation, but they can also create uncertainty around provenance, permissions and operational behaviour. Eric Doerr, Chief Product Officer at Tenable, said the collaboration is intended to address that issue. "Agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments," Doerr said. "By combining OpenAI GPT cyber models with Tenable's security expertise and researcher review, we're building a more rigorous way to inspect community-built AI components before they're used in enterprise environments. This is an important step in applying frontier AI to help defenders identify and prioritise risk across the growing agent ecosystem." OpenAI's cyber-focused summit, where the initiative was introduced, brought together security industry leaders to discuss defensive uses of advanced AI systems. The discussions focused on how AI reasoning tools can be integrated into existing security products and workflows to help defenders handle threat findings and remediation more quickly. For Tenable, the tie-up also extends its effort to position itself in the emerging market for AI security oversight. As organisations test agent-based systems for security operations and other tasks, vendors are competing to offer assessment tools that can give risk teams clearer visibility into what those systems do and how they connect to enterprise environments.

AI2
Sep 5th, 2026
Tenable builds an openai-powered vetting gate for MCP servers.

Tenable builds an openai-powered vetting gate for MCP servers. Tenable and OpenAI are building Exchange Inspector, a security review for AI agents, skills and MCP servers on the CyberAgents Exchange. Here's what it means. Key takeaways. * 1Tenable and OpenAI unveiled the CyberAgents Exchange AI Inspector on September 3, 2026 at OpenAI's Intelligence at Work: Cyber Summit; Tenable says it is expected to be available in September. * 2The review combines OpenAI GPT cyber models, skills inspection via Tenable One AI Exposure, and human review by Tenable researchers - a three-layer gate rather than an automated scan. * 3Independent research suggests the underlying problem is real: an Endor Labs analysis of 2,614 MCP implementations found 82% used file operations prone to path traversal, though scanner methodologies vary widely and headline 'percent vulnerable' figures should be read with care. The CyberAgents Exchange launched in August 2026 with a deliberately open pitch: free to use, open to all, no gates. Six weeks later, Tenable is adding one. On September 3, at OpenAI's Intelligence at Work: Cyber Summit, Tenable announced it is collaborating with OpenAI to build the CyberAgents Exchange AI Inspector - a security review process for the AI agents, skills, MCP servers and multi-agent playbooks listed on its registry. The exchange, launched in August 2026 as an open-source, cybersecurity-native directory, now carries more than 100 community-submitted components following Tenable's SWARM build event at Black Hat USA 2026. Tenable says Exchange Inspector is expected to be available in September. The tension is the story. A registry that grows by accepting whatever practitioners contribute eventually has to answer a question enterprise buyers always ask: which of these is safe to plug into production? Tenable's answer is a vetting layer built on frontier models - and it arrives at a moment when the MCP ecosystem's security record is under sustained scrutiny. Three layers: frontier model, platform scan, human researcher. According to Tenable's announcement, Exchange Inspector combines three things: frontier assessment using OpenAI GPT cyber models, skills inspection powered by Tenable One AI Exposure, and expert review from Tenable researchers. The collaboration grew out of Tenable's participation in the OpenAI Daybreak Defense Network, the partner program through which OpenAI says more than 35 enterprise products and partner-operated services are bringing its cyber-tuned models into defender workflows. The architecture matters more than the branding. Static scanners have struggled badly with this class of artifact - one independent audit cited in 2026 security roundups found roughly a 78% false-positive rate from YARA-based MCP scanners, and Endor Labs has noted that conventional SAST tooling does not detect LLM-specific issues at all. A malicious instruction hidden in a tool description is not a code smell; it is prose that reads as documentation. Keeping a human researcher in the loop, rather than shipping a pure automated verdict, is a reasonable read of where the tooling actually is. > "Agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments," said Eric Doerr, chief product officer at Tenable, adding that the goal is a more rigorous way to inspect community-built AI components before they are used in enterprise environments. Why a vetting gate, and why now. The independent research on MCP security is uncomfortable reading. Endor Labs' analysis of 2,614 MCP implementations found that 82% used file operations prone to path traversal, 67% used APIs related to code injection, and 34% used APIs susceptible to command injection. BlueRock Security analysed over 7,000 MCP servers and reported 36.7% as potentially vulnerable to server-side request forgery. Censys counted 12,520 internet-accessible MCP services, most of them unauthenticated. The incident record is not theoretical either. CVE-2025-6514 in mcp-remote - a CVSS 9.6 OS command injection disclosed by JFrog in July 2025, in a package with more than 437,000 downloads - demonstrated remote code execution on a client machine simply from connecting to an untrusted remote server. In June 2026, the Miasma worm campaign planted adversarial MCP configuration files across 73 GitHub repositories, executing credential-harvesting payloads against developers who opened them in IDEs that auto-load project-defined servers. One caveat worth carrying: these figures come from different vendors using different methodologies, and "potentially vulnerable" is doing real work in several of them. The direction of travel is clear; the precise percentages are not directly comparable. What enterprise buyers should watch. For security leaders, the useful question is not whether Tenable's gate exists but what a pass actually certifies. The announcement describes a review process for components "available through" the exchange, and Tenable's own X post referred to a review for select components - which suggests coverage will be partial at launch rather than a blanket sweep of all 100-plus listings. Buyers should ask what fraction of the registry is inspected, how often re-inspection happens, and what the verdict format looks like. Re-inspection is the load-bearing detail. The rug pull attack class - where a server passes review and later silently redefines its tools - makes one-time approval structurally insufficient. So does the fact that a server's tool descriptions enter the model's context window with instruction-level authority the moment it is connected, before any tool is deliberately called. A vetting badge that reflects a single point in time is a weaker signal than it looks. Tenable, which reports over 40,000 customers, is not alone here: Palo Alto Networks, SentinelOne, Sophos, Proofpoint and Trend Micro all announced Daybreak-based capabilities the same day. What distinguishes Tenable's move is the target - not the enterprise's own agents, but the open ecosystem of components those agents pull in. That is the harder surface, and the one nobody currently owns. #Tenable #MCP servers #AI agent security #OpenAI #agentic AI #exposure management #supply chain security #CyberAgents Exchange