Most of them work in the security industry and do:
* malware analysis (how does this malware work, how can it be detected, can we somehow decrypt data affected by this ransomware, are there any leads to who wrote this malware, etc)
* vulnerability research (finding and exploiting vulnerabilities in closed source software)
* assessment of closed source software (how secure is it, how does it work, does it have undocumented apis and how can those be used, etc.)
there is likely also a small market for analysis of competitor software, but I haven't seen this openly advertised yet.