Lead / Senior Offensive Security Engineer (Offsec AI Team)

Airkit
Airkit

Software Engineering, Data Science

Tel Aviv-Yafo, Israel

Posted on Aug 25, 2026

Description

We're looking for a passionate Lead or Senior Offensive Security Engineer for our growing Offensive Security Automation team. This hands-on offensive security position requires a cyber security professional whose primary focus is to perform security assessments and vulnerability research using internal AI tools using frontier models, with a focus of designing and developing the AI automation and autonomous harnesses together with the team.
This is a role for someone who can perform offensive security testing at scale, combining deep security expertise with the judgment to direct and improve AI-driven tooling.

Key Responsibilities:

Offensive Security & Vulnerability Research (primary)

  • Perform security assessments and vulnerability research across web applications, APIs, and cloud/hybrid infrastructure, using internal AI tools and frontier models to scale coverage and depth that you will develop.

  • Make sure our internal solution can perform exploitation, vulnerability chaining, business logic and authorization abuse, privilege escalation, and lateral movement, beyond what automated tooling alone can find.

  • Run end-to-end engagements: scoping, execution, reporting, and remediation guidance.

  • Discover systemic/architectural weaknesses, not just isolated bugs, and drive secure-by-default fixes.

  • Partner with engineering, security architecture, and detection & response teams to close root causes and validate control effectiveness.

  • Produce high-quality technical reports with clear exploitation paths and prioritized remediation.

AI Automation & Autonomous Harness Design (secondary)

  • Develop the automation and autonomous harnesses that direct frontier models to perform offensive security testing continuously and at scale.

  • Design agent-based workflows that reason over large data, plan for risk signals, business logic and execute multi-step offensive testing that will adapt based on results, recon, hypothesis ranking, chaining of bugs exploitation, AI-Driven assessments, and reporting.

  • Establish human-in-the-loop checkpoints so automation scales offensive coverage without sacrificing safety or precision.

  • Translate your own tradecraft into reusable, explainable automation that the team can run and build on.

Required Qualifications:

  • 6+ years (Senior) / 8+ years (Lead) hands-on offensive security experience such as pentesting, red teaming, or app/security research, with proven complex engagement delivery.

  • Deep, must-have vulnerability knowledge in cloud and web application security: OWASP Top 10+ vulnerability classes, identity/authz attack vectors, and cloud/hybrid attack surfaces.

  • Hands-on experience using internal AI tools and frontier models to perform or accelerate security testing, not just conceptual familiarity!

  • Software engineering fundamentals: System design, API integration, working with distributed services and technologies.

  • Ability to write custom scripts/tooling/payloads and contribute to building automation and autonomous harnesses including prompt engineering.

  • Excellent written and verbal communication skills.

Preferred Qualifications:

  • Experience with agentic frameworks, prompt optimization, agent evaluation, or lightweight model fine-tuning.

  • Published security research, CVEs, or conference talks.

  • Familiarity with MITRE ATT&CK/ATLAS and offensive AI/ML attack surfaces (prompt injection, agentic privilege abuse).

Benefits & Perks:

Check out our benefits site which explains our various benefits, including wellbeing reimbursement, generous parental leave, adoption assistance, fertility benefits, and more.

Open to Flex (1-3 days/week in the office), or Office-Based (4-5 days/week in the office)