Description
We're looking for a passionate Lead or Senior Offensive Security Engineer for our growing Offensive Security Automation team. This hands-on offensive security position requires a cyber security professional whose primary focus is to perform security assessments and vulnerability research using internal AI tools using frontier models, with a focus of designing and developing the AI automation and autonomous harnesses together with the team.
This is a role for someone who can perform offensive security testing at scale, combining deep security expertise with the judgment to direct and improve AI-driven tooling.
Key Responsibilities:
Offensive Security & Vulnerability Research (primary)
Perform security assessments and vulnerability research across web applications, APIs, and cloud/hybrid infrastructure, using internal AI tools and frontier models to scale coverage and depth that you will develop.
Make sure our internal solution can perform exploitation, vulnerability chaining, business logic and authorization abuse, privilege escalation, and lateral movement, beyond what automated tooling alone can find.
Run end-to-end engagements: scoping, execution, reporting, and remediation guidance.
Discover systemic/architectural weaknesses, not just isolated bugs, and drive secure-by-default fixes.
Partner with engineering, security architecture, and detection & response teams to close root causes and validate control effectiveness.
Produce high-quality technical reports with clear exploitation paths and prioritized remediation.
AI Automation & Autonomous Harness Design (secondary)
Develop the automation and autonomous harnesses that direct frontier models to perform offensive security testing continuously and at scale.
Design agent-based workflows that reason over large data, plan for risk signals, business logic and execute multi-step offensive testing that will adapt based on results, recon, hypothesis ranking, chaining of bugs exploitation, AI-Driven assessments, and reporting.
Establish human-in-the-loop checkpoints so automation scales offensive coverage without sacrificing safety or precision.
Translate your own tradecraft into reusable, explainable automation that the team can run and build on.
Required Qualifications:
6+ years (Senior) / 8+ years (Lead) hands-on offensive security experience such as pentesting, red teaming, or app/security research, with proven complex engagement delivery.
Deep, must-have vulnerability knowledge in cloud and web application security: OWASP Top 10+ vulnerability classes, identity/authz attack vectors, and cloud/hybrid attack surfaces.
Hands-on experience using internal AI tools and frontier models to perform or accelerate security testing, not just conceptual familiarity!
Software engineering fundamentals: System design, API integration, working with distributed services and technologies.
Ability to write custom scripts/tooling/payloads and contribute to building automation and autonomous harnesses including prompt engineering.
Excellent written and verbal communication skills.
Preferred Qualifications:
Experience with agentic frameworks, prompt optimization, agent evaluation, or lightweight model fine-tuning.
Published security research, CVEs, or conference talks.
Familiarity with MITRE ATT&CK/ATLAS and offensive AI/ML attack surfaces (prompt injection, agentic privilege abuse).
Benefits & Perks:
Check out our benefits site which explains our various benefits, including wellbeing reimbursement, generous parental leave, adoption assistance, fertility benefits, and more.
Open to Flex (1-3 days/week in the office), or Office-Based (4-5 days/week in the office)
