Remote job
Offensive Security Engineer
Job details
About this role
Role overview Join an internal product security team as a hands-on Offensive Security Engineer focused on a large-scale cloud platform serving AI workloads. You will design and execute adversarial simulations against the same infrastructure customers depend on, then translate findings into measurable security improvements. The role combines red team operations, penetration testing program building, and original research into novel threat vectors.
Responsibilities - Continuously validate and extend Secure-SDLC threat models through penetration testing, challenging assumptions from earlier modeling and system design, and automating routine checks to scale with feature flow. - Plan and run full-scope red team engagements spanning compute, storage, inference, networking, orchestration layers, and internal tooling, including purple team exercises with detection and response teams to close coverage gaps. - Research novel attacks against GPU infrastructure (firmware, vendor drivers, device passthrough, SR-IOV/IOMMU misconfigurations, RDMA/InfiniBand fabric issues), inference stacks, and managed AI services, probing tenant-isolation boundaries. - Conduct targeted security assessments of new products and infrastructure changes before they ship. - Deliver clear, actionable reports for both engineers and leadership, with prioritized findings and remediation guidance. - Establish red team processes, tooling, and a methodology that scales with platform growth.
Requirements - Six or more years in offensive security, including penetration testing, red teaming, or adversary simulation. - Deep experience attacking cloud-native environments: Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes. - Strong fundamentals across the attack lifecycle: initial access, persistence, lateral movement, and data exfiltration. - Proficiency developing custom tooling and post-exploitation capabilities in Python, Go, or similar languages. - Experience running purple team exercises and collaborating constructively with blue teams. - Ability to write senior-level reports with business-contextualized risk that engineers can act on directly.
Nice to have - Background attacking ML infrastructure, model serving pipelines, or GPU clusters. - Reverse engineering and exploit development experience, plus application security experience. - Familiarity with eBPF bypass techniques or kernel-level exploitation. - Vulnerability research or CVE discovery experience. - Knowledge of cloud provider internals at the hypervisor or networking layer. - Public security research presented at events like Black Hat or DEF CON.
Benefits and work setup - Flexible, remote-first culture. - Competitive compensation with equity upside in a high-growth, publicly traded company. - International environment with collaborative teams and opportunities for career growth and learning. - Hiring process: recruiter chat, live-coding interview, security interview, security system design interview, optional technical deep dive, and final closing interview. - Equal opportunity employer committed to an inclusive and diverse workplace.