Remote job
Senior Security Researcher (Red Team)
Job details
About this role
Role overview
As a Senior Security Researcher on a red team, you will proactively discover and demonstrate weaknesses across cloud infrastructure, applications, APIs, SaaS products, and AI-enabled systems. The role combines hands-on offensive security with GenAI attack simulation, deepfake and voice-spoofing research, security automation, and close partnership with defensive, product, and machine-learning teams.
Responsibilities
- Plan and execute red-team operations against LLM pipelines, retrieval-augmented systems, autonomous agents, APIs, SaaS products, and cloud environments. - Test for prompt injection, jailbreaks, indirect attacks, model extraction, training-data poisoning, data leakage, inference abuse, and manipulated outputs. - Use voice synthesis, deepfake generation, and related spoofing methods to evaluate authentication and synthetic-media defenses. - Build realistic attack chains combining AI, application, identity, infrastructure, and API weaknesses. - Conduct penetration tests, support bug-bounty activity, and perform architecture reviews, code reviews, and threat modeling. - Automate offensive-security workflows, testing, reporting, alerting, and compliance checks, then partner with defensive teams to improve detections and remediation.
Requirements
- At least 3 years of practical penetration-testing or offensive-security experience. - Demonstrated hands-on work attacking AI systems, LLM applications, cloud platforms, APIs, or modern web applications. - Strong understanding of common web, API, identity, infrastructure, and cloud attack techniques. - Ability to script in Python or a similar language and develop or adapt offensive-security tooling. - Clear communication skills, including the ability to turn technical findings into prioritized guidance for technical and executive audiences. - Independence, curiosity, resilience, and sound judgment in ambiguous, fast-moving environments.
Nice to have
- Experience in adversarial machine learning, LLM security, voice or audio deepfake detection, fraud prevention, or voice biometrics. - Certifications such as OSCP, GPEN, GWAPT, GXPN, CEH, or comparable credentials. - Familiarity with evolving GenAI threat research, threat intelligence, or relevant regulatory developments.
Benefits and work setup
- Remote-first environment with periodic team gatherings and company events. - Equity eligibility, unlimited paid time off, health and welfare plans, and employer HSA contributions. - Paid parental leave, connectivity support, professional-development funding, and enhanced fertility and wellness benefits.