Remote job
Sr Offensive AI Security Engineer II
Job details
About this role
Role overview
This position sits at the intersection of offensive security engineering and applied AI, focused on using frontier AI models to discover vulnerabilities across cloud software, application code, and embedded firmware. The role exists to pressure-test AI-driven attack and defense workflows, evaluate each new generation of models for security use, and help shape the long-term strategy for adopting AI safely within security operations. It is a senior, hands-on engineering role that partners with application security, hardware, and engineering leadership, and reports findings to executive stakeholders.
Responsibilities
- Conduct security assessments of software, source code, and firmware, evaluating resilience to AI-driven and adversarial attacks and driving remediation. - Translate general AI security findings into concrete fixes for the application security layer, including adapting software techniques for hardware and embedded firmware contexts. - Hunt for AI-specific and traditional vulnerabilities (for example injection and IDOR) using AI-assisted offensive validation techniques. - Build, pressure-test, and iterate on AI-enabled security tooling and workflows, then lead adoption of what proves useful across the broader security organization. - Benchmark new frontier models against prior versions for security tasks and define release criteria and guardrails for safe adoption. - Support vulnerability triage through an office-hours rotation and contribute to running a bug bounty program, with potential expansion to hardware targets. - Partner cross-functionally with engineering, hardware, and leadership teams, presenting findings to security and executive leadership as the team's authority on AI-related security risk. - Help define and drive the medium- and long-term strategy for adopting AI safely and effectively within security operations.
Requirements
- Senior-level experience in offensive security, application security, or related security engineering work. - Hands-on experience integrating, securing, or red-teaming AI-enabled systems such as large language models, agentic workflows, and related AI tooling. - Familiarity with frontier AI/LLM platforms and their use for both offensive validation (including prompt injection and adversarial testing) and defensive tooling. - Strong background in identifying and remediating traditional web and application vulnerabilities such as injection flaws and authorization issues. - Ability to work across software, hardware, and firmware domains, adapting techniques between environments. - Demonstrated ability to communicate findings to technical and executive audiences and to influence security posture across teams.
Nice to have
- Experience with embedded firmware or hardware security testing. - Prior involvement running or scaling a bug bounty program. - Experience benchmarking AI models and defining safe-use policies or guardrails.
Benefits and work setup
- Flexible working model that supports remote, hybrid, or in-office arrangements depending on role and operational requirements. - Professional development stipend and comprehensive health and parental leave plans. - Inclusive hiring practices with reasonable accommodations available throughout the recruiting process. - Eligibility contingent on ability to secure and maintain legal right to work in the specified location; geographic restrictions apply to certain US metro areas.