About this role
Advance the security of frontier AI and software systems by finding novel attack paths before they are exploited. In this role, you will work as an internal adversary across AI agents, cloud infrastructure, developer platforms, and production environments, partnering with engineering teams to strengthen resilience.
Key Responsibilities- Conduct offensive security research across AWS and GCP infrastructure, production services, internal tools, and AI platforms.
- Design realistic adversary simulations involving identity systems, cloud control planes, supply chains, and distributed architectures.
- Discover and exploit weaknesses in proprietary applications, APIs, infrastructure as code, CI/CD pipelines, and AI-enabled developer workflows.
- Research attacks affecting LLMs, AI agents, retrieval systems, MCP integrations, prompt orchestration, and autonomous workflows.
- Reverse engineer critical services to identify architectural weaknesses, exploitation techniques, and new vulnerability classes.
- Model insider-threat and advanced persistent threat scenarios, including privilege escalation, lateral movement, and defense evasion.
- Build offensive tools, automation frameworks, fuzzers, and proof-of-concept exploits.
- Validate remediations with infrastructure, product, and AI engineering teams, improve secure-by-design practices, and assess security controls.
- Document attack methods, publish internal research, and help shape long-term security strategy.
- Experience in offensive security, vulnerability research, red teaming, or exploit development.
- Deep AWS and GCP security knowledge, including IAM, networking, Kubernetes, containers, and identity systems.
- Strong application-security, code-auditing, reverse-engineering, and vulnerability-discovery capabilities.
- Experience assessing software supply chains, CI/CD systems, APIs, and infrastructure automation.
- Proficiency in Python, Go, Rust, C/C++, or comparable languages for security research and offensive tooling.
- Strong knowledge of operating-system internals, networking, authentication protocols, and modern security architectures.
- Ability to independently investigate ambiguous problems and develop new attack techniques.
- Excellent written communication, including the ability to explain complex vulnerabilities to engineering teams.
- AI and LLM security research involving agentic systems, prompt injection, tool abuse, indirect prompt attacks, jailbreaks, model manipulation, RAG security, or autonomous workflows.
- Discovering zero-day vulnerabilities or developing exploits.
- Full-time remote role.
- Annual compensation of $240, 000 to $400, 000.