
Senior Engineer, Offensive Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in District of Columbia, +4 more states.
• Develop high-quality AI agents and offensive security tools, incorporating LLM-driven planning loops, multi-agent orchestration, and tool/function-calling.
• Contribute to the internal agent platform that supports penetration testing and red team operations.
• Manage the tooling as a production-ready, event-driven cloud platform utilizing serverless functions, change-stream pipelines, alarms, and integrated LLM inference.
• Execute network, web application, cloud, and infrastructure penetration tests, covering reconnaissance, exploitation, privilege escalation, and lateral movement.
• Conduct purple team exercises to validate EDR/XDR, NDR, DLP, and firewall countermeasures.
• Collaborate with detection engineering to address vulnerabilities identified during offensive testing.
• Carry out objective-driven red team operations and adversarial assessments of internal LLM products, agents, RAG pipelines, and ML applications.
• Test for prompt injection, jailbreaking, model extraction and inversion, membership inference, poisoning, evasion, and agent tool/sandbox misuse.
• Deliver penetration tests and purple team exercises within the first 90 days and implement enhancements to agentic tooling.
• Deploy AI-driven tools integrated into live workflows, conduct an end-to-end red team operation, and establish consistent adversarial testing and evaluation methodologies.
• Work closely with service lines and the AI & Tooling Lead to influence technical direction.
• Present findings and tooling with detailed reproduction steps, severity, business impact, and remediation strategies.
• Monitor risk using the enterprise risk platform while adhering to acceptable-use-of-AI policies and rules of engagement.
• Minimum of 4 years of experience in offensive operations, including red team, penetration testing, purple team/control validation, or bug bounty roles.
• Proven ability to deliver engagements from start to finish, encompassing scoping, execution, and clear written findings.
• Proficient in production Python engineering for the development and operation of real tools.
• Hands-on experience with designing, building, or operating AI agents or LLM applications.
• Familiarity with agentic workflows, tool/function-calling, and orchestration.
• Practical experience in testing AI/ML systems, including prompt injection, jailbreaking, and adversarial techniques.
• Production experience with at least one major cloud service provider: AWS, GCP, or Azure.
• Ability to operate with significant autonomy on moderately complex engagements.
• Skill in producing reproducible software with evaluations, safety guardrails, and human-in-the-loop controls as necessary.
• Competence in delivering findings with reproduction steps, severity, business impact, and remediation suggestions.
• Ability to track risk within an enterprise risk platform and comply with AI acceptable-use policies and offensive security rules of engagement.
• The selected candidate must live within approximately 60 minutes driving distance of an eligible location.
• Home internet must provide a minimum of 25 Mbps download and 10 Mbps upload speeds.
• Must work from a dedicated space free from interruptions to safeguard PHI/HIPAA information.
• Preferred qualifications include experience with autonomous offensive agents, C2 frameworks, evasion/OPSEC, EDR/XDR, MITRE ATT&CK, VECTR, Atomic Red Team, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, MCP, RAG pipelines, cloud penetration testing, threat intelligence, advanced offensive specialties, research/open-source/talk experience, and relevant certifications.
• Bonus incentive plan.
• Fridays dedicated to research and development.
• Access to Hack The Box Pro Labs.
• All HTB role-based paths and certifications.
• Discretionary funding for certifications.
• Budgets for conferences and training.
• Medical benefits.
• Dental benefits.
• Vision benefits.
• 401(k) retirement savings plan.
• Paid time off.
• Company holidays.
• Personal holidays.
• Paid parental leave.
• Paid caregiver leave.
• Short-term disability.
• Long-term disability.
• Life insurance.
• Additional whole-person wellness and healthcare benefits.
Cloudera
Stellar Cyber
Pragmatike
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.