Staff Security Researcher – Offensive AI

Posted 17 hours ago

This is a fully remote position, open to applicants in United States, +1 more country.

📋 Description

• Conduct original offensive research targeting Dia, its agents, and backend services.

• Explore prompt injection, indirect data exfiltration, tool-call misuse, permission and provenance circumvention, sandbox escape, cross-profile data access, and quota and abuse-scoring evasion.

• Collaborate with product teams to develop threat models for new surface areas and assess features prior to launch.

• Design and implement automated vulnerability discovery methods, including model-driven code and infrastructure analysis, fuzzing harnesses, and agentic hunting pipelines.

• Work alongside engineers to eradicate classes of vulnerabilities and make it structurally challenging to reintroduce issues.

• Establish standards for security testing prior to feature deployment.

• Evaluate commercial scanning solutions, frontier models, and open-source security frameworks, deploying them against the codebase, infrastructure, and agent runtime.

• Organize and execute regular AI-assisted red team exercises, creating attack corpora and harnesses.

• Influence pre-launch assessments for tools, integrations, agent capabilities, enterprise controls, and platform enhancements.

• Report directly to the Head of Security and collaborate across client, infrastructure, and product engineering disciplines.


⛳️ Requirements

• Over 8 years of experience in offensive security, including vulnerability research, exploit development, red teaming, or product security testing, with a proven track record of identifying genuine bugs in previously reviewed software.

• Expertise in at least one challenging area: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure, along with a willingness to learn the others.

• Practical proficiency in using LLMs as tools rather than just targets, along with a discerning ability to identify when their output is irrelevant.

• Experience in production-quality coding with one or more of the following languages: Go, TypeScript, Python, or Swift.

• Capable of documenting findings that engineers can act upon and engaging in the remediation discussion without owning the fixes.

• Ability to excel in a high-trust, high-ambiguity environment.

• Alignment with company values.

• Preference for candidates primarily located in North American time zones.

• At least 4 hours of overlap with team members in the Eastern Time Zone.


🏝️ Benefits

• Competitive base salary, equity, and comprehensive benefits package.

• Top-tier benefits aimed at supporting you, your family, and your life outside of work.

• Remote-first, distributed team structure.

• Option to work from the office located in Brooklyn, New York.

• Opportunity for startup-style impact, ownership, and innovative working practices.

People also viewed

Sony Interactive Entertainment12 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads12 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j12 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)13 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting13 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International14 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers