
Staff Security Researcher – Offensive AI
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Conduct original offensive research targeting Dia, its agents, and backend services.
• Explore prompt injection, indirect data exfiltration, tool-call misuse, permission and provenance circumvention, sandbox escape, cross-profile data access, and quota and abuse-scoring evasion.
• Collaborate with product teams to develop threat models for new surface areas and assess features prior to launch.
• Design and implement automated vulnerability discovery methods, including model-driven code and infrastructure analysis, fuzzing harnesses, and agentic hunting pipelines.
• Work alongside engineers to eradicate classes of vulnerabilities and make it structurally challenging to reintroduce issues.
• Establish standards for security testing prior to feature deployment.
• Evaluate commercial scanning solutions, frontier models, and open-source security frameworks, deploying them against the codebase, infrastructure, and agent runtime.
• Organize and execute regular AI-assisted red team exercises, creating attack corpora and harnesses.
• Influence pre-launch assessments for tools, integrations, agent capabilities, enterprise controls, and platform enhancements.
• Report directly to the Head of Security and collaborate across client, infrastructure, and product engineering disciplines.
• Over 8 years of experience in offensive security, including vulnerability research, exploit development, red teaming, or product security testing, with a proven track record of identifying genuine bugs in previously reviewed software.
• Expertise in at least one challenging area: LLM agent systems, browser or Chromium internals, OS sandboxing and native clients, or backend and cloud infrastructure, along with a willingness to learn the others.
• Practical proficiency in using LLMs as tools rather than just targets, along with a discerning ability to identify when their output is irrelevant.
• Experience in production-quality coding with one or more of the following languages: Go, TypeScript, Python, or Swift.
• Capable of documenting findings that engineers can act upon and engaging in the remediation discussion without owning the fixes.
• Ability to excel in a high-trust, high-ambiguity environment.
• Alignment with company values.
• Preference for candidates primarily located in North American time zones.
• At least 4 hours of overlap with team members in the Eastern Time Zone.
• Competitive base salary, equity, and comprehensive benefits package.
• Top-tier benefits aimed at supporting you, your family, and your life outside of work.
• Remote-first, distributed team structure.
• Option to work from the office located in Brooklyn, New York.
• Opportunity for startup-style impact, ownership, and innovative working practices.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.