Offensive Security Engineer
Core
Conduct offensive security assessments, red/purple team exercises, and penetration testing across cloud, web, mobile, and AI/ML systems to uncover high-impact vulnerabilities.
Role type
Senior hands-on IC offensive security engineer (red teaming)
Builds
Custom offensive tools, exploits, and automation for security testing
Domain
Cybersecurity, Cloud Security, AI/ML Security
Deliverable
Production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Offensive security, red teaming, penetration testing, cloud security (AWS/GCP/Azure), web and API security, Kubernetes/container security, endpoint security (macOS/Linux), network penetration testing, CI/CD pipeline security, Python/Go programming, exploit development, adversarial simulation, threat modeling
Preferred skills
AI/ML security evaluation, LLM application security, agentic workflow security, prompt injection testing, model exfiltration prevention, published research, conference presentations, CVE contributions, bug bounty results
Technologies
Burp Suite, Cobalt Strike, Sliver, Mythic, Metasploit, BloodHound, nuclei, Python, Go, AWS, GCP, Azure, Kubernetes, Linux, macOS
Responsibilities
Plan and execute red team and purple team exercises emulating sophisticated threat actors; perform ongoing penetration testing of web apps, APIs, mobile clients, and cloud environments; evaluate AI/ML attack surfaces including prompt injection and agent misuse; build and maintain custom offensive tools and automation; lead threat modeling discussions with engineering teams; present actionable findings to stakeholders; strengthen CI/CD pipeline security and supply chain integrity; research emerging exploitation techniques and adversary tactics