Skip to content
CloudflareCloudflareAustin, TX

AI Security Research & Red Team Engineer

Conducts AI-focused security research, agent and LLM testing, adversary simulation, and detection-efficacy validation. The role requires 4+ years of offensive or application security experience, strong penetration-testing or cloud-security fundamentals, and knowledge of AI attack vectors and MITRE ATT&CK.

166k – 208k/yr
Hybrid4+ YOESecurity Engineering

About the role

Responsibilities

  • Conduct AI security and vulnerability research across Cloudflare’s products and services, focusing on AI, agents, harnesses, and large language models.
  • Identify AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage.
  • Define requirements and implementation guidance for secure AI adoption.
  • Execute full-chain red team operations targeting global infrastructure, corporate networks, and product ecosystems.
  • Establish frameworks for measuring security efficacy against known tactics, techniques, and procedures (TTPs).
  • Test the effectiveness of WAF, EDR, and SIEM detections.
  • Partner with Blue Team, Security Incident Response, Threat Detection, and Threat Engineering teams to translate findings into defensive improvements.
  • Conduct unannounced exercises, refine incident-response playbooks, test on-call rotations, and evaluate forensic tooling.
  • Identify detection gaps, develop detection logic, and validate coverage against emerging TTPs.
  • Provide technical leadership and mentorship while fostering ethical hacking and security collaboration.
  • Translate complex exploits into risk-based narratives for leadership and help prioritize engineering resources.
  • Partner with Product Engineering and SRE as a customer-zero tester of security products and processes.
  • Provide empirical evidence of control effectiveness to Governance, Risk, and Compliance teams.

Requirements

  • 4+ years of experience in offensive security, application security, or a related field.
  • Deep knowledge of AI, coding agents, LLMs, prompt engineering, AI-related attack vectors such as prompt injection and jailbreaking, and agentic concepts.
  • Strong background in manual penetration testing, exploit development, or cloud security across AWS, Google Cloud, or bare-metal environments.
  • Experience using the MITRE ATT&CK framework to map coverage and identify defensive telemetry gaps.
  • Ability to explain complex exploits, including zero-day vulnerabilities, to both technical and non-technical stakeholders.
  • Knowledge of automated breach and attack simulation tools and custom frameworks for payload delivery and command-and-control infrastructure.

Compensation and Benefits

  • New York-based hires: estimated annual salary of $166,000–$208,000.
  • Compensation may be adjusted depending on work location.
  • Eligible to participate in Cloudflare’s equity plan.

Skills

ai securityLLMsPrompt Engineeringprompt injectionjailbreakingPenetration Testingexploit developmentAWSGCPmitre att&ckbreach and attack simulationwafedrSIEMcommand and control
Scale AI

Security Engineer, Public Sector

Scale AINew York, NY +2

Security Engineer building high-precision detections, incident response automation, and telemetry pipelines for cloud and SaaS platforms in the Public Sector. Requires active Top Secret clearance, 5+ years in detection engineering or incident response, and production coding skills.

164k – 342k/yrOn-site5+ YOESecurity Engineering
Fluidstack

Information Security Engineer, Bare Metal

FluidstackNew York, NY +3

Build and own end-to-end security for Fluidstack's bare metal AI compute fleet, from supply chain to decommissioning. Harden Linux, enforce BMC security, implement zero-trust networking and encryption at gigawatt scale.

168k – 225k/yrOn-site5+ YOESecurity Engineering
Tailscale

Security Infrastructure Engineer

TailscaleUnited States

Builds security controls across cloud, Kubernetes, networks, and CI/CD for Tailscale. Audits infrastructure, implements security features in Go/Terraform, and provides threat modeling expertise. Requires cloud security and infrastructure experience.

163k – 204k/yrRemoteSecurity Engineering
Tailscale

Security Software Engineer

TailscaleUnited States

Software engineer focused on security and privacy, improving Tailscale's security through feature development, audits, threat modeling, and spending 50% time writing code. Requires proficiency in Go or similar, security experience, and deep knowledge of vulnerabilities and cryptography.

163k – 204k/yrRemoteSecurity Engineering
Clickhouse

Product Security Engineer

ClickhouseUnited States

Product Security Engineer collaborating with engineering and product teams on threat modeling, secure implementation, vulnerability triage, and security tooling for ClickHouse Cloud and OSS. Requires experience with distributed systems, cloud platforms, Kubernetes, and automation-focused security practices.

169k – 225k/yrRemote5+ YOESecurity Engineering