Offensive Security Engineer
Offensive Security Engineer conducts red team operations, penetration testing, and AI/ML attack simulations on cloud infrastructure, applications, and pipelines. Requires 5+ years experience in offensive security, expertise in cloud/web/K8s security, and custom tooling in Python/Go.
About the job
Responsibilities
- Plan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces
- Conduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services
- Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries
- Develop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testing
- Perform open-scope adversary simulations that test detection and response capabilities end to end, collaborating closely with the defensive security team
- Drive threat modeling sessions with engineering teams to identify and prioritize attack vectors in new features and architectures
- Deliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediations
- Contribute to the security of CI/CD pipelines, supply chain integrity, and secrets management through offensive assessment
- Stay current on emerging attack techniques, vulnerability research, and adversary tradecraft; bring external perspective into Perplexity's security strategy
Qualifications
- 5+ years of hands-on experience in offensive security, red teaming, or penetration testing
- Deep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes and container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline security
- Track record of discovering impactful vulnerabilities or developing novel attack techniques in production environments
- Strong programming and scripting skills in Python, Go, or similar languages; comfortable writing custom tooling and exploits
- Experience with industry-standard offensive tools (Burp Suite, Cobalt Strike / Sliver / Mythic, Metasploit, BloodHound, nuclei, etc.) and ability to operate beyond them
- Excellent written and verbal communication; able to translate complex technical findings into clear risk narratives
- Experience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilities
Bonus
- Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributions
Skills
AWS, Kubernetes, Python, Go, Burp Suite, Cobalt Strike, Metasploit, Bloodhound, Nuclei, Ai/Ml Security, Prompt Injection
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.