Skip to content
PindropPindrop

Senior Security Engineer

Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.

About the job

What you’ll do

  • Design and execute red team operations against Pindrop’s GenAI systems, LLM pipelines, RAG architectures, autonomous agents, APIs, SaaS products, and cloud environments, simulating real-world attacks across both traditional and AI-specific attack surfaces.
  • Conduct adversarial testing focused on prompt injection, indirect prompt attacks, jailbreaking, model extraction, training-data poisoning, data leakage, inference abuse, and unauthorized output manipulation.
  • Use deepfake generation, voice synthesis, and related spoofing techniques to test and attempt to defeat Pindrop’s voice authentication and deepfake detection capabilities, helping identify model robustness and detection gaps.
  • Develop novel attack chains that combine GenAI vulnerabilities with infrastructure, application, identity, and API weaknesses to create realistic end-to-end threat scenarios.
  • Plan and execute full-scope penetration tests and support bug bounty efforts across Pindrop’s web applications, APIs, SaaS products, and AWS/GCP environments using commercial and open-source offensive tooling.
  • Perform architecture reviews, security code reviews, and threat modeling with emphasis on vulnerabilities introduced by AI/ML components, model integrations, and LLM-facing services.
  • Build automation for offensive security workflows, testing, compliance checks, alerting, and reporting using Python or similar scripting languages, including AI-native attack tooling where useful.
  • Partner closely with SecOps and security engineering to improve detections, tune response workflows, and translate red team findings into practical remediation and defensive improvements.
  • Stay current on GenAI security research, adversarial ML techniques, evolving threat intelligence, and relevant regulatory developments, then apply those insights to Pindrop’s security program.

Who you are

  • Adversarial thinker who approaches security from an attacker’s perspective with creativity, rigor, and curiosity.
  • Genuine hands-on experience attacking AI systems.
  • Continuously look for automation and AI-powered efficiencies in offensive security workflows.
  • Communicate clearly and translate technical findings into prioritized, actionable guidance for technical and executive audiences.
  • Work independently in ambiguous, fast-moving environments with minimal supervision.
  • Resilient, optimistic, accountable, and adaptable.

Your skill-set

Must-haves

  • 3+ years of hands-on penetration testing and red team experience across SaaS applications, cloud infrastructure, APIs, and web applications.
  • Demonstrable experience attacking GenAI or LLM-based systems, including prompt injection, jailbreaking, indirect prompt attacks, model extraction, or adversarial input generation.
  • Hands-on experience with deepfake tools, voice synthesis, or audio/visual spoofing technologies in an offensive or research context.
  • Strong proficiency with offensive security tooling such as Burp Suite, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, or equivalent frameworks.
  • Experience configuring and operating SAST and DAST tools and integrating them into CI/CD pipelines.
  • Proficiency in at least one scripting or programming language, with Python strongly preferred, for custom attack tooling and workflow automation.
  • Familiarity with AI-specialized security tools or frameworks such as Garak, PyRIT, Claude Security, or similar adversarial ML tooling.
  • Strong understanding of cloud security architecture, container security, API security, and common security standards including ISO 27001/27002, NIST, CIS, PCI DSS, OWASP, and SOC 2.

Nice-to-haves

  • Prior software development or secure architecture experience, including the ability to reason about production code across multiple languages.
  • Research, publication, or deep practitioner background in adversarial machine learning, LLM security, or voice/audio deepfake detection.
  • Relevant certifications such as OSCP, GPEN, GWAPT, GXPN, CEH, or equivalent.
  • Prior experience in voice biometrics, AI security, fraud prevention, or similarly high-risk product environments.

What we offer

  • Competitive compensation package, including RSUs (Restricted Stock Units) for all employees.
  • Remote-first environment.
  • Unlimited Paid Time Off (PTO).
  • Generous health and welfare plans including employer-paid “employee-only” plan, HSA contribution, low-cost vision and dental.
  • Paid Parental Leave.
  • One year of diaper delivery for new additions.
  • Recurring monthly phone and internet allowance.
  • Enhanced fertility and GLP-1 benefits.
  • Annual Learning & Development stipend.

Skills

Penetration Testing, Red Team Operations, Prompt Injection, Jailbreaking, Model Extraction, Deepfake Generation, Voice Synthesis, Burp Suite, Metasploit, Cobalt Strike, Python, Garak, Pyrit, AWS, GCP

GitLab

GitLab

United States

Senior Security Compliance Engineer, Public Sector
$139k+/yrRemote5+ YOESecurity Engineering

Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.

GitLab

GitLab

United States

Senior Security Assurance Engineer
$139k+/yrRemote5+ YOESecurity Engineering

Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.

Twilio

Twilio

United States

Senior Security Engineer, Incident Response
$142k+/yrRemote5+ YOESecurity Engineering

Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.

Writer

Writer

San Francisco, CA
Security Engineer, Detection and Response
$132k+/yrHybrid7+ YOESecurity Engineering

Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.

Plaid

Plaid

New York, NY

Fraud Intelligence Lead
$149k+/yrHybrid5+ YOESecurity Engineering

Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.