Skip to content

Senior Security Engineer, Research & Engineering

Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.

About the job

Responsibilities

  • Conduct red-team evaluations of systems supported by formal specifications and machine-checked proofs.
  • Analyze specifications, designs, proof artifacts, threat models, trusted computing bases, and deployment assumptions to determine what has—and has not—been established.
  • Find and demonstrate exploitable vulnerabilities, including memory corruption, weaknesses in threat models, and failures of deployment assumptions.
  • Build and extend AI-driven vulnerability discovery and triage tooling, including agentic harnesses, automated exploit generation, and cyber reasoning systems.
  • Prepare for fixed one-week red-team sprints within defined acceptance criteria and external schedules.
  • Produce rigorous security assessment reports for expert audiences, documenting findings, attempted approaches, and unsuccessful efforts.
  • Collaborate in small teams with third parties and domain leads across applied cryptography, proof systems, operating system internals, applications, hardware, and AI infrastructure.
  • Publish tooling and methodology, write technical blog content, present internally, and carry lessons between engagements.
  • Report vulnerabilities ethically through established disclosure practices.

Requirements

  • Direct hands-on experience red teaming production software and proving exploitable vulnerabilities.
  • Experience building AI-driven vulnerability-discovery tooling, such as agentic harnesses, LLM-assisted triage pipelines, or automated exploit-generation systems.
  • Experience applying formal methods to system designs and code implementations, including interpreting specifications and machine-checked proof artifacts.
  • Ability to read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust.
  • Deep vulnerability research experience in at least one systems domain, such as network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure.
  • Software development experience with Python, C++, and/or Rust.
  • Experience writing security assessment findings for expert readers.
  • Experience delivering work to fixed external schedules with defined acceptance criteria.
  • Experience with ethical vulnerability disclosure.

Nice-to-haves

  • Published vulnerability research, including CVEs, advisories, or talks at security conferences.
  • Experience auditing or contributing to formally verified codebases such as HACL*, EverCrypt, seL4, CompCert, or CakeML.
  • Experience building automated bug-finding infrastructure at scale, including cyber reasoning systems, fuzzing fleets, or symbolic execution engines.
  • Experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling.
  • Experience attacking AI inference infrastructure, including weight confidentiality and integrity, tenant isolation, or output mediation.
  • Participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar programs.
  • Experience with compiler technology, program analysis, or binary analysis.
  • Experience reading, writing, and publishing academic papers.

Compensation and Benefits

  • Competitive compensation with performance-based bonuses.
  • $1,000 working-from-home stipend.
  • $750 annual learning and development stipend.
  • Company-sponsored all-team celebrations, including travel and accommodation.
  • Philanthropic contribution matching up to $2,000 annually.

Skills

Red Teaming, Formal Methods, Lean, Rocq, F*, Dafny, Verus, Python, C++, Rust, Fuzzing, Symbolic Execution, Binary Analysis, Zero-Knowledge Proofs, AI Infrastructure

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

Writer

Writer

London, United Kingdom

Security Engineer, Detection and Response
No salary listedHybrid7+ YOESecurity Engineering

Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

GitLab

GitLab

Israel
Senior Security Engineer, Security Incident Response Team - EMEA
No salary listedRemote5+ YOESecurity Engineering

Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.

Immersive

Immersive

United Kingdom

Senior Cyber Security Engineer - Red Team
No salary listedRemote5+ YOESecurity Engineering

This role creates and tests red-team labs, ranges, and learning content that simulate real-world attacks and teach offensive-security concepts. It requires several years of penetration-testing or offensive-security experience, strong MITRE ATT&CK knowledge, and broad technical cybersecurity skills.