Offensive Security Engineer, Agent Security
Principal-level Offensive Security Engineer conducts red/purple team operations and penetration testing on AI agent products like Codex and Operator, hunting vulnerabilities in app-infra-model interactions and collaborating with defensive teams to strengthen security.
About the job
Responsibilities
- Continuously hunt for vulnerabilities in the interactions between the applications, infrastructure, and models that power our agentic products.
- Conduct open-scope red and purple team operations, simulating realistic attack scenarios.
- Collaborate proactively with defensive security teams to enhance detection, response, and mitigation capabilities.
- Perform comprehensive penetration testing on our diverse suite of products.
- Leverage advanced automation and OpenAI technologies to optimize your offensive security work.
- Present insightful, actionable findings clearly and compellingly to inspire impactful change.
- Influence security strategy by providing attacker-driven insights into risk and threat modeling.
Requirements
- 7+ years of hands-on red team experience or exceptional accomplishments demonstrating equivalent expertise.
- Deep expertise conducting offensive security operations within modern technology companies.
- Experience designing, developing, or testing assessing the security of AI-powered systems.
- Experience working finding, exploiting and mitigating common vulnerabilities in AI systems like prompt injection, leaking sensitive data, confused deputies, and dynamically generated UI components.
- Exceptional skill in code review, identifying novel and subtle vulnerabilities.
- Proven experience performing offensive security assessments in at least one hyperscaler cloud environment (Azure preferred).
- Demonstrated mastery assessing complex technology stacks, including:
- Highly customized Kubernetes clusters
- Container environments
- CI/CD pipelines
- GitHub security
- macOS and Linux operating systems
- Data science tooling and environments
- Python-based web services
- React-based frontend applications
- Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
- Excellent coding skills, capable of writing robust tools and automation for offensive operations.
- Ability to communicate complex technical concepts effectively through compelling storytelling.
- Proven track record of not just finding vulnerabilities but actively contributing to solutions in complex codebases.
Nice-to-Haves
- Background or expertise in AI or data science.
- Prior experience working in tech startups or fast-paced technology environments.
- Experience in related disciplines such as Software Engineering (SWE), Detection Engineering, Site Reliability Engineering (SRE), Security Engineering, or IT Infrastructure.
Skills
Red Teaming, Purple Teaming, Penetration Testing, Kubernetes, Python, React, Azure, CI/CD, GitHub, Linux, macOS, Prompt Injection, Code Review, Automation, Ai Security
Similar jobs
Security Engineering jobsLeads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.