Назад
7 часов назад

Offensive Security Engineer (AI Cloud)

Формат работы
remote (только Netherlands)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Security Engineer (AI Cloud): Designing and executing penetration tests, red team engagements, and adversarial simulations across a multi-tenant AI cloud platform with an accent on GPU infrastructure, Kubernetes, virtualization, networking, and inference systems. Focus on researching novel attacks, validating tenant isolation and detection coverage, automating security assessments, and translating complex findings into actionable engineering improvements.

Location: Amsterdam, Netherlands; remote-first culture.

Company

Nebius builds a full-stack AI cloud platform covering data, model training, inference, and production deployment for developers and enterprises.

What you will do

  • Design and execute continuous penetration testing and full-scope red team engagements across compute, storage, inference, networking, orchestration, and internal tooling.
  • Validate Secure SDLC threat models, assess threat severity and mitigation status, and automate routine security validations.
  • Research novel attacks against GPU infrastructure, firmware, drivers, device passthrough, SR-IOV/IOMMU, RDMA/InfiniBand, inference stacks, and managed AI services.
  • Assess tenant-isolation boundaries and conduct targeted security reviews of new products and infrastructure changes.
  • Run purple team exercises with Detection & Response and security engineering teams to validate detection coverage and close gaps.
  • Establish scalable red team processes, tooling, methodology, and reporting practices with prioritized remediation guidance.

Requirements

  • 6+ years of experience in offensive security, penetration testing, red teaming, or adversary simulation.
  • Deep experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes.
  • Strong knowledge of the attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities with Python, Go, or similar languages.
  • Experience running purple team exercises and collaborating constructively with blue teams.
  • Ability to write clear senior-level reports with business-contextualized risk and actionable remediation guidance.

Nice to have

  • Experience attacking ML infrastructure, model-serving pipelines, or GPU clusters.
  • Reverse engineering, exploit development, vulnerability research, or CVE discovery experience.
  • Application security experience and familiarity with eBPF bypass techniques or kernel-level exploitation.
  • Experience with cloud provider internals, including hypervisor and networking layers.
  • Security research presentations at conferences such as BlackHat or DEF CON.

Culture & Benefits

  • Flexible, remote-first work culture with ownership and autonomy.
  • Competitive compensation with equity upside in a Nasdaq-listed company.
  • Career growth and learning opportunities.
  • Collaborative, international environment with experienced engineering teams.
  • Opportunity to work on impactful AI infrastructure and novel security challenges.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →