Senior Engineer, Offensive Security (AI)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Senior Engineer, Offensive Security (AI): Building production-grade AI agents and offensive security tooling for penetration tests, purple-team exercises, red-team operations, and adversarial testing of internal AI systems with an accent on agentic workflows, cloud platforms, and LLM security. Focus on designing event-driven tooling, testing prompt injection and model abuse, and translating live engagement findings into reliable security capabilities.
Location: Remote nationwide within the United States; occasional travel to offices for training or meetings may be required. A dedicated, interruption-free workspace and internet service with at least 25 Mbps download and 10 Mbps upload are required.
Salary: $117,600β$161,700 per year, plus eligibility for a bonus incentive plan.
Company
is a U.S. healthcare company providing insurance and healthcare services to millions of people.
What you will do
- Build and operate production-grade Python tooling, AI agents, LLM planning loops, function-calling capabilities, and multi-agent orchestration.
- Develop and operate an event-driven cloud platform supporting offensive security workflows at scale.
- Conduct network, web application, cloud, and infrastructure penetration tests from reconnaissance through exploitation and lateral movement.
- Run purple-team exercises with defensive partners to validate EDR/XDR, NDR, DLP, firewall, and detection controls.
- Lead objective-driven red-team operations and adversarial assessments of LLM products, agents, RAG pipelines, and ML applications.
- Deliver reproducible findings, severity assessments, business impact, remediation guidance, and measurable tooling improvements.
Requirements
- 4+ years of offensive security experience in red teaming, penetration testing, purple teaming, control validation, or bug bounty work.
- Production Python engineering experience, including building and operating real tooling.
- Hands-on experience designing, building, or operating AI agents and LLM applications with agentic workflows, function calling, or orchestration.
- Hands-on experience testing AI/ML systems, including prompt injection, jailbreaking, and adversarial techniques.
- Production experience with at least one major cloud provider: AWS, GCP, or Azure.
- Must be able to work remotely within the United States and protect PHI/HIPAA information in a dedicated workspace.
Nice to have
- Experience with autonomous offensive agents, LLM-driven penetration-testing agents, or reinforcement-learning attack planners.
- Knowledge of C2 frameworks, evasion, OPSEC, EDR/XDR, MITRE ATT&CK, VECTR, or Atomic Red Team.
- Experience with PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, MCP, or RAG security.
- Advanced offensive security, cloud penetration testing, threat intelligence, adversarial ML research, published research, or relevant conference contributions.
- Offensive or AI-security certifications such as OSCP, OSEP, OSCE3, CRTO, CPTS, CWES, or OSAI.
Culture & Benefits
- Considerable autonomy on moderately complex engagements and influence over technical direction.
- Dedicated Fridays for research and development.
- Access to Hack The Box Pro Labs, role-based paths, certifications, conference budgets, and training funding.
- Medical, dental, vision, 401(k), paid time off, holidays, parental and caregiver leave, disability coverage, and life insurance.
- Work combines software engineering, live offensive operations, collaborative detection validation, and responsible use of AI.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β