Назад
Company hidden
23 часа назад

Senior Security Researcher (Red Team)

125 000 - 165 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Researcher (Red Team) (GenAI and Deepfake Security): Identifying and exploiting weaknesses across GenAI systems, LLM pipelines, SaaS products, APIs, cloud environments, and voice authentication with an accent on adversarial AI testing, offensive security, and deepfake defense. Focus on designing attack chains, simulating prompt injection and model extraction, testing voice-synthesis spoofing, and translating findings into practical remediation.

Location: Remote within the United States

Salary: $125,000–$165,000 USD per year

Company

hirify.global provides an identity trust platform focused on real-time identity verification and deepfake detection across voice, video, and digital interactions.

What you will do

  • Design and execute red team operations against GenAI systems, LLM pipelines, RAG architectures, autonomous agents, APIs, SaaS products, and cloud environments.
  • Conduct adversarial testing for prompt injection, jailbreaking, model extraction, training-data poisoning, data leakage, inference abuse, and unauthorized output manipulation.
  • Use deepfake generation, voice synthesis, and audio/visual spoofing techniques to test voice authentication and deepfake detection systems.
  • Develop end-to-end attack chains combining GenAI, infrastructure, application, identity, and API vulnerabilities.
  • Perform penetration tests, support bug bounty efforts, and conduct architecture reviews, security code reviews, and threat modeling.
  • Build offensive security automation and partner with SecOps and security engineering on detection improvements and remediation.

Requirements

  • 3+ years of hands-on penetration testing and red team experience across SaaS applications, cloud infrastructure, APIs, and web applications.
  • Demonstrable experience attacking GenAI or LLM-based systems, including prompt injection, jailbreaking, model extraction, or adversarial input generation.
  • Hands-on experience with deepfake tools, voice synthesis, or audio/visual spoofing technologies.
  • Proficiency with offensive security tooling such as Burp Suite, OWASP ZAP, Nmap, Metasploit, or Cobalt Strike.
  • Experience with SAST and DAST tools, CI/CD integration, and scripting or programming, with Python strongly preferred.
  • Knowledge of cloud security architecture, container security, API security, AI security tools, and standards including NIST, CIS, PCI DSS, OWASP, and SOC 2.

Nice to have

  • Software development or secure architecture experience.
  • Research or practitioner experience in adversarial machine learning, LLM security, or voice/audio deepfake detection.
  • OSCP, GPEN, GWAPT, GXPN, CEH, or equivalent certification.
  • Experience in voice biometrics, AI security, fraud prevention, or other high-risk product environments.

Culture & Benefits

  • Remote-first work environment with flexibility and autonomy.
  • Regular team off-sites, company-wide events, and in-person gatherings.
  • Unlimited paid time off and paid parental leave.
  • Health, dental, vision, and HSA benefits, plus enhanced fertility and GLP-1 benefits.
  • Monthly phone and internet allowance, RSUs for all employees, and an annual learning and development stipend.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →