Offensive Security & Red Team
Engineers in this role execute offensive security assessments and red team operations across AI company infrastructure, applications, and—critically—AI-specific attack surfaces including prompt injection, model exfiltration, agent abuse, and tool-use exploitation. They combine hands-on penetration testing and adversarial simulation with custom tooling development, performing both rapid, targeted engagements and comprehensive open-scope operations that validate detection and response capabilities end-to-end. What sets this work apart is the focus on emerging AI risks: engineers assess production language models, agentic systems, and ML pipelines alongside traditional cloud, Kubernetes, and endpoint surfaces. They sit within the security function, partnering closely with defensive teams and product engineering to identify vulnerabilities early in design, then translate findings into actionable risk narratives that drive remediation and inform broader security strategy.
Skills
What companies are looking for in this role.
Conducting penetration testing and vulnerability assessment of web applications, APIs, and cloud infrastructure
Planning and executing red team and purple team engagements to simulate advanced threat actors
Developing custom offensive tools, exploits, and automation frameworks to improve security testing coverage
Assessing Kubernetes and containerized environment security
Evaluating cloud infrastructure security across major cloud providers
Performing code review and architecture review to identify logic flaws and design weaknesses
Conducting threat modeling sessions with engineering teams to identify attack vectors
Chaining vulnerabilities together to demonstrate realistic business impact and lateral movement
Researching emerging attack techniques and adversary tradecraft to stay current on threats
Assessing CI/CD pipeline and supply chain security
Performing endpoint security testing on macOS and Linux systems
Conducting whitebox penetration testing with full access to source code and systems
Performing manual code-level inspections to uncover complex logic errors and authorization bypasses
Integrating and operationalizing security scanning and remediation tooling
Assessing distributed microservice ecosystems and service-to-service trust boundaries
Building hardened base images and reusable security libraries across systems
Performing reverse engineering and firmware analysis on hardware and silicon components
Identifying and exploiting AI/ML-specific attack surfaces including prompt injection and model exfiltration
Testing agentic AI systems and autonomous workflows for exploitation and abuse
Identifying novel attack surfaces and conducting security research on emerging risks
Developing automated defensive strategies and regression pipelines for non-deterministic AI risks
Testing vector databases, retrieval-augmented generation architectures, and LLM pipelines
Communicating technical security findings to both technical and non-technical stakeholders
Collaborating with engineering and product teams to validate remediations and drive security fixes
Embedding security into development lifecycle and design review processes
Leading and directing offensive security teams and cross-functional security initiatives
Technology
The tools and technologies that define this role.
Open Jobs
11 open Offensive Security & Red Team jobs across 7 companies.
Other Security roles
Identifies and mitigates security vulnerabilities in applications and products.
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Builds detection systems, investigates security incidents, and leads incident response efforts.
Designs and maintains identity infrastructure, authentication systems, and access control policies.