Applied Methods
~The MetaSecurityOffensive Security & Red Team

Offensive Security & Red Team

Engineers in this role execute offensive security assessments and red team operations across AI company infrastructure, applications, and—critically—AI-specific attack surfaces including prompt injection, model exfiltration, agent abuse, and tool-use exploitation. They combine hands-on penetration testing and adversarial simulation with custom tooling development, performing both rapid, targeted engagements and comprehensive open-scope operations that validate detection and response capabilities end-to-end. What sets this work apart is the focus on emerging AI risks: engineers assess production language models, agentic systems, and ML pipelines alongside traditional cloud, Kubernetes, and endpoint surfaces. They sit within the security function, partnering closely with defensive teams and product engineering to identify vulnerabilities early in design, then translate findings into actionable risk narratives that drive remediation and inform broader security strategy.

$ titles --canonical
Offensive Security EngineerSecurity Lead, Agentic Red Team
Open Jobs11
Companies Hiring7
$02

Skills

What companies are looking for in this role.

$ skills --core

Conducting penetration testing and vulnerability assessment of web applications, APIs, and cloud infrastructure

95%

Planning and executing red team and purple team engagements to simulate advanced threat actors

95%

Developing custom offensive tools, exploits, and automation frameworks to improve security testing coverage

90%

Assessing Kubernetes and containerized environment security

85%

Evaluating cloud infrastructure security across major cloud providers

85%

Performing code review and architecture review to identify logic flaws and design weaknesses

80%

Conducting threat modeling sessions with engineering teams to identify attack vectors

80%

Chaining vulnerabilities together to demonstrate realistic business impact and lateral movement

80%

Researching emerging attack techniques and adversary tradecraft to stay current on threats

75%

Assessing CI/CD pipeline and supply chain security

75%

Performing endpoint security testing on macOS and Linux systems

75%

Conducting whitebox penetration testing with full access to source code and systems

70%

Performing manual code-level inspections to uncover complex logic errors and authorization bypasses

70%

Integrating and operationalizing security scanning and remediation tooling

60%

Assessing distributed microservice ecosystems and service-to-service trust boundaries

60%

Building hardened base images and reusable security libraries across systems

55%

Performing reverse engineering and firmware analysis on hardware and silicon components

50%
$ skills --emerging

Identifying and exploiting AI/ML-specific attack surfaces including prompt injection and model exfiltration

90%

Testing agentic AI systems and autonomous workflows for exploitation and abuse

85%

Identifying novel attack surfaces and conducting security research on emerging risks

70%

Developing automated defensive strategies and regression pipelines for non-deterministic AI risks

65%

Testing vector databases, retrieval-augmented generation architectures, and LLM pipelines

60%
$ skills --soft

Communicating technical security findings to both technical and non-technical stakeholders

95%

Collaborating with engineering and product teams to validate remediations and drive security fixes

90%

Embedding security into development lifecycle and design review processes

65%

Leading and directing offensive security teams and cross-functional security initiatives

60%
$03

Technology

The tools and technologies that define this role.

$ tech --language
Pythonvery high
Gohigh
$ tech --framework
Reactmoderate
$ tech --platform
AWSvery high
Kubernetesvery high
Linuxvery high
Azurehigh
Dockerhigh
GCPhigh
macOShigh
GitHubmoderate
HackerOnemoderate
$ tech --tool
Burp Suitehigh
Cobalt Strikemoderate
DASTmoderate
SASTmoderate
SCAmoderate
Havoclow
JTAGlow
Sliverlow
SWDlow
UARTlow
$ tech --concept
API securityvery high
LLMvery high
Prompt injectionvery high
CI/CDhigh
Tool-use exploitationhigh
RAGmoderate
$04

Open Jobs

11 open Offensive Security & Red Team jobs across 7 companies.

OpenAI1w
Security Preparedness Lead, Coding Agents
San Francisco·Security
OpenAI1w
Security Researcher, Agentic AI Threats
San Francisco·Security
Perplexity1mo
Member of Technical Staff (Offensive Security Engineer)
San Francisco·Security
Mistral AI1mo
CyberSecurity, Offensive Security Engineer
Paris·Security
CoreWeave2mo
Offensive Security Engineer
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA·Security
Anthropic2mo
Offensive Security Research Engineer, Safeguards
San Francisco, CA·Security
Anthropic2mo
Security Engineer, Offensive Security
Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA·Security
Replit2mo
Offensive Security Engineer
Foster City, CA·Security
OpenAI7mo
Offensive Security Engineer, Agent Products
San Francisco·Security
OpenAI7mo
Offensive Security Engineer, Hardware
San Francisco·Security
Crusoe1y+
Staff Product Security Engineer
San Francisco, CA - US·Security