Offensive Security & Red Team
Engineers in this role execute offensive security assessments and red team operations across AI company infrastructure, applications, and—critically—AI-specific attack surfaces including prompt injection, model exfiltration, agent abuse, and tool-use exploitation. They combine hands-on penetration testing and adversarial simulation with custom tooling development, performing both rapid, targeted engagements and comprehensive open-scope operations that validate detection and response capabilities end-to-end. What sets this work apart is the focus on emerging AI risks: engineers assess production language models, agentic systems, and ML pipelines alongside traditional cloud, Kubernetes, and endpoint surfaces. They sit within the security function, partnering closely with defensive teams and product engineering to identify vulnerabilities early in design, then translate findings into actionable risk narratives that drive remediation and inform broader security strategy.
Measured across 8 of 8 open postings.
“Design and run rigorous evaluations of model cyber capabilities and safeguards”
“developing agentic offensive security tooling: LLM-driven systems that encode operator tradecraft”
“Research and implement novel testing approaches for emerging capabilities, including agent systems, tool use, and new interaction paradigms”
“Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries”
Skills
What companies are looking for in this role.
Offensive security testing
Threat modeling and architecture review
Security engineering
Cloud and infrastructure security
Incident response and forensics
Detection engineering
Security tooling and automation engineering
AI red teaming and safety testing
Agentic system research
AI safety and guardrails
AI risk and safety evaluation
AI evaluation design
Technology
The tools and technologies that define this role.
Open Jobs
8 open Offensive Security & Red Team jobs across 6 companies.
Other Security roles
Identifies and mitigates security vulnerabilities in applications and products.
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Builds detection systems, investigates security incidents, and leads incident response efforts.
Designs and maintains identity infrastructure, authentication systems, and access control policies.