Jobgether
Senior Offensive AI Security Engineer
- Compensation
- $124K–$271.2K / yr
- From job posting
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Senior
- Posted
- 1 October 2026 (today)
Checked todayApplications go to the employer, never to RoleSprint
About this role
Accountabilities: • Conduct vulnerability research across applications, products, services, and infrastructure, focusing on subtle, high-impact vulnerabilities and attack paths that cross component or trust boundaries.
• Use threat analysis, architecture knowledge, source code, observed system behavior, and target familiarity to select research areas and guide investigations.
• Apply frontier and open-weight AI models, agents, and other AI capabilities throughout the research lifecycle, including reconnaissance, code analysis, hypothesis generation, exploit development, and verification.
• Design and optimize research harnesses that provide AI models with appropriate context, tools, execution environments, and feedback.
• Develop custom security tooling such as analysis utilities, fuzzers, agents, test harnesses, proofs of concept, and full exploits when required to answer research questions.
• Validate model-generated findings by reproducing issues, eliminating false positives, establishing prerequisites, and distinguishing theoretical weaknesses from demonstrated vulnerabilities with meaningful impact.
• Improve the reliability and scalability of AI-assisted security research by addressing false positives, false negatives, context limitations, nondeterministic behavior, and reproducibility challenges.
• Evaluate trade-offs between constrained, orchestrated research pipelines and more autonomous tool-using agents depending on the research objective.
• Partner with engineering and product security teams to communicate findings, support remediation, identify related risks, and validate fixes.
• Share tools, techniques, research methods, and lessons learned to help strengthen AI-enabled security practices across the broader security organization.
Requirements:
• 5+ years of hands-on experience in vulnerability research, offensive security, application security, penetration testing, or a related discipline.
• Demonstrated ability to select research targets, formulate and refine hypotheses, and establish exploitability and security impact in complex software or production environments.
• Hands-on experience applying frontier and open-weight AI models to offensive security workflows, including selecting models appropriately when refusal behavior can interfere with legitimate security research.
• Experience evaluating AI-driven security research processes, including identifying false positives, missed vulnerabilities, unstable results, and reproducibility gaps.
• Strong understanding of agent architecture trade-offs and the ability to determine when controlled, reproducible workflows are appropriate versus when more open-ended agents provide value.
• Deep technical expertise in at least one area such as web applications and APIs, Java applications, cloud or service infrastructure, client software, operating systems, or reverse engineering.
• Strong programming and debugging capabilities, including the ability to understand unfamiliar code, develop research tooling, create proofs of concept, and trace behavior across system boundaries.
• Strong intuition for attack surfaces, trust boundaries, exploitability, and security impact.
• Persistence and self-direction when conducting open-ended research without a predetermined methodology or guaranteed outcome.
• Ability to communicate complex security findings clearly to both technical and non-technical audiences, including evidence, uncertainties, significance, and potential impact.
• Strong analytical thinking, research discipline, technical curiosity, and adaptability in a rapidly evolving AI and security environment.
Benefits:
• Base salary range of $124,000–$271,200 , depending on qualifications, experience, and location.
• Total direct compensation may also include bonus and equity in addition to base salary.
• Remote work opportunity within the United States.
• Location-based compensation structure, with ranges potentially varying by location.
• Comprehensive benefits designed to support physical, mental, emotional, and financial well-being.
• Benefits and perks supporting work-life balance and personal financial health.
• Opportunities to work on cutting-edge applications of AI in offensive security and vulnerability research.
• Collaborative, growth-oriented environment with opportunities to expand technical expertise and take on challenging research problems.
• Support for reasonable accommodations throughout the hiring process.
• Commitment to fair hiring practices focused on skills, experience, and potential.
• Anticipated application closing date: October 14, 2026 .
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 1 October 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.