Offensive Security Engineer, Vulnerability Operations

SECURITY PRODUCTS, INC.
Austin, TX, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$224,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Encodings Fuzz Testing Python (Programming Language) OpenShift Program Analysis Red Team (Cyber Security) Software Engineering Web Applications Large Language Models Multi-Agent Systems
+6 more
Model Validation Kubernetes Production Code Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Crafting and building new red team agents: autonomous and semi-autonomous LLM agents that perform reconnaissance, hypothesis-driven exploitation, and evidence capture against NVIDIA-owned targets
  • Extending our existing agent harnesses (multi-phase orchestration, parallel specialist subagents, judge/verifier stages, out-of-band callback infrastructure) across multiple agent runtimes and model providers
  • Encoding real operator tradecraft into prompts, tools, and playbooks - web app exploitation, auth bypass, SSRF/deserialization chains, cloud and Kubernetes attack paths - so agents find what a skilled human would
  • Building the verification layer: exploit-confirmation harnesses that prove findings are real before a human ever sees them, driving false-positive rates down
  • Engineering the safety side of autonomy: sandboxing, scope enforcement, tool allowlists/blocklists, credential isolation, and prompt-injection defenses for agents operating with offensive capability
  • Evaluating and benchmarking frontier models for offensive tasks; partnering with our human red team to turn their engagements into repeatable agent capabilities
  • Mentoring engineers on the team and setting the technical bar for agentic offensive tooling

Requirements

  • Bachelor’s degree or equivalent experience
  • 12+ years in security engineering, with at least 4 years in offensive security: penetration testing, red teaming, exploit development, or vulnerability research
  • Deep, hands-on exploitation skill in at least one domain (web application, cloud/Kubernetes, or systems/binary) - you can build and prove an exploit chain, not just run a scanner
  • Strong software engineering ability in Python; you ship production code, not just PoCs
  • Practical experience building with LLMs: agent frameworks, tool use/function calling, multi-agent orchestration, or coding agents (Claude Code, Codex CLI, or similar)
  • Sound judgment about autonomous offensive tooling - scoping, authorization, and blast-radius thinking are second nature
  • Respectful, responsible approach to offensive testing - we break things carefully and fix them fast

Ways to stand out from the crowd:

  • Published security research, CVEs, conference talks, or notable CTF results
  • Certifications like OSWE, OSEP, OSCP, or GXPN
  • Experience with SAST/DAST internals, fuzzing, or program analysis
  • Experience red-teaming AI systems themselves (prompt injection, jailbreaks, model evaluation) or contributing to AI-security research
  • Familiarity with Kubernetes/OpenShift, GitOps, and operating worker fleets at scale

Benefits & conditions

With competitive salaries and a generous benefits package, NVIDIA is widely considered to be one of the technology world’s most desirable employers. We have some of the most forward-thinking and talented people in the world working for us and, due to unprecedented growth, our elite engineering teams are rapidly growing. If you’re a creative and autonomous engineer with a real passion for technology, we want to hear from you!

Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 431,250 USD for Level 6.

You will also be eligible for equity and benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

4:47 min

Exploring OpenShift and Red Hat Developer Sandbox resources

Markus Eisele Markus Eisele · World Congress 2024

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:12 min

Distilling cross-encoder models into smaller efficient sentence embedding models

Marek Suppa · LIVE

Videos

See all

Related articles

See all