> Markdown version of [/jobs/ext/2735934-offensive-security-engineer-vulnerability-operations](https://www.wearedevelopers.com/jobs/ext/2735934-offensive-security-engineer-vulnerability-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Engineer, Vulnerability Operations - **Company:** SECURITY PRODUCTS, INC. - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $224,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Encodings, Fuzz Testing, Python (Programming Language), OpenShift, Program Analysis, Red Team (Cyber Security), Software Engineering, Web Applications, Large Language Models, Multi-Agent Systems, Model Validation, Kubernetes, Production Code, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/senior-offensive-security-engineer-vulnerability-operations-2100-nvidia-usa-9875814 ## About the Role * Bachelor's degree or equivalent experience * 12+ years in security engineering, with at least 4 years in offensive security: penetration testing, red teaming, exploit development, or vulnerability research * Deep, hands-on exploitation skill in at least one domain (web application, cloud/Kubernetes, or systems/binary) - you can build and prove an exploit chain, not just run a scanner * Strong software engineering ability in Python; you ship production code, not just PoCs * Practical experience building with LLMs: agent frameworks, tool use/function calling, multi-agent orchestration, or coding agents (Claude Code, Codex CLI, or similar) * Sound judgment about autonomous offensive tooling - scoping, authorization, and blast-radius thinking are second nature * Respectful, responsible approach to offensive testing - we break things carefully and fix them fast Ways to stand out from the crowd: * Published security research, CVEs, conference talks, or notable CTF results * Certifications like OSWE, OSEP, OSCP, or GXPN * Experience with SAST/DAST internals, fuzzing, or program analysis * Experience red-teaming AI systems themselves (prompt injection, jailbreaks, model evaluation) or contributing to AI-security research * Familiarity with Kubernetes/OpenShift, GitOps, and operating worker fleets at scale ## Description * Crafting and building new red team agents: autonomous and semi-autonomous LLM agents that perform reconnaissance, hypothesis-driven exploitation, and evidence capture against NVIDIA-owned targets * Extending our existing agent harnesses (multi-phase orchestration, parallel specialist subagents, judge/verifier stages, out-of-band callback infrastructure) across multiple agent runtimes and model providers * Encoding real operator tradecraft into prompts, tools, and playbooks - web app exploitation, auth bypass, SSRF/deserialization chains, cloud and Kubernetes attack paths - so agents find what a skilled human would * Building the verification layer: exploit-confirmation harnesses that prove findings are real before a human ever sees them, driving false-positive rates down * Engineering the safety side of autonomy: sandboxing, scope enforcement, tool allowlists/blocklists, credential isolation, and prompt-injection defenses for agents operating with offensive capability * Evaluating and benchmarking frontier models for offensive tasks; partnering with our human red team to turn their engagements into repeatable agent capabilities * Mentoring engineers on the team and setting the technical bar for agentic offensive tooling ## Related Videos - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)