Senior Security Researcher – Red Team

🕒 Julho 1

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $125.000 - $165.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

infoinfo

👻 Score fantasma 25%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Pindrop

Pindrop

201 - 500 funcionários

Fundada em 2011

🛡️ Seguros

💼 Consultoria

🏥 Saúde

Insurance • Consulting • Healthcare

A Pindrop é líder em autenticação de voz e detecção de fraude, oferecendo soluções inovadoras para aumentar a segurança das comunicações por voz. A empresa utiliza tecnologias avançadas, como detecção de vitalidade, análise comportamental e biometria de voz para combater ameaças como deepfakes e falsificações em diversos setores, incluindo bancário, financeiro, segurador e varejo. A Pindrop integra-se com plataformas como a Five9 para fornecer autenticação multifatorial, garantindo tanto a proteção de informações sensíveis quanto uma experiência de usuário perfeita. Com foco na segurança de call centers e dispositivos inteligentes, a Pindrop ajuda empresas a prevenir fraudes e melhorar as interações com clientes, aproveitando tecnologias de ponta em áudio, voz e IA. Suas soluções são confiadas por algumas das maiores instituições financeiras e companhias de seguro do mundo.

Descrição

• Design and execute red team operations against GenAI systems, LLM pipelines, RAG architectures, autonomous agents, APIs, SaaS products, and cloud environments • Conduct adversarial testing for prompt injection, indirect prompt attacks, jailbreaking, model extraction, training-data poisoning, data leakage, inference abuse, and unauthorized output manipulation • Use deepfake generation, voice synthesis, and spoofing techniques to test voice authentication and deepfake detection capabilities • Develop attack chains combining GenAI vulnerabilities with infrastructure, application, identity, and API weaknesses • Plan and execute penetration tests and support bug bounty efforts across web applications, APIs, SaaS products, and AWS/GCP environments • Perform architecture reviews, security code reviews, and threat modeling focused on AI/ML components and LLM-facing services • Build automation for offensive security workflows, testing, compliance checks, alerting, and reporting using Python or similar scripting languages • Partner with SecOps and security engineering to improve detections, response workflows, remediation, and defensive improvements • Monitor GenAI security research, adversarial ML techniques, threat intelligence, and regulatory developments and apply insights to Pindrop’s security program

🎯 Requisitos

• 3+ years of hands-on penetration testing and red team experience across SaaS applications, cloud infrastructure, APIs, and web applications • Demonstrable experience attacking GenAI or LLM-based systems, including prompt injection, jailbreaking, indirect prompt attacks, model extraction, or adversarial input generation • Hands-on experience with deepfake tools, voice synthesis, or audio/visual spoofing technologies in an offensive or research context • Strong proficiency with offensive security tooling such as Burp Suite, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, or equivalent frameworks • Experience configuring and operating SAST and DAST tools and integrating them into CI/CD pipelines • Proficiency in at least one scripting or programming language; Python strongly preferred • Familiarity with AI-specialized security tools or frameworks such as Garak, PyRIT, Claude Security, or similar adversarial ML tooling • Strong understanding of cloud security architecture, container security, API security, and security standards including ISO 27001/27002, NIST, CIS, PCI DSS, OWASP, and SOC 2 • Prior software development or secure architecture experience, including reasoning about production code across multiple languages (nice-to-have) • Research, publication, or deep practitioner background in adversarial machine learning, LLM security, or voice/audio deepfake detection (nice-to-have) • Relevant certifications such as OSCP, GPEN, GWAPT, GXPN, CEH, or equivalent (nice-to-have) • Prior experience in voice biometrics, AI security, fraud prevention, or similarly high-risk product environments (nice-to-have)

🏖️ Benefícios

• Competitive compensation package, including RSUs (Restricted Stock Units) for all employees • Remote-first environment, providing flexibility and autonomy • Regular team on-sites, company-wide events, and intentional gatherings • Unlimited Paid Time Off (PTO) • Generous health and welfare plans, including one employer-paid employee-only plan • Best-in-class Health Savings Account (HSA) employer contribution • Low-cost vision and dental plans for employees and families • Paid Parental Leave for birth, adoptive, and foster parents • One year of diaper delivery for a newest family addition • Recurring monthly phone and internet allowance • Enhanced fertility and GLP-1 benefits • Annual Learning & Development stipend for professional growth, skill-building, certifications, and continued education

Candidatar-se

Vagas Similares

🕒 Julho 1

ICF

5001 - 10000

🏥 Saúde

📦 Logística

📣 Marketing

Security Engineer securing environments and applications to meet Federal Security Standards for ICF. Requires five years of experience and a Bachelor's degree, based in the U.S.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $98.614 - $167.644 / ano

💰 $30.000.000 Grant em 2021-03

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 1

Arch Capital Group Ltd.

5001 - 10000

💼 Consultoria

📦 Logística

🛡️ Seguros

Senior Security Engineer developing and deploying AI-driven security capabilities. Leading investigations and enhancing security automation and threat detection for enterprise systems.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 1

ThedaCare

5001 - 10000

💼 Consultoria

🛡️ Seguros

🏥 Saúde

Cyber Security Engineer improving visibility and response to security threats in a healthcare environment. Leading incident response and enhancing security protocols with IT teams.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 30

LTS

1001 - 5000

🏥 Saúde

💼 Consultoria

📦 Logística

Cyber Security Engineer supporting cybersecurity engineering within Department of Veterans Affairs. Securing cloud environments and ensuring compliance with federal regulations.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 30

Vytalize Health

201 - 500

🏥 Saúde

☁️ SaaS

⚕️ Seguro de Saúde

Information Security Engineer responsible for protecting healthcare data by designing security mechanisms and assessing risks. Collaborating with teams on risk assessments and security audits.

🇺🇸 Estados Unidos – Remoto (EUA)

💰 $100.000.000 Series C - Vytalize Health em 2023-02

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório