Senior Security Researcher – Red Team

🕒 il y a 2 mois

🇺🇸 États-Unis – Télétravail

💵 $125 000 - $165 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

👻 Score fantôme 21%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Pindrop

Pindrop

201 - 500 employés

Fondée en 2011

🛡️ Assurance

💼 Conseil

🏥 Santé

Insurance • Consulting • Healthcare

Pindrop est un leader en authentification vocale et détection de la fraude, offrant des solutions innovantes pour améliorer la sécurité des communications vocales. L'entreprise utilise des technologies avancées telles que la détection de vivacité, l'analyse comportementale et la biométrie vocale pour combattre les menaces telles que les deepfakes et usurpations dans divers secteurs, y compris la banque, la finance, l'assurance, et le commerce de détail. Pindrop s'intègre avec des plateformes comme Five9 pour fournir une authentification multifactorielle, garantissant à la fois la protection des informations sensibles et une expérience utilisateur fluide. En mettant l'accent sur la sécurisation des centres d'appels et des appareils intelligents, Pindrop aide les entreprises à prévenir la fraude et améliorer les interactions avec les clients en exploitant des technologies audio, vocales et d'IA de pointe. Leurs solutions sont approuvées par certains des plus grands établissements financiers et compagnies d'assurance au monde.

Description

• Design and execute red team operations against GenAI systems, LLM pipelines, RAG architectures, autonomous agents, APIs, SaaS products, and cloud environments • Conduct adversarial testing for prompt injection, indirect prompt attacks, jailbreaking, model extraction, training-data poisoning, data leakage, inference abuse, and unauthorized output manipulation • Use deepfake generation, voice synthesis, and spoofing techniques to test voice authentication and deepfake detection capabilities • Develop attack chains combining GenAI vulnerabilities with infrastructure, application, identity, and API weaknesses • Plan and execute penetration tests and support bug bounty efforts across web applications, APIs, SaaS products, and AWS/GCP environments • Perform architecture reviews, security code reviews, and threat modeling focused on AI/ML components and LLM-facing services • Build automation for offensive security workflows, testing, compliance checks, alerting, and reporting using Python or similar scripting languages • Partner with SecOps and security engineering to improve detections, response workflows, remediation, and defensive improvements • Monitor GenAI security research, adversarial ML techniques, threat intelligence, and regulatory developments and apply insights to Pindrop’s security program

🎯 Exigences

• 3+ years of hands-on penetration testing and red team experience across SaaS applications, cloud infrastructure, APIs, and web applications • Demonstrable experience attacking GenAI or LLM-based systems, including prompt injection, jailbreaking, indirect prompt attacks, model extraction, or adversarial input generation • Hands-on experience with deepfake tools, voice synthesis, or audio/visual spoofing technologies in an offensive or research context • Strong proficiency with offensive security tooling such as Burp Suite, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, or equivalent frameworks • Experience configuring and operating SAST and DAST tools and integrating them into CI/CD pipelines • Proficiency in at least one scripting or programming language; Python strongly preferred • Familiarity with AI-specialized security tools or frameworks such as Garak, PyRIT, Claude Security, or similar adversarial ML tooling • Strong understanding of cloud security architecture, container security, API security, and security standards including ISO 27001/27002, NIST, CIS, PCI DSS, OWASP, and SOC 2 • Prior software development or secure architecture experience, including reasoning about production code across multiple languages (nice-to-have) • Research, publication, or deep practitioner background in adversarial machine learning, LLM security, or voice/audio deepfake detection (nice-to-have) • Relevant certifications such as OSCP, GPEN, GWAPT, GXPN, CEH, or equivalent (nice-to-have) • Prior experience in voice biometrics, AI security, fraud prevention, or similarly high-risk product environments (nice-to-have)

🏖️ Avantages

• Competitive compensation package, including RSUs (Restricted Stock Units) for all employees • Remote-first environment, providing flexibility and autonomy • Regular team on-sites, company-wide events, and intentional gatherings • Unlimited Paid Time Off (PTO) • Generous health and welfare plans, including one employer-paid employee-only plan • Best-in-class Health Savings Account (HSA) employer contribution • Low-cost vision and dental plans for employees and families • Paid Parental Leave for birth, adoptive, and foster parents • One year of diaper delivery for a newest family addition • Recurring monthly phone and internet allowance • Enhanced fertility and GLP-1 benefits • Annual Learning & Development stipend for professional growth, skill-building, certifications, and continued education

Postuler Maintenant

Emplois Similaires

🕒 il y a 2 mois

ICF

5001 - 10000

🏥 Santé

📦 Logistique

📣 Marketing

Security Engineer securing environments and applications to meet Federal Security Standards for ICF. Requires five years of experience and a Bachelor's degree, based in the U.S.

🇺🇸 États-Unis – Télétravail

💵 $98 614 - $167 644 / an

💰 €30 000 000 Grant en 2021-03

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Arch Capital Group Ltd.

5001 - 10000

💼 Conseil

📦 Logistique

🛡️ Assurance

Senior Security Engineer developing and deploying AI-driven security capabilities. Leading investigations and enhancing security automation and threat detection for enterprise systems.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

ThedaCare

5001 - 10000

💼 Conseil

🛡️ Assurance

🏥 Santé

Cyber Security Engineer improving visibility and response to security threats in a healthcare environment. Leading incident response and enhancing security protocols with IT teams.

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

Python

🕒 il y a 2 mois

LTS

1001 - 5000

🏥 Santé

💼 Conseil

📦 Logistique

Cyber Security Engineer supporting cybersecurity engineering within Department of Veterans Affairs. Securing cloud environments and ensuring compliance with federal regulations.

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Vytalize Health

201 - 500

🏥 Santé

☁️ SaaS

⚕️ Assurance santé

Information Security Engineer responsible for protecting healthcare data by designing security mechanisms and assessing risks. Collaborating with teams on risk assessments and security audits.

🇺🇸 États-Unis – Télétravail

💰 €100 000 000 Series C - Vytalize Health en 2023-02

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis