Red Team Engineer/ Offensive Security Lead

4 weeks, 1 day ago
Full-time
Senior
Cybersecurity
Authentic8

Authentic8

Authentic8 provides a secure and anonymous online investigation platform, Silo, that allows users to conduct investigations without revealing their identity or intent. With complete control over web browsing and third-party apps, Authentic8 ensures dat...

IT Services
51-250
Founded 2010

Description

  • Design, build, and operate an AI-augmented red teaming harness using frontier LLM APIs.
  • Implement a control loop architecture for autonomous and semi-autonomous vulnerability discovery.
  • Integrate the harness with SBOM tooling, CVE monitoring feeds, and CI/CD pipeline security tools.
  • Conduct adversarial testing across internal and external attack perspectives.
  • Chain findings to identify exploitable paths and corresponding vulnerabilities.
  • Validate and prioritize findings using CVSS, EPSS, and KEV context before handoff to patch management.
  • Support the development and day-to-day operation of the internal Bug Bounty Program.
  • Collaborate with engineering on custom mitigation decisions when vendor patches are unavailable.
  • Own security stage-gates within the CI/CD pipeline and integrate security findings into the build process.
  • Partner with DevSecOps, SOC, and security leadership on harness architecture, monitoring, prioritization, and reporting.

Requirements

  • 5+ years of experience in cybersecurity, penetration testing, or red team operations.
  • Demonstrated experience building tools, such as scripting exploits, automating workflows, or constructing test harnesses.
  • Python and/or Go experience strongly preferred.
  • Hands-on experience with LLM APIs in a security or agent context.
  • Understanding of tool use, control loops, and context management in agent architectures.
  • Proficiency with static and dynamic analysis (SAST/DAST) and ability to interpret and chain automated findings.
  • Working knowledge of CVE and vulnerability data sources, including NVD, EPSS, KEV, OSV.dev, and the GitHub Advisory Database.
  • Experience testing cloud-hosted SaaS platforms, with GCP familiarity preferred.
  • Familiarity with container security and Linux-based infrastructure.
  • Ability to work independently, manage scope, and deliver against milestones.
  • Excellent documentation and communication skills.
  • Must be a US citizen.
  • Experience with frontier AI model platforms in an agentic context strongly desired.
  • OSCP, GXPN, GPEN, or equivalent offensive security certification strongly desired.
  • Experience with SBOM tooling and software composition analysis strongly desired.
  • Familiarity with CI/CD pipeline security tooling such as Snyk and SonarQube strongly desired.
  • Experience with infrastructure-as-code or configuration management security, with Chef/InSpec as a plus, strongly desired.
  • Bug bounty program operations experience on platforms such as HackerOne or Bugcrowd strongly desired.

Benefits

  • Salary range of $150,000 to $175,000, depending on location, skills, experience, and education or training.
  • Medical, dental, and vision insurance.
  • Flexible PTO.
  • 401(k) program.
  • Stock options.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Grupo QuintoAndar | Information Security Manager - GRC

QuintoAndar 1K-5K Real Estate

Grupo QuintoAndar is hiring a Manager of Information Security, GRC to lead cyber governance, risk, and compliance efforts that enable safe, scalable business growth across a cloud-native, multinational environment.

Cybersecurity
8 hours, 30 minutes ago

Vulnerability Researchers / Security Researchers

SevenPro 51-250 Internet Software & Services

Barcelona-based R&D center is hiring a Vulnerability Researcher / Security Researcher to perform hands-on research, exploitation, and validation of vulnerabilities in complex software systems.

Android Embedded Systems iOS Linux macOS
1 day, 9 hours ago

Principal Consultant - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring a Principal, Consultant to lead complex multi-discipline project delivery, provide technical leadership, and strengthen discipline standards and client relationships.

Agile Asana GitHub
2 days, 8 hours ago

Senior Security Researcher

Cobalt 251-1K Internet Software & Services

Cobalt.io is hiring a Senior Security Researcher to lead advanced vulnerability research and offensive security assessments across modern software, cloud, and enterprise environments.

AWS Azure Bash Docker GCP Go Java Kubernetes Linux macOS Node.js Python Rust
3 days, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers