← Back to list
Job · Principal

Member of Technical Staff (Offensive Security Engineer)

Security Engineer • Principal • Hybrid • Full-time United States San Francisco, USA

Perplexity is seeking a highly skilled, hands-on Offensive Security Engineer to join its security team, taking an adversarial approach to hardening infrastructure, applications, and AI systems.

Responsibilities

  • Plan and execute red/purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces
  • Conduct continuous penetration testing of web apps, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services
  • Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries
  • Develop and maintain custom offensive tooling, exploits, and automation
  • Perform open-scope adversary simulations testing detection and response end to end, working closely with the defensive security team
  • Drive threat modeling sessions with engineering teams to identify attack vectors in new features and architectures
  • Deliver clear, actionable findings to technical and executive audiences
  • Contribute to CI/CD, supply chain, and secrets management security through offensive assessment
  • Stay current on emerging attack techniques and adversary tradecraft

Requirements

  • 5+ years hands-on experience in offensive security, red teaming, or penetration testing
  • Deep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes/container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline security
  • Track record of discovering impactful vulnerabilities or developing novel attack techniques in production
  • Strong programming/scripting skills in Python, Go, or similar, comfortable writing custom tooling and exploits
  • Experience with industry-standard offensive tools (Burp Suite, Cobalt Strike/Sliver/Mythic, Metasploit, BloodHound, nuclei, etc.) and beyond
  • Excellent written and verbal communication, translating technical findings into risk narratives
  • Experience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilities

Nice to have

  • Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributions

Soft skills

Excellent written and verbal communicationCross-team collaborationStructured, calm approach under pressure

Similar jobs