Member of Technical Staff (offensive Security Engineer)

Perplexity Perplexity · AI Frontier · San Francisco, CA · Security

The role focuses on offensive security for AI systems, including assessing AI/ML pipelines, prompt injection, model exfiltration, agent abuse, and tool-use exploitation. The engineer will plan and execute red team operations, penetration tests, and attack simulations across various systems, including AI/ML components, and develop custom offensive tooling. Experience with AI/ML systems and agentic workflows is required.

What you'd actually do

  1. Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries
  2. Plan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces
  3. Conduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services
  4. Develop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testing
  5. Deliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediations

Skills

Required

  • Python
  • Go
  • cloud security (AWS/GCP/Azure)
  • web/API application security
  • Kubernetes and container security
  • macOS/Linux endpoint security
  • network penetration testing
  • CI/CD pipeline security
  • offensive security
  • red teaming
  • penetration testing
  • AI/ML systems
  • LLM applications
  • agentic workflows

Nice to have

  • Published security research
  • conference talks (DEF CON, Black Hat, BSides)
  • CVE credits
  • meaningful bug bounty contributions

What the JD emphasized

  • AI/ML-specific attack surfaces
  • agentic workflows
  • AI/ML systems
  • LLM applications

Other signals

  • AI/ML pipeline security
  • AI/ML-specific attack surfaces
  • LLM applications
  • agentic workflows