Offensive Security Engineer

Replit Replit · Enterprise · Foster City, CA · Hybrid · IT

Seeking a senior Offensive Security Engineer to act as an "adversary-in-residence" for Replit's cloud-native platform. This role involves leading whitebox penetration testing, simulating adversarial attacks on AI-integrated systems, and building offensive tooling, including AI-assisted tools. The focus is on ensuring the security of Replit's AI-enabled development environment.

What you'd actually do

  1. Lead Whitebox Penetration Testing: Execute end-to-end testing with full access to source code. You will perform manual code-level inspections to uncover complex logic flaws and authorization bypasses that automated tools miss.
  2. Simulate Adversarial Attacks: Conduct Red and Purple team engagements across our cloud-native stack (K8s, Docker), simulating how a sophisticated actor might move from a code-level exploit to infrastructure-wide impact.
  3. Secure AI-Enabled Systems: Perform offensive testing on LLM-backed applications and agentic AI workflows, focusing on prompt injection, data leakage, and abuse of AI-driven components.
  4. Vulnerability Research & Chaining: Identify, exploit, and demonstrate realistic business risk by chaining vulnerabilities—from the application layer down through our internal trust boundaries.
  5. Build Offensive Tooling: Contribute to internal security frameworks and build AI-assisted testing tools to automate the discovery of common bug classes while maintaining deep manual testing depth.

Skills

Required

  • 7+ years of hands-on experience in penetration testing, offensive security, or vulnerability research
  • Ability to navigate large codebases and deep understanding of modern application architectures and secure coding pitfalls
  • Comfortable in a cloud-native environment (Kubernetes, Docker, hybrid cloud infrastructure)
  • Strong proficiency in Go, Python, or TypeScript
  • Proven track record of manual exploitation beyond automated scanners
  • Ability to translate complex code-level exploits into clear narratives

Nice to have

  • Public recognition on platforms like HackerOne or Bugcrowd
  • Experience building or extending AI-based security testing tools
  • Background in incident response or detection engineering
  • Published CVEs or security research in the cloud-native or AI space

What the JD emphasized

  • whitebox penetration testing
  • AI-assisted testing tools
  • agentic AI workflows

Other signals

  • AI-integrated development environment
  • AI-assisted testing tools
  • LLM-backed applications
  • agentic AI workflows