Description
NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to push the frontier of AI-driven offensive security. We already run language model agents that audit source code and attack live web applications at fleet scale. These include multi-agent orchestration, adversarial verification, exploit-confirmation harnesses, and sandboxed execution. Your job is to make these agents meaningfully better attackers: new attack capabilities, new target classes, higher true-positive rates, and safer autonomy. This is a hands-on role for someone who is both a strong offensive security practitioner and a builder of agentic systems.
Responsibilities:
- Crafting and building new red team agents: autonomous and semi-autonomous LLM agents that perform reconnaissance, hypothesis-driven exploitation, and evidence capture against NVIDIA-owned targets
- Extending existing agent harnesses across multiple agent runtimes and model providers
- Encoding real operator tradecraft into prompts, tools, and playbooks , web app exploitation, auth bypass, SSRF/deserialization chains, cloud and Kubernetes attack paths , so agents find what a skilled human would
- Building the verification layer: exploit-confirmation harnesses that prove findings are real before a human ever sees them, driving false-positive rates down
- Engineering the safety side of autonomy: sandboxing, scope enforcement, tool allowlists/blocklists, credential isolation, and prompt-injection defenses for agents operating with offensive capability
- Evaluating and benchmarking frontier models for offensive tasks; partnering with our human red team to turn their engagements into repeatable agent capabilities
- Mentoring engineers on the team and setting the technical bar for agentic offensive tooling
Requirements:
- Bachelor's degree or equivalent experience
- 12+ years in security engineering, with at least 4 years in offensive security: penetration testing, red teaming, exploit development, or vulnerability research
- Deep, hands-on exploitation skill in at least one domain (web application, cloud/Kubernetes, or systems/binary) , you can build and prove an exploit chain, not just run a scanner
- Strong software engineering ability in Python; you ship production code, not just PoCs
- Practical experience building with LLMs: agent frameworks, tool use/function calling, multi-agent orchestration, or coding agents (Claude Code, Codex CLI, or similar)
- Sound judgment about autonomous offensive tooling , scoping, authorization, and blast-radius thinking are second nature
- Respectful, responsible approach to offensive testing , we break things carefully and fix them fast
Benefits:
- Competitive salaries
- Generous benefits package
- Equity eligibility
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://nvidia.wd5.myworkdayjobs.com/en-US/NVIDIAExternalCareerSite/job/US-CA-Remote/Senior-Offensive-Security-Engineer--Vulnerability-Operations_JR2024625