Staff Attack Engineer (AI/LLM)
Horizon3 · United States
About The Role
Join our team as a Staff Attack Engineer specializing in AI/LLM security. In this role, you will break AI and agentic systems and turn that research into automated attacks inside NodeZero, our autonomous pentesting platform. You will design and execute prompt injection and defense evasion attacks, conduct tool-use exploitation, target AI infrastructure, research and apply model and supply chain attacks, perform threat modeling for agentic systems, and apply a strong productization mindset. You will also build and extend LLM-powered applications and design with production concerns in mind. This is a remote position with numerous career advancement opportunities and a collaborative, innovative culture.
- Concevoir et exécuter des attaques d'injection de prompt et d'évasion de défense, en se concentrant sur des modèles généralisés et réutilisables.
- Casser les systèmes d'IA et agentiques et traduire cette recherche en modules d'attaque automatisés et répétables pour NodeZero.
- Effectuer la modélisation des menaces pour les systèmes agentiques, en cartographiant les frontières de confiance et les surfaces d'attaque.
- Proven ability to break AI/LLM and agentic systems
- Experience in a security product or offensive security team, ideally with shipped offensive capabilities or tooling
- Industry obsessed – tracks the fast-moving AI security landscape and can speak to recent developments, new attacks, and where the field is heading
- Solid penetration testing fundamentals and understanding of common attack chains
- Expert-level ownership – drives high-complexity, high-risk programs and sets strategy, not just execution
- Familiarity with AI/LLM security frameworks (e.g., OWASP Top 10 for LLMs, MITRE ATLAS)
- Expert-level Python and software engineering skills
- Self-motivated – identifies problems and builds solutions proactively
- Clear understanding of trust boundaries around AI tools, data sources, and permissions, and how to systematically test and exploit them
- Familiarity with graph databases (e.g., Neo4j)
- CTF experience, particularly in AI/ML-focused challenge categories
- Contributions to AI security research (blog posts, conference talks, CVEs, open-source tools)
- Experience with other cloud AI services (e.g., Azure OpenAI, GCP Vertex AI)
- We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply
- Experience with AWS Bedrock and AWS Agent Core
- Background in traditional exploit development or vulnerability research
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring