Source Job

$235,000–$275,000/yr
Global

  • Break AI and agentic systems and turn research into automated, repeatable attacks for NodeZero.
  • Design and execute prompt injection, defense evasion, and tool-use exploitation against AI infrastructure.
  • Build and extend LLM-powered applications and microservices, focusing on production safety and reliability.

Python Penetration Testing Offensive Security Threat Modeling

20 jobs similar to Staff Attack Engineer

Jobs ranked by similarity.

US Unlimited PTO

  • Lead security assessments of AI/ML models, data pipelines, and AI-enabled applications, identifying vulnerabilities such as prompt injection, model inversion, data poisoning, and adversarial inputs.
  • Partner with Data & Analytics and Engineering to embed security requirements and threat modeling into the AI development lifecycle, from data collection through model deployment.
  • Build and maintain guardrails, monitoring, and detection controls for AI systems in production, flagging anomalous model behavior and unauthorized data access.

Interra Health is a healthcare technology company that helps providers and patients navigate the prescription journey. It is a fast-growing, mission-driven team of about 100 employees, formed through the merger of DoseSpot, Arrive Health, and pVerify, and focused on reducing friction and improving access to medications.

US

  • Craft creative prompts and multi-turn scenarios to stress-test AI guardrails across diverse risk categories.
  • Discover ways around safety filters and restrictions using jailbreak, evasion, and prompt injection techniques.
  • Evaluate and score model responses against structured harm taxonomies and severity rubrics.

Handshake AI partners with leading AI research labs to make models safer and more robust. Our red teaming operations help identify vulnerabilities before they reach users, contributing directly to the responsible development of frontier AI systems.

$204,000–$290,000/yr
US Unlimited PTO

  • Lead Affirm's enterprise AI security review process, evaluating architecture, data flows, and design of AI tools and agentic systems.
  • Threat model AI/LLM systems for risks like prompt injection, insecure output handling, and data poisoning, and drive remediation.
  • Build security guardrails, tooling, and policy-as-code to automate AI security and support cross-functional initiatives.

Affirm is a financial technology company that offers clear, predictable point-of-sale installment loans with no hidden fees. The company is remote-first and values transparency, care, and flexibility, with a focus on building a diverse and inclusive team.

US 4w PTO 12w maternity 4w paternity

  • Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
  • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.

Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.

Global 6w PTO 26w maternity 26w paternity

  • Lead security reviews of architecture, code, and security-sensitive changes.
  • Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
  • Threat model new capabilities and build scalable guardrails that reduce recurring risks.

Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.

US Unlimited PTO

  • Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
  • Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
  • Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.

$235,000–$305,000/yr
US 4w PTO 12w maternity 12w paternity

  • Lead threat modeling and security architecture for AI-enabled systems, including LLM applications and cloud-native platforms.
  • Define and implement secure engineering patterns and guardrails across AWS infrastructure, CI/CD pipelines, and third-party integrations.
  • Partner with engineering and security teams to embed security throughout the AI product lifecycle and drive cross-functional security initiatives.

Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions for State Farm and HiRoad. We are a wholly owned subsidiary of State Farm with a remote-first culture that values inclusion and positive team dynamics.

$157,675–$238,500/yr
US

  • Deliver accurate security assessments of software, code, and firmware, evaluating resilience against AI-driven attacks.
  • Build and pressure-test novel AI-enabled security tooling and workflows, then drive adoption across the security org.
  • Partner cross-functionally to define and drive Samsara's medium- and long-term AI security strategy.

Samsara provides a Connected Operations Cloud platform that helps organizations improve safety, efficiency, and sustainability of physical operations. As a publicly traded company, they foster a culture of rapid career development and hyper growth, with a high-caliber team.

$230,000–$322,000/yr
US

  • Lead the development and optimization of machine learning models to detect and prevent AI security risks like prompt injection and jailbreaks.
  • Build reproducible training and evaluation pipelines on Reddit's ML platform, partnering with platform engineers to improve performance and reliability.
  • Set the technical vision and multi-quarter modeling roadmap, mentoring engineers and establishing best practices for responsible ML development.

Reddit is a community of communities, built on shared interests and authentic conversations, with 100,000+ active communities and 130 million daily active visitors. It is one of the internet's largest sources of information, fostering a culture of openness and trust.

$100,000–$300,000/yr
US

  • Shape the Cogent product at the frontier of AI and cybersecurity, working hand-in-hand with ML engineers.
  • Build the world's first AI-native cybersecurity organization, extending security posture and incident response.
  • Educate the market and elevate the industry through thought leadership and customer partnerships.

Cogent is an applied AI lab building next-generation AI agents for cybersecurity. The company is a rapidly growing startup backed by Greylock, with a team of experts from top universities and companies, fostering a culture of cutting-edge research and real-world execution.

$128,369–$183,384/yr
Europe

  • Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
  • Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
  • Build offensive tooling, develop exploits, and support incident response and security education.

Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.

Global

  • Apply your cybersecurity expertise to train next-generation AI systems with real-world input.
  • Analyze, debug, and resolve software bugs and vulnerabilities across diverse codebases.
  • Perform security audits, penetration testing, and contribute to backend development.

Our client is a venture-backed AI company developing intelligent systems via human expertise and machine learning. They are rapidly growing with over $40 million in funding and a global network of experts.

Global 4w PTO

  • Perform weekly code reviews to catch security vulnerabilities before they ship.
  • Coordinate external security audits and penetration tests, and track remediation.
  • Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.

EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.

US

  • Design and develop AI-powered applications using LLMs, Generative AI, and Machine Learning.
  • Build AI Copilots, AI Agents, and RAG solutions to improve software engineering and operational workflows.
  • Integrate AI capabilities into enterprise applications, APIs, Azure cloud services, and DevSecOps pipelines.

Planned Systems International (PSI) is a technology solutions provider specializing in IT services for government agencies. They foster a collaborative culture focused on innovation and professional growth.

US

  • Collaborate with client teams to diagnose operational bottlenecks and develop testable hypotheses.
  • Build and test AI-powered prototypes using coding agents like Claude Code or Cursor.
  • Drive adoption by working directly with users and iterating on solutions until they are effective in live workflows.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The platform uses AI to review applications and provide a shortlist to employers, emphasizing efficiency and objectivity.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Plan and execute realistic adversary simulations using threat intelligence to assess security and detection capabilities.
  • Hunt for vulnerabilities across AI systems, payment infrastructure, autonomous delivery hardware, and emerging technologies.
  • Build custom tools, exploits, and payloads tailored to DoorDash's tech stack and partner with Blue Teams.

DoorDash is a technology and logistics company that empowers local economies by enabling door-to-door delivery for consumers, merchants, and Dashers. The company is growing rapidly and constantly changing, with a culture focused on empathy, diversity, and employee well-being.

Global

  • Develop and deploy cutting-edge AI/ML solutions to enhance the platform and improve student learning experiences.
  • Design, develop, and optimize LLM-powered agentic systems and APIs for real product use cases.
  • Collaborate with senior engineers and contribute to evaluation frameworks and MLOps pipelines.

Interview Kickstart specializes in interview preparation and career transitions into high-demand tech fields like AI, ML, and Data Science. Over 17,000 tech professionals have been guided by current and former hiring managers to land coveted positions at companies like Google and Amazon.

  • Own vulnerability management across code, dependencies, images, and cloud config, automating triage and remediation.
  • Build and expand security gates in CI/CD pipelines, define secure cloud baselines, and drive least privilege identity.
  • Partner with DevOps on paved roads for secure-by-default development and lead incident response.

Aegis AI is a startup founded by ex-Google engineers who built Safe Browsing and reCAPTCHA, focused on stopping adversarial AI attacks. The team is flat, flexible, and fast, with engineers owning decisions and clear KPIs.

$140,000–$160,000/yr
US

  • Design and maintain secure architectures across AWS, Azure, and GCP with infrastructure-as-code and policy-as-code enforcement.
  • Secure AI/ML pipelines and LLM applications, addressing OWASP Top 10 for LLMs and implementing guardrails and content-filtering controls.
  • Drive security operations, including SIEM monitoring, incident response, and supporting HIPAA/HITRUST/SOC 2 compliance.

Reveleer delivers a unified platform for risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations in value-based care. Trusted by 80+ customer organizations nationwide, the company fosters a collaborative, compliance-focused culture with transparent, human-in-the-loop AI at its core.

US 4w PTO

  • Own the technical direction of a product area, defining how teams specify, delegate, and verify agentic work.
  • Set standards for specification quality, verification, and security architecture to keep AI-generated work safe at scale.
  • Mentor engineers across teams and drive large-scale initiatives combining human and agentic contributors.

BambooHR builds a people intelligence platform that transforms HR for small and mid-sized businesses. The company is a values-driven market leader with a culture that champions growth, flexibility, and meaningful work.