Senior Offensive AI Security Engineer

Zoom
•$124,000 - $271,200•Remote

About The Position

This role sits at the intersection of offensive security and applied AI, focused on surfacing critical risks across Zoom's products, applications, services, and infrastructure before they become incidents. Day to day, you will combine deep target knowledge, threat analysis, and cutting edge models to form hypotheses about where complex systems are likely to fail, validate exploitability, and trace attack paths that standard testing would miss. This is not a vulnerability-scanning or prompt-engineering role: a strong hands-on research craft is the foundation, and success is measured by whether your findings change how Zoom understands its risk, not by finding volume. Research directions are chosen in collaboration with the Security Assurance teams (Offensive Security, Vulnerability Management, Bug Bounty, PSIRT), but most work is self-directed, with high autonomy and no predetermined outcome.

Requirements

  • 5+ years of hands-on vulnerability research, offensive security, application security, or penetration testing, with a demonstrated track record of choosing targets, forming and revising hypotheses, and establishing exploitability and impact in complex software or production systems.
  • Hands-on experience running offensive workflows with frontier and open-weight models, including model selection where refusal behavior would otherwise block legitimate exploit development.
  • Experience assessing the quality of AI-driven research processes, including identifying false positives, missed vulnerabilities, unstable results, and reproducibility gaps, as well as sound judgment on agent architecture trade-offs: when constrained, orchestrated pipelines deliver reproducible results and when open-ended tool-using agents are worth the nondeterminism.
  • Deep technical expertise in at least one security domain: web applications and APIs, Java applications, cloud or service infrastructure, client software, operating systems, or reverse engineering.
  • Strong programming and debugging skills: ability to read unfamiliar code, build research tooling, write proofs of concept, and trace behavior across system boundaries.
  • Strong intuition for attack surfaces, trust boundaries, exploitability, and security impact, combined with the persistence to work independently on open-ended research with no guaranteed path or outcome.
  • Ability to communicate findings clearly to both technical and nontechnical audiences, covering what the evidence shows, what remains uncertain, and why it matters.

Responsibilities

  • Leverage AI to conduct vulnerability research across Zoom's products, applications, services, and infrastructure, with a focus on high-impact issues, subtle vulnerabilities, confirmed exploitability, and attack paths that cross component and trust boundaries.
  • Use experience, threat analysis, architecture knowledge, source code, and observed system behavior to choose targets and guide investigations.
  • Apply frontier and open-weight models, agents, and other AI capabilities across the research lifecycle: reconnaissance, code analysis, hypothesis generation, exploit development, and verification.
  • Design and tune research harnesses that give models the right context, tools, execution environments, and feedback to investigate real targets.
  • Develop custom tooling, including analysis utilities, fuzzers, agents, test harnesses, proofs of concept, and full exploits, when it helps answer the research question.
  • Convert promising model output into defensible security evidence: reproduce findings, rule out false claims, establish preconditions, and distinguish a possible weakness from a demonstrated vulnerability with real impact.
  • Improve the reliability and reach of AI-driven research by tackling false positives, false negatives, context limits, nondeterminism, and reproducibility.
  • Work directly with Engineering and Product Security to communicate findings, support remediation, surface related risks, and verify fixes.
  • Share tools, techniques, and lessons learned so Security Assurance and the broader Security org can enhance their processes through the use of AI.

Benefits

  • bonus
  • equity value
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service