About The Position

NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to push the frontier of AI-driven offensive security. We already run language model agents that audit source code and attack live web applications at fleet scale. These include multi-agent orchestration, adversarial verification, exploit-confirmation harnesses, and sandboxed execution. Your job is to make these agents meaningfully better attackers: new attack capabilities, new target classes, higher true-positive rates, and safer autonomy. This is a hands-on role for someone who is both a strong offensive security practitioner and a builder of agentic systems. Join us!

Requirements

  • Bachelor's degree or equivalent experience
  • 12+ years in security engineering, with at least 4 years in offensive security: penetration testing, red teaming, exploit development, or vulnerability research
  • Deep, hands-on exploitation skill in at least one domain (web application, cloud/Kubernetes, or systems/binary) — you can build and prove an exploit chain, not just run a scanner
  • Strong software engineering ability in Python; you ship production code, not just PoCs
  • Practical experience building with LLMs: agent frameworks, tool use/function calling, multi-agent orchestration, or coding agents (Claude Code, Codex CLI, or similar)
  • Sound judgment about autonomous offensive tooling — scoping, authorization, and blast-radius thinking are second nature
  • Respectful, responsible approach to offensive testing — we break things carefully and fix them fast

Nice To Haves

  • Published security research, CVEs, conference talks, or notable CTF results
  • Certifications like OSWE, OSEP, OSCP, or GXPN
  • Experience with SAST/DAST internals, fuzzing, or program analysis
  • Experience red-teaming AI systems themselves (prompt injection, jailbreaks, model evaluation) or contributing to AI-security research
  • Familiarity with Kubernetes/OpenShift, GitOps, and operating worker fleets at scale

Responsibilities

  • Crafting and building new red team agents: autonomous and semi-autonomous LLM agents that perform reconnaissance, hypothesis-driven exploitation, and evidence capture against NVIDIA-owned targets
  • Extending our existing agent harnesses (multi-phase orchestration, parallel specialist subagents, judge/verifier stages, out-of-band callback infrastructure) across multiple agent runtimes and model providers
  • Encoding real operator tradecraft into prompts, tools, and playbooks — web app exploitation, auth bypass, SSRF/deserialization chains, cloud and Kubernetes attack paths — so agents find what a skilled human would
  • Building the verification layer: exploit-confirmation harnesses that prove findings are real before a human ever sees them, driving false-positive rates down
  • Engineering the safety side of autonomy: sandboxing, scope enforcement, tool allowlists/blocklists, credential isolation, and prompt-injection defenses for agents operating with offensive capability
  • Evaluating and benchmarking frontier models for offensive tasks; partnering with our human red team to turn their engagements into repeatable agent capabilities
  • Mentoring engineers on the team and setting the technical bar for agentic offensive tooling

Benefits

  • Competitive salaries
  • Generous benefits package
  • Equity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service