About the role
Agents that call tools are an attack surface. You attack ours on purpose: prompt injection, tool abuse, data exfiltration through retrieval, and then help build the defences that hold.
What you’ll do
Red-team agents, tools and the model gateway continuously
Build automated adversarial test suites into CI
Review designs for injection and privilege-escalation paths
Run incident response when something real happens
What we need
4+ years in application or offensive securityPractical LLM attack experience, not just theoryStrong code review skills in Python or TypeScriptClear reporting to both engineers and executives
Nice to have
OSCP or equivalentPublished security researchThreat modelling for multi-tenant SaaS
How hiring works
1Intro call, 30 minutesWhat you have shipped, what you want next, and an honest picture of where we are as a company.
2Working sessionA real problem from our backlog, discussed or built together. No whiteboard algorithm puzzles.
3Team conversationsTwo calls with the people you would work with daily, across both regions.
4Offer within a weekDecision and written offer inside five working days of the last call, references in parallel.
Ready to apply?
Send a CV or a link to something you’ve shipped. A short note on why this role beats a paragraph of cover letter.