Security Research Engineer, Ai Safety And Security Engineering
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
LLM @ 2
Machine Learning
Python @ 3
Security @ 5
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA’s AI Safety & Security Engineering team builds and evaluates AI-powered tooling that finds, validates, and patches software vulnerabilities. The team is seeking a Security Research Engineer to advance Validate and Patch capabilities by establishing what counts as a confirmed vulnerability and defining what constitutes a truly correct, safe fix.
In this critical role, you will apply rigorous security judgment to well-defined categories of vulnerabilities affecting NVIDIA-internal targets. You will turn complex analysis into repeatable methods that improve software people rely on daily.
Validation requires confirming reports are real and reachable rather than noise; patching requires ensuring fixes repair flaws, protect existing behavior, and hold up under strict revalidation. Working alongside harness and evaluation engineers, you will establish high engineering standards, document your reasoning for independent security reviews, and ensure your methods run reliably with fully traceable evidence. AI-assisted workflows are integral, but maintaining disciplined skepticism about their outputs is also required. Beyond immediate fixes, your work will teach the program what trustworthy patching looks like while helping decide which vulnerability classes to tackle next.
Responsibilities
- Validation methods: Develop techniques that confirm vulnerabilities are real and reachable.
- Patch methods: Advance approaches for generating and verifying safe fixes.
- Quality standards: Define correctness, regression, and revalidation standards with reviewers.
- Applied research: Work bounded vulnerability classes against internal targets.
Requirements
- Bachelor’s degree (or equivalent experience) with 5+ years in security research or software engineering.
- Security foundations: Hands-on vulnerability research, fuzzing, program analysis, or secure development in C, C++, or Python.
- Fix quality: Rigor about what makes a fix correct and safe, including regression and behavior preservation.
- AI-assisted workflows: Comfort using AI-assisted tools for analysis and development.
Ways to Stand Out from the Crowd
- Public research: CVEs, advisories, or publications in vulnerability research.
- Analysis tooling: Experience building or extending fuzzers, static analyzers, or symbolic-execution tools.
- Agentic ML: Familiarity with LLM-based coding or analysis agents.
Compensation and Other Details
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 152,000 USD - 241,500 USD. You will also be eligible for equity and benefits.