Security Research Engineer, AI Safety and Security Engineering
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 6
LLM @ 3
Python @ 6
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA's AI Safety & Security Engineering team builds and evaluates AI-powered tooling that finds, validates, and patches software vulnerabilities. The team is seeking a Security Research Engineer to advance its Validate and Patch capabilities by establishing what constitutes a confirmed vulnerability and a correct, safe fix for NVIDIA-internal targets.
Validation requires confirming that vulnerability reports are real and reachable rather than noise. Patching requires ensuring that fixes repair flaws, preserve existing behavior, and withstand strict revalidation. The role involves working with harness and evaluation engineers to establish engineering standards, document reasoning for independent security reviews, and ensure methods run reliably with fully traceable evidence. AI-assisted workflows are integral to the role, alongside disciplined skepticism about their outputs.
Responsibilities
- Develop validation techniques that confirm vulnerabilities are real and reachable.
- Advance approaches for generating and verifying safe fixes.
- Define correctness, regression, and revalidation standards with reviewers.
- Conduct applied research on bounded vulnerability classes against internal targets.
- Help determine which vulnerability classes the team should address next.
- Establish repeatable methods and high engineering standards for trustworthy patching.
Requirements
- Bachelor's degree or equivalent experience.
- 12 or more years of experience in security research or software engineering.
- Hands-on experience with vulnerability research, fuzzing, program analysis, or secure development.
- Proficiency in C, C++, or Python.
- Strong understanding of what makes a fix correct and safe, including regression prevention and behavior preservation.
- Comfort using AI-assisted tools for analysis and development.
Preferred Qualifications
- Public vulnerability research, including CVEs, advisories, or publications.
- Experience building or extending fuzzers, static analyzers, or symbolic-execution tools.
- Familiarity with LLM-based coding or analysis agents.
Benefits
- Competitive salary.
- Equity.
- Benefits package.
- NVIDIA is committed to fostering an inclusive work environment and is an equal opportunity employer.
Applications will be accepted at least until August 2, 2026. This posting is for an existing vacancy. NVIDIA uses AI tools in its recruiting processes.