Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Audit
Claude Code @ 4
Codex @ 4
Kubernetes @ 7
LLM
OpenShift @ 3
Python @ 7
Scoping @ 6
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA's Product Security organization is looking for a Senior Offensive Security Engineer to advance AI-driven offensive security. The team operates language model agents that audit source code and attack live web applications at fleet scale, using multi-agent orchestration, adversarial verification, exploit-confirmation harnesses, and sandboxed execution. This role focuses on improving these agents' attack capabilities, target coverage, true-positive rates, and safe autonomy.
Responsibilities
- Build new red team agents, including autonomous and semi-autonomous LLM agents for reconnaissance, hypothesis-driven exploitation, and evidence capture against NVIDIA-owned targets.
- Extend agent harnesses with multi-phase orchestration, parallel specialist subagents, judge and verifier stages, and out-of-band callback infrastructure across multiple agent runtimes and model providers.
- Encode offensive security tradecraft into prompts, tools, and playbooks, including web application exploitation, authentication bypass, SSRF and deserialization chains, and cloud and Kubernetes attack paths.
- Build exploit-confirmation harnesses that verify findings before human review and reduce false-positive rates.
- Engineer safety controls for autonomous offensive tooling, including sandboxing, scope enforcement, tool allowlists and blocklists, credential isolation, and prompt-injection defenses.
- Evaluate and benchmark frontier models for offensive security tasks.
- Partner with human red teams to turn security engagements into repeatable agent capabilities.
- Mentor engineers and set the technical standard for agentic offensive tooling.
Requirements
- Bachelor's degree or equivalent experience.
- 12 or more years of experience in security engineering, including at least 4 years in offensive security, penetration testing, red teaming, exploit development, or vulnerability research.
- Deep, hands-on exploitation experience in at least one domain: web applications, cloud and Kubernetes, or systems and binary security.
- Ability to build and prove exploit chains rather than simply operate scanners.
- Strong Python software engineering skills, including production code development.
- Practical experience building with LLMs, including agent frameworks, tool use and function calling, multi-agent orchestration, or coding agents such as Claude Code or Codex CLI.
- Sound judgment regarding autonomous offensive tooling, including scoping, authorization, and blast-radius considerations.
- A respectful and responsible approach to offensive testing.
Preferred Qualifications
- Published security research, CVEs, conference talks, or notable CTF results.
- Certifications such as OSWE, OSEP, OSCP, or GXPN.
- Experience with SAST and DAST internals, fuzzing, or program analysis.
- Experience red-teaming AI systems, including prompt injection, jailbreaks, and model evaluation, or contributing to AI security research.
- Familiarity with Kubernetes, OpenShift, GitOps, and operating worker fleets at scale.
Compensation And Benefits
The base salary range is USD 224,000–356,500 for Level 5 and USD 272,000–431,250 for Level 6. Compensation is determined based on location, experience, and the pay of employees in similar positions. The role also includes eligibility for equity and benefits.
Applications will be accepted at least until September 6, 2026. This posting is for an existing vacancy. NVIDIA uses AI tools in its recruiting processes and is an equal opportunity employer.