About the job
Join Perplexity, a pioneering organization at the forefront of AI and technology, as we seek a talented and proactive Offensive Security Engineer. In this critical role, you will be part of our innovative security team, adopting an adversarial mindset to fortify our infrastructure, applications, and AI systems. Your expertise will drive red team operations, penetration tests, and attack simulations across various environments—including our cloud infrastructure, web, and mobile applications. You will actively identify vulnerabilities before they can be exploited by adversaries, collaborating closely with engineering teams to implement effective remediations.
Key Responsibilities
Plan and execute red and purple team engagements, simulating advanced threat actors across our cloud services (AWS, Kubernetes), endpoints, and application surfaces.
Conduct thorough and ongoing penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services.
Evaluate AI/ML-specific attack surfaces, tackling challenges such as prompt injection, model exfiltration, agent abuse, tool exploitation, and security boundaries of MCP.
Develop and maintain custom offensive security tools, exploits, and automation to enhance the efficiency and scope of security testing.
Perform open-scope adversary simulations to test detection and response capabilities, working closely with the defensive security team.
Lead threat modeling sessions with engineering teams to identify and prioritize potential attack vectors in new features and architectures.
Provide clear and actionable insights to both technical and executive audiences, collaborating with engineering teams to validate remediation efforts.
Contribute to securing CI/CD pipelines, ensuring supply chain integrity, and managing secrets through offensive assessments.
Remain informed about emerging attack techniques, vulnerability research, and adversarial tactics, bringing fresh insights to Perplexity's security strategy.

