Member of Technical Staff (Offensive Security Engineer)
Full Description
Perplexity is seeking a highly skilled, experienced and hands-on Offensive Security Engineer to join our dynamic security team, taking an adversarial approach to hardening Perplexity's infrastructure, applications, and AI systems. You'll plan and execute red team operations, penetration tests, and attack simulations across our cloud infrastructure, web and mobile applications, AI/ML pipeline, and corporate environment—finding real vulnerabilities before adversaries do and working directly with engineering teams to drive remediation. Responsibilities - Plan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces - Conduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services - Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries - Develop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testing - Perform open-scope adversary simulations that test detection and response capabilities end to end, collaborating closely with the defensive security team - Drive threat modeling sessions with engineering teams to identify and prioritize attack vectors in new features and architectures - Deliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediations - Contribute to the security of CI/CD pipelines, supply chain integrity, and secrets management through offensive assessment - Stay current on emerging attack techniques, vulnerability research, and adversary tradecraft; bring external perspective into Perplexity's security strategy Qualifications - 5+ years of hands-on experience in offensive security, red teaming, or penetration testing - Deep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes and container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline security - Track record of discovering impactful vulnerabilities or developing novel attack techniques in production environments - Strong programming and scripting skills in Python, Go, or similar languages; comfortable writing custom tooling and exploits - Experience with industry-standard offensive tools (Burp Suite, Cobalt Strike / Sliver / Mythic, Metasploit, BloodHound, nuclei, etc.) and ability to operate beyond them - Excellent written and verbal communication; able to translate complex technical findings into clear risk narratives - Experience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilities - Bonus: Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributions
Why This Role?
Anda akan bekerja dengan tim yang dinamis dan memiliki kesempatan untuk mengembangkan alat penyerangan khusus.
Key Responsibilities
- Rencanakan dan jalankan operasi red team dan purple team untuk menguji keamanan infrastruktur cloud, endpoint, dan aplikasi
- Lakukan uji penetrasi terus-menerus pada aplikasi web, API, klien mobile, ekstensi browser, dan infrastruktur cloud
- Evaluasi serangan yang spesifik untuk AI/ML seperti injeksi prompt, eksfiltrasi model, dan eksploitasi penggunaan alat
- Bangun dan perbarui alat penyerangan khusus, eksploitasi, dan otomatisasi untuk meningkatkan efisiensi uji keamanan
- Lakukan simulasi penyerangan terbuka untuk menguji kemampuan deteksi dan tanggapan
- Lakukan sesi modeling ancaman dengan tim engineering untuk mengidentifikasi dan memprioritaskan vektor serangan
Requirements
- Pernah bekerja di bidang offensive security, red teaming, atau penetration testing selama 5+ tahun
- Memiliki keahlian teknis dalam setidaknya dua bidang: keamanan cloud, keamanan aplikasi web/API, keamanan Kubernetes, keamanan endpoint macO
- Memiliki catatan menemukan kelemahan yang berdampak atau mengembangkan teknik serangan baru di lingkungan produksi
- Memiliki keterampilan pemrograman dan scripting yang kuat dalam Python, Go, atau bahasa serupa
- Memiliki pengalaman dalam mengembangkan alat penyerangan khusus dan eksploitasi
Required Skills
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
Perplexity is seeking a highly skilled, experienced and hands-on Offensive Security Engineer to join our dynamic security team, taking an adversarial approach to hardening Perplexity's infrastructure, applications, and AI systems. You'll plan and execute red team operations, penetration tests, and attack simulations across our cloud infrastructure, web and mobile applications, AI/ML pipeline, and corporate environment—finding real vulnerabilities before adversaries do and working directly with engineering teams to drive remediation. Responsibilities - Plan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces - Conduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services - Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries - Develop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testing - Perform open-scope adversary simulations that test detection and response capabilities end to end, collaborating closely with the defensive security team - Drive threat modeling sessions with engineering teams to identify and prioritize attack vectors in new features and architectures - Deliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediations - Contribute to the security of CI/CD pipelines, supply chain integrity, and secrets management through offensive assessment - Stay current on emerging attack techniques, vulnerability research, and adversary tradecraft; bring external perspective into Perplexity's security strategy Qualifications - 5+ years of hands-on experience in offensive security, red teaming, or penetration testing - Deep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes and container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline security - Track record of discovering impactful vulnerabilities or developing novel attack techniques in production environments - Strong programming and scripting skills in Python, Go, or similar languages; comfortable writing custom tooling and exploits - Experience with industry-standard offensive tools (Burp Suite, Cobalt Strike / Sliver / Mythic, Metasploit, BloodHound, nuclei, etc.) and ability to operate beyond them - Excellent written and verbal communication; able to translate complex technical findings into clear risk narratives - Experience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilities - Bonus: Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributions
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume