JOBSEARCHER

Offensive Security Engineer

ARCHIVED

We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.

Perplexity is seeking a highly skilled, experienced and hands-on Offensive Security Engineer to join our dynamic security team, taking an adversarial approach to hardening Perplexity's infrastructure, applications, and AI systems. You'll plan and execute red team operations, penetration tests, and attack simulations across our cloud infrastructure, web and mobile applications, AI/ML pipeline, and corporate environment—finding real vulnerabilities before adversaries do and working directly with engineering teams to drive remediation.ResponsibilitiesPlan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfacesConduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal servicesAssess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundariesDevelop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testingPerform open-scope adversary simulations that test detection and response capabilities end to end, collaborating closely with the defensive security teamDrive threat modeling sessions with engineering teams to identify and prioritize attack vectors in new features and architecturesDeliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediationsContribute to the security of CI/CD pipelines, supply chain integrity, and secrets management through offensive assessmentStay current on emerging attack techniques, vulnerability research, and adversary tradecraft; bring external perspective into Perplexity's security strategyQualifications5+ years of hands-on experience in offensive security, red teaming, or penetration testingDeep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes and container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline securityTrack record of discovering impactful vulnerabilities or developing novel attack techniques in production environmentsStrong programming and scripting skills in Python, Go, or similar languages; comfortable writing custom tooling and exploitsExperience with industry-standard offensive tools (Burp Suite, Cobalt Strike / Sliver / Mythic, Metasploit, BloodHound, nuclei, etc.) and ability to operate beyond themExcellent written and verbal communication; able to translate complex technical findings into clear risk narrativesExperience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilitiesBonus: Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributionsCompensation Range: $220K - $405K