xelys jobs xelys jobs

Staff Attack Engineer (AI/LLM)

Horizon3

full-remoteleadpermanentsecuritybackend Full remote 71 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AI/LLM SecurityPrompt InjectionDefense EvasionAutonomous PentestingNodeZeroPythonThreat ModelingOWASP Top 10 for LLMsMITRE ATLASNeo4j

About the role

Role Overview

Staff Attack Engineer specializing in AI/LLM security. You will break AI and agentic systems and translate that research into automated, repeatable attacks inside NodeZero.

Key Missions

  • Design and execute prompt injection and defense evasion attacks, focusing on models that are generalizable and reusable.
  • Build automated attack modules for NodeZero based on offensive AI/agent research.
  • Exploit tool-use and attack AI infrastructure.
  • Perform threat modeling for agentic systems by mapping trust boundaries and attack surfaces.
  • Apply a productization mindset by building and extending LLM-powered applications with production concerns.

Requirements

  • Proven ability to break AI/LLM and agentic systems.
  • Experience in a security product or offensive security team; ideally shipped offensive capabilities or tooling.
  • Strong penetration testing fundamentals and understanding of common attack chains.
  • Expert-level ownership: drive high-complexity, high-risk programs and set strategy.
  • Self-motivated problem solver who builds proactive solutions.
  • Deep understanding of trust boundaries around AI tools, data sources, and permissions; ability to systematically test and exploit them.
  • Familiarity with AI/LLM security frameworks such as OWASP Top 10 for LLMs and MITRE ATLAS.
  • Expert-level Python and software engineering skills.

Nice to Have

  • Familiarity with graph databases (e.g., Neo4j).
  • CTF experience, especially AI/ML-focused challenge categories.
  • Contributions to AI security research (blogs, conference talks, CVEs, open-source tools).
  • Experience with cloud AI services: Azure OpenAI and GCP Vertex AI.
  • Experience with AWS Bedrock and AWS Agent Core.
  • Background in traditional exploit development or vulnerability research.

About Horizon3

Horizon3 is a security-focused company building autonomous pentesting capabilities. It develops NodeZero, a platform that automates security testing and offensive workflows for modern systems, including AI and agentic technologies.

Scraped 7/14/2026