技术员工(进攻性安全工程师)
Member of Technical Staff (Offensive Security Engineer)
Perplexity正在寻找一位技术能力突出、经验丰富的进攻性安全工程师加入我们充满活力的安全团队,以对抗性方式强化Perplexity的基础设施、应用程序和AI系统。你将规划并执行红队行动、渗透测试和攻击模拟,覆盖我们的云基础设施、网页和移动应用、AI/ML流程以及企业环境,提前发现真实漏洞,并与工程团队合作推动修复。
职责
- 规划并执行红队和紫队行动,模拟高级威胁行为者在云基础设施(AWS、Kubernetes)、终端和应用表面的攻击
- 持续对网页应用、API、移动客户端、浏览器扩展、云基础设施和内部服务进行渗透测试
- 评估AI/ML特有的攻击面,包括提示注入、模型外泄、代理滥用、工具使用漏洞利用和MCP安全边界
- 开发和维护定制的进攻性工具、漏洞利用和自动化脚本,提高安全测试的效率和覆盖率
- 执行开放范围的对手模拟,全面测试检测和响应能力,与防御安全团队紧密合作
- 与工程团队合作开展威胁建模会议,识别并优先处理新功能和架构中的攻击路径
- 向技术和高管受众清晰传达可操作的发现;与工程团队合作验证修复措施
- 通过进攻性评估为CI/CD流水线、供应链完整性及密钥管理做出安全贡献
- 跟踪最新的攻击技术、漏洞研究和对手战术;将外部视角带入Perplexity的安全策略中
要求
- 在进攻性安全、红队或渗透测试领域有5年以上实际工作经验
- 在至少两个领域具备深厚的技术专长:云安全(AWS/GCP/Azure)、网页/API应用安全、Kubernetes和容器安全、macOS/Linux终端安全、网络渗透测试或CI/CD流水线安全
- 在生产环境中发现具有影响力的漏洞或开发出新颖的攻击技术的记录
- 具备Python、Go或其他类似语言的编程和脚本编写能力;能够编写自定义工具和漏洞利用
- 有...
查看英文原文
Perplexity is seeking a highly skilled, experienced and hands-on Offensive Security Engineer to join our dynamic security team, taking an adversarial approach to hardening Perplexity's infrastructure, applications, and AI systems. You'll plan and execute red team operations, penetration tests, and attack simulations across our cloud infrastructure, web and mobile applications, AI/ML pipeline, and corporate environment—finding real vulnerabilities before adversaries do and working directly with engineering teams to drive remediation.
Responsibilities
- Plan and execute red team and purple team engagements simulating advanced threat actors across cloud infrastructure (AWS, Kubernetes), endpoints, and application surfaces
- Conduct continuous penetration testing of web applications, APIs, mobile clients, browser extensions, cloud infrastructure, and internal services
- Assess AI/ML-specific attack surfaces including prompt injection, model exfiltration, agent abuse, tool-use exploitation, and MCP security boundaries
- Develop and maintain custom offensive tooling, exploits, and automation to improve the efficiency and coverage of security testing
- Perform open-scope adversary simulations that test detection and response capabilities end to end, collaborating closely with the defensive security team
- Drive threat modeling sessions with engineering teams to identify and prioritize attack vectors in new features and architectures
- Deliver clear, actionable findings to both technical and executive audiences; partner with engineering to validate remediations
- Contribute to the security of CI/CD pipelines, supply chain integrity, and secrets management through offensive assessment
- Stay current on emerging attack techniques, vulnerability research, and adversary tradecraft; bring external perspective into Perplexity's security strategy
Qualifications
- 5+ years of hands-on experience in offensive security, red teaming, or penetration testing
- Deep technical expertise in at least two of: cloud security (AWS/GCP/Azure), web/API application security, Kubernetes and container security, macOS/Linux endpoint security, network penetration testing, or CI/CD pipeline security
- Track record of discovering impactful vulnerabilities or developing novel attack techniques in production environments
- Strong programming and scripting skills in Python, Go, or similar languages; comfortable writing custom tooling and exploits
- Experience with industry-standard offensive tools (Burp Suite, Cobalt Strike / Sliver / Mythic, Metasploit, BloodHound, nuclei, etc.) and ability to operate beyond them
- Excellent written and verbal communication; able to translate complex technical findings into clear risk narratives
- Experience assessing AI/ML systems, LLM applications, or agentic workflows for security vulnerabilities
- Bonus: Published security research, conference talks (DEF CON, Black Hat, BSides), CVE credits, or meaningful bug bounty contributions