产品安全工程师
Product Security Engineer
准备好开展职业生涯中最有影响力的工作了吗?在Coinbase,我们对提升经济自由的使命毫不妥协。标准很高,环境紧张,我们喜欢这样。这里不是安于现状的地方,而是让你突破自我认知极限的地方。如果你准备与那些不愿满足于“足够好”的人一起打造金融的未来,你就在正确的地方。Coinbase是一家以远程办公为主,但不局限于远程的公司。你将每季度参加一次高强度的线下工作会,称为“冲刺”。
作为安全团队中的进攻安全工程师,你将开创Coinbase如何利用前沿AI模型来扩大漏洞发现、红队AI系统和自动化安全流程。这个职位将传统渗透测试与下一代AI增强的进攻安全相结合,直接加速我们保护产品和客户的能力。你将负责开发AI驱动的安全工具,并与漏洞管理、进攻安全和事件响应团队合作,从根本上改变我们的运作方式。
你将做的事情:
- 构建、部署和维护定制的安全扫描器,利用前沿模型在Coinbase的产品范围内大规模检测漏洞。
- 领导针对内部AI系统的红队测试,包括越狱测试、提示注入分析和工具滥用模拟。
- 开发AI驱动的自动化工具,用于漏洞分类、验证和修复流程,加快漏洞赏金和漏洞响应流程。
- 与工程团队合作,优先处理、修复和验证通过AI增强和人工测试发现的关键漏洞。
- 指导初级安全工程师将AI整合到进攻安全流程中,以扩大团队能力。
所需的技能和经验:
- 在应用安全、渗透测试或进攻安全领域有3年以上经验,并有构建定制安全工具的实证能力。
- 有使用大语言模型或前沿模型自动化安全任务、扩大漏洞研究或构建安全扫描器的实际经验。
- 有对基于AI的系统进行红队测试的经验(提示注入、越狱测试、工具滥用)。
- 对常见漏洞类别(OWASP Top 10、SANS Top 25)有深入理解,并有识别和利用这些漏洞的实证记录。
查看英文原文
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
As an Offensive Security Engineer on the Application Security team within Security, you'll pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how we operate.
What you'll do:
- Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface.
- Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation.
- Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate the bug bounty and vulnerability response pipelines.
- Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing.
- Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities.
Required Skills and Experience:
- 3+ years of experience in application security, penetration testing, or offensive security with demonstrated ability to build custom security tooling.
- Hands-on experience using LLMs or frontier models to automate security tasks, scale vulnerability research, or build security scanners.
- Demonstrated experience red teaming AI-based systems (prompt injection, jailbreak testing, tool abuse).
- Deep understanding of common vulnerability classes (OWASP Top 10, SANS Top 25) and proven track record identifying and exploiting them in production environments.
- Proficiency in at least one programming language (Python, Go, or similar) with experience writing production-grade security tooling.
- Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).
Annual base salary range (excluding equity and bonus):
$154,000—$154,000 CAD
- Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
- Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
- US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
- Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
- Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.