- Strong background in application security, offensive security, or a combination of both
- Hands-on experience identifying and exploiting security weaknesses in modern applications and services
- Experience testing or securing AI-enabled systems, LLM integrations, or agent-based workflows
- Ability to reason about attacker misuse, abuse scenarios, and emergent behavior beyond traditional vulnerability classes
- Experience building automation, tooling, or security agents using languages such as Python, Go, JavaScript, or similar
- Familiarity with source code review and security tooling such as CodeQL, Semgrep, or equivalent
- Strong collaboration and communication skills, with the ability to work directly with engineers and security partners
- Preferred: Experience assessing commercial AI platforms or enterprise AI services
- Preferred: Familiarity with agent orchestration, tool calling, function execution, or multi-agent systems
- Preferred: Experience with traditional red team tooling or adversary simulation techniques
- Preferred: Exposure to detection engineering, incident response, or threat intelligence workflows
- Preferred: Experience turning novel AI security findings into scalable guidance rather than one-off fixes