Threat Researcher – AI, Identity & Data Security
פורסם אתמול · 0 מועמדים
- 3+ years in Threat Research, Red Teaming, or Applied Security Engineering
- Strong background in threat research, red teaming, or offensive security
- Deep understanding of AI/LLM architectures, AI agents, and orchestration patterns
- Solid knowledge of IAM: OAuth/OIDC, token-based systems, privilege and policy abuse
- Understanding of DLP, data flows, and exfiltration techniques
חולץ מתיאור המשרה · מתעדכן אוטומטית
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןThreat Researcher – AI, Identity & Data Security
Location: [Global/Remote]
Minimum Experience: 3+ years in Threat Research, Red Teaming, or Applied Security Engineering
Role Overview
The Threat Researcher focuses on identifying, modeling, and emulating threats targeting AI systems, LLMs, AI agents, identity layers, and data flows. This role blends research rigor, offensive security thinking, and strong communication, with a clear expectation of original research and external visibility.
Key Responsibilities
• Research emerging threats across:
• AI / LLM misuse and abuse
• AI agent manipulation and control-plane attacks
• Prompt injection, context poisoning, and data exfiltration
• Identity-based attacks (OAuth abuse, token theft, over-privileged agents)
• DLP bypass and policy evasion
• Design and execute threat emulation scenarios reflecting real adversary behavior.
• Build PoCs and test harnesses using:
• Python
• Docker
• Cloud environments
• Create reproducible labs and simulations for internal validation.
• Map threats to:
• MITRE ATT&CK
• AI-specific attack taxonomies
• Collaborate with Product, Engineering, and Deployment teams to validate mitigations.
• Publish research via blogs, whitepapers, talks, advisories, or open-source tools.
Required Skills & Experience
• Strong background in threat research, red teaming, or offensive security.
• Deep understanding of:
• AI/LLM architectures
• AI agents and orchestration patterns
• Solid knowledge of IAM:
• OAuth/OIDC
• Token-based systems
• Privilege and policy abuse
• Strong understanding of DLP, data flows, and exfiltration techniques.
• Proficiency in Python for PoCs and tooling.
• Comfortable with GitHub, open-source publishing, and documentation.
• Experience with MITRE ATT&CK or similar frameworks.
• Prior publication of security research (blogs, talks, CVEs, tools).
• Familiarity with cloud security, CASB, or SaaS security architectures.
• Experience emulating insider threats and abuse-of-function scenarios.
What Success Looks Like
• Original, high-impact research shaping product and industry thinking.
• Threat emulations that expose real weaknesses and drive product improvements.
• Published work that is cited and referenced externally.
• Strong collaboration turning research into real defenses.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3+ years in Threat Research, Red Teaming, or Applied Security Engineering, Strong background in threat research, red teaming, or offensive security, Deep understanding of AI/LLM architectures, AI agents, and orchestration patterns, Solid knowledge of IAM: OAuth/OIDC, token-based systems, privilege and policy abuse, Understanding of DLP, data flows, and exfiltration techniques