AI Security - Principal Security Research Engineer INew$46K–$183K

The opportunity

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…

What you'll do

  • Design and carry out security tests for GenAI applications, agentic systems,: and LLM-backed products. These tests will check for various attack types. They include prompt injection, indirect injection, retrieval poisoning, tool misuse, sensitive data extraction, and unsafe delegation

  • Investigate new multi-domain threat vectors and attack methodologies to stay: ahead of emerging risks and translating these into new security protections (e.g. detection rules)

  • Create and present findings to enhance team knowledge and community awareness

  • Apply AI-assisted techniques to expand coverage and accelerate validation.: This may include developing new capabilities and Elastic AI workflows to streamline our threat research and detection engineering processes

  • You should have experience running penetration tests or vulnerability: assessments on web applications, or APIs. Experience as a Red Team operator is also valuable. You should understand the OWASP Top 10 and have some exposure to the OWASP LLM Top 10 or MITRE ATLAS. Additionally, you need to be able to triage findings. You should communicate risks clearly to both technical and non-technical audiences.

  • You should have hands-on experience using LLM tools for security testing,: research, or daily tasks. You need to understand how LLMs work. This includes context windows, tool use, RAG, and agentic chaining. Knowledge of AI testing tools or frameworks, such as Garak, PyRIT, PromptBench, Inspect AI, or similar (including personal research or experiments) is a plus.

What they're looking for

  • You should have experience using AI-assisted development tools. These tools: help you speed up feature development. They also help you debug complex systems and optimize existing codebases. You will generate telemetry, conduct threat research, and assist with detection engineering workflows.
  • Proven ability to seamlessly transition between different projects,: codebases, or scrum teams based on dynamic business priorities.
  • Proficiency in modern AI/ML frameworks and hands-on experience integrating: LLM APIs into production applications
  • You work autonomously and can drive decisions and results in a distributed: team by leveraging asynchronous, direct, and transparent communication.