The opportunity
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…
What you'll do
Design and carry out security tests for GenAI applications, agentic systems,: and LLM-backed products. These tests will check for various attack types. They include prompt injection, indirect injection, retrieval poisoning, tool misuse, sensitive data extraction, and unsafe delegation to with the core purpose of building security protections
Investigate new multi-domain threat vectors and attack methodologies to stay: ahead of emerging risks and translating these into new security protections (e.g. detection rules)
Create and present findings to enhance team knowledge and community awareness
Apply AI-assisted techniques to expand coverage and accelerate validation.: This may include developing new capabilities and Elastic AI workflows to streamline our threat research and detection engineering processes
You should have experience working with endpoint data and understand: detection engineering GenAI pitfalls working with existing telemetry
You should have hands-on experience using LLM tools for security testing,: research, or daily tasks. You need to understand how LLMs work. This includes context windows, tool use, RAG, and agentic chaining. Knowledge of AI testing tools or frameworks, such as Garak, PyRIT, PromptBench, Inspect AI, or similar (including personal research or experiments) is a plus.
What they're looking for
- You should have experience using AI-assisted development tools and modern: AI/ML frameworks. These tools help you accelerate up feature development. They also help you debug complex systems and optimize existing codebases. You will generate telemetry, conduct threat research, and assist with detection engineering workflows.
- Proven ability to seamlessly transition between different projects,: codebases, or scrum teams based on dynamic business priorities.
- You work autonomously and can drive decisions and results in a distributed: team by leveraging asynchronous, direct, and transparent communication.
- Previous successes in presenting findings and insights to technical audiences