Security Engineer
coderabbit
About CodeRabbit
CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems. Our primary goal is to create the next generation of Gen AI-driven code reviewers: a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers. We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.
About the Role
We're looking for a hardcore offensive security engineer/researcher to join our security team — someone who thinks like an attacker and builds like an engineer. You'll spend your time finding ways to break our own systems before anyone else does, then work directly with engineering to fix what you find.
If you've disclosed vulnerabilities, hunted bug bounties, or get genuinely excited about a new CVE writeup, this role is built for you.
What You'll Do
Plan and execute scoped offensive security assessments, red team operations and adversary-emulation exercises across enterprise, application, cloud, and network environments — simulating real attacker behavior, not checklist-based audits
Identify, exploit, and responsibly document vulnerabilities across web applications, APIs, network infrastructure, wireless, mobile, and cloud-native attack surfaces
Assess AI and agentic-system attack surfaces, including prompt injection, tool/function-calling abuse, agent privilege boundaries, RAG/vector-store poisoning, model/system-prompt leakage, data exfiltration paths, and abuse of connectors or automation workflows.
Develop and refine proof-of-concept exploits, custom tooling, and scripts (Python, Go, or similar) to support engagements and scale offensive capabilities
Work as part of a team to explore systems methodically, taking time to avoid detection — the goal is reaching the objective quietly, not finding every possible vulnerability
Turn findings into durable fixes: partner with engineering on root cause, remediation design, secure-by-default patterns, tests, logging, detection opportunities, and fix validation.
Continuously evolve tactics, techniques, and procedures (TTPs) to reflect emerging adversary behavior, including AV/EDR evasion and detection-bypass techniques
Collaborate with the Security Incident Response Team (SIRT) and infrastructure security to translate red team findings into improved detection and defensive posture
Stay current on emerging attack techniques, CVEs, security advisories, and the broader offensive security research community
Help shape the security program via vulnerability management, bug bounty or responsible disclosure triage etc.
Occasionally support blue-team efforts during live incidents — log analysis, triage, pattern recognition
You'll Be a Strong Fit If You Have
6-8 years of hands-on experience in penetration testing, red teaming, exploit development, vulnerability research, bug bounty hunting, or equivalent demonstrated work.
Practical familiarity with tools such as Burp Suite or Caido, Nmap, ffuf, Nuclei, sqlmap, Metasploit, Wireshark, Semgrep, CodeQL, BloodHound, Impacket, cloud security tooling, and Linux-based offensive workflows.
A track record of finding real vulnerabilities: CVEs, public advisories, bug bounty credits, responsible disclosures, internal high-impact findings, or open-source offensive/security tooling.
Strong scripting/programming ability (Python preferred; C/C++/Go a plus) to build or modify exploits and tooling rapidly, even under tight timelines
Strong cloud and infrastructure security fundamentals across at least one major cloud provider, with practical understanding of IAM abuse, logging, and secrets management.
Familiarity with the MITRE ATT&CK framework and ability to map findings to known adversary tactics
Ability to reason through attack chains end to end: reconnaissance, initial access, privilege escalation, persistence where in scope, lateral movement, data access/exfiltration, impact analysis, reporting, remediation, and retest.
Experience working at a cybersecurity-native company, security consultancy, or a tech company with a mature internal red team
Excellent written and verbal communication skills — ability to explain complex attack chains clearly to both engineers and non-technical stakeholders
OSCP or equivalent practical certification is a strong plus
Nice to Have
Experience with cloud-native attack surfaces (GCP/AWS/Azure)
Experience securing or attacking AI/ML, LLM, RAG, multi-agent, or agentic workflow systems, including OWASP Top 10 for LLM Applications and emerging AI red-team practices.
Exposure to incident response or SIEM, threat hunting, forensics
Active participation in bug bounty, CTFs, security research, conference talks, open-source security tools, or responsible disclosure communities.
Familiarity with AI/ML system attack surfaces (prompt injection, confused sub-agents etc.) — emerging but increasingly relevant
Our Values
Collaborative Humans : Prioritizing collective intelligence
Fearless Innovators : Turning obstacles into growth opportunities
Persistent, Passionate Developers : Thriving on complex, long-term challenges
Impact-Driven Creators : Crafting intuitive tools for developers
Rapid Learners and Un-learners : Adapting quickly in our fast-paced technological world
What We Offer
Work on cutting-edge technology with real-world impact
Collaborative and innovative environment
Competitive salary, equity, and benefits
Professional development opportunities
To apply, submit your resume and relevant project samples or GitHub profiles. CodeRabbit is an equal-opportunity employer committed to diversity and inclusion.
- ...About the Team The security team at Meesho is like the Avengers to Meesho's S.H.I.E.L.D. After all, when 5% of Indian households... ...with zero downtime! Sounds impossible? Well, that’s the kind of Engineering muscle that has helped Meesho become the e-commerce giant it is...SuggestedFull time
- ...At SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously... ...into what makes SAFE unique. We’re looking for a Security Engineer II to join our SecOps team and play a critical role in strengthening...Suggested
- Key Responsibilities at this Role :- Drive application security reviews across new services, APIs, and platform architectures.- Implement... ...5+ years in Application Security, Cloud Security, or Security Engineering.- Strong understanding of OWASP Top 10 and SANS Top 25...Suggested
- Role : Security Engineer II Job Description :4+ years of work experience. We at Setu are looking for those who share our core belief Every Day is Game Day.We bring our best selves to work each day to realize our mission of enriching the world through the power of digital commerce...SuggestedWork at office
- Job Description : We are seeking a highly skilled Mobile App Payments and Red Teaming Engineer to strengthen the security posture of our mobile payment ecosystem through advanced offensive security testing and adversary simulation exercises. The role will focus on identifying...Suggested
- ...About Akto Akto is an enterprise-grade Agentic AI Security platform used by global organizations to discover APIs, continuously test... .... Role Overview We are looking for a hands-on security engineer with a strong pentesting background who wants to move beyond traditional...Long term contract
- ...Required Skills: Strong hands-on experience in Application Security (AppSec), Vulnerability Assessment, and Penetration Testing (VAPT). Proficiency in Java or Python with the ability to understand application logic, review code, and develop automation scripts. Experience...
- ...the job descriptions mentioned below. Position 1: Senior IAM Engineer Simplify ID: 1544 Experience: 8–10 Years Location: Bangalore... ...modeling Act as IAM SME and collaborate with engineering and security teams Required Skills ~8–10 years of IAM experience ~...Hybrid work
- ...retail experiences ever. Tekion employs close to 3,000 people across North America, Asia and Europe. We are seeking a Cloud Security Engineer with 5+ years of experience to join our Security Engineering team and help safeguard our SaaS infrastructure. This role is...
- ...If you are motivated by impact, growth, and purpose, you will find a strong sense of belonging at Quince. THE ROLE Staff Security Engineer We’re looking for a Staff Security Engineer to join our growing Security team. In this role, you will drive security strategy...Local area
- ....How You Will Make an Impact:- Design, implement, and maintain security controls across cloud infrastructure, applications, and network... ...incidents and driving timely remediation.- Partner with Cloud Engineering, DevOps, and application teams to embed security best practices...Immediate start
- ...every business deserves access to cloud-enabled, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect... ...seeking a highly motivated and detail-oriented Information Security Engineer to join our team. The successful candidate will have a strong...Local areaWorldwide
- ...about cybersecurity, hybrid infrastructure, and building a strong security culture? Join WirelessCar and help secure connected mobility... ...impact on society. Your Role We are looking for a Security Engineer – Hybrid Infrastructure and Security Awareness to strengthen our...Long term contractHybrid workWork at officeWork from homeWorldwide
- Job Description: Network & Security EngineerDepartment: Service DeliveryDesignation: Network & Security EngineerLocation: BengaluruReporting... ...Summary:We are seeking a skilled Network & Security Engineer with 4 to 6 years of experience in implementing, managing and troubleshooting...
- Roles & Responsibilities:Platform Security & Hardening:- Own and continuously strengthen the information security posture of VuNet's Business... ..., including endpoint hardening, malware protection, detection engineering, and security monitoring across enterprise assets.- Support...Hybrid work
- What you'll own : - Lead engineering and delivery for SWG, Proxy, SASE, Secure Access, and IPS/IDS across a global enterprise environment.- Administer and harden Zscaler (ZIA/ZPA) and Palo Alto platforms, including Panorama, Prisma Access, NGFW, and Threat Prevention.- Design...Hybrid work
- ...play a key role in keeping Axi colleagues safe in the world of Cyber. With a key focus on engineering and automation, this role focuses on implementing strategic solutions to security problems, providing a secure environment for our customers and colleagues to operate in without...Local area
- L2 Network & Security Engineer_LUX_HCS Position Description Company Profile: Founded in 1976, CGI is among the largest independent IT and business consulting services firms in the world. With 94,000 consultants and professionals across the globe, CGI delivers an end...Full timeLocal area
- ...but works for the good guys—someone who's obsessed with ensuring ZERO vulnerabilities in our technology. As a key member of our security and compliance team, you’ll be the first line of defense, protecting our users' data, money, and identity. Your mission? Keep our...Full timeWork at office
- ...seek individuals who embody our core traits: Scrappy, Curious, Optimistic, Persistent, and Empathetic . Your role As a Security Engineer focused on Product Security and AI, you will help secure Dialpad’s applications, platforms, and AI-powered capabilities throughout...Full time
- ...Security Engineer Experience: 3-5 years Location: Coimbatore & Bangalore Who we are and What we do? AppViewX is trusted by the world’s leading organizations to reduce risk, ensure compliance, and increase visibility through automated certificate lifecycle management...Flexible hoursShift work
- ...automotive retail experiences ever. Tekion employs close to 3,000 people across North America, Asia and Europe. Summary: The Security Engineer II is responsible for implementing and maintaining security controls, monitoring systems, and supporting incident response...
- ...growing, and we need forward-thinking, uncompromising, competitive team members to continue to facilitate our growth. Job Role : Security Engineer – IAM Experience : 3- 6 years About Netradyne Netradyne is a leader in cutting-edge AI-powered safety and fleet...Hybrid work
- ...is backed by Google, Jio Platforms, and Mithril Capital. About the Role We are looking for an experienced and hands-on Sr. Security Engineer to drive application security initiatives across Glance AI's rapidly evolving technology landscape. This role will partner...Long term contractFull timeWorldwide
- This role is for one of our clients Industry: Software Development Seniority level: Mid-Senior level Min Experience: 6+ years Location: Bengaluru JobType: full-timeFull time
- ...patch deployments for zero-day vulnerabilities and critical/high security incidents.- Integrate vulnerability scanning tools with patch... ...remediation workflows.- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.- Design...
- ...more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 900 people who collaborate to support the business of EY by protecting EY and...Hybrid workLocal areaFlexible hours
- Job Description : We are seeking an experienced Cloud Security Engineer to join our Enterprise Engineering team and play a key role in securing our cloud-native platforms and enterprise infrastructure. This position is responsible for designing, implementing, and maintaining...
- ...challenge the status quo & evolve cyber practices to the next level of maturity. Our core competencies revolve around “Product & Platform security”, “Cloud Native Risk Management” ,and “Detection & Response”. What will you be doing? Conduct Vulnerability Assessments,...Worldwide
- ...Place to Work in the US , Australia , India , Lithuania, France, Germany and the UK ! We are looking for a Senior Offensive Security Engineer who is a "Jack of all trades, Master of some." You don’t need to be a world-class Red Teamer AND a Cloud Architect; rather, you...Long term contractFull timeHybrid workWork at officeWork from homeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
