Security Engineer
coderabbit
About CodeRabbit
CodeRabbit is the leading AI code review platform, trusted by more than 17,000 customers and 150,000 open-source projects, conducting over 2 million code reviews each week. We build the symbiotic partnership between developers and AI that makes shipping fast software safe again, reviewing every pull request, IDE change, and CLI commit so teams can move quickly without breaking things.
We are a fast-moving, well-funded company, fresh off a $143M Series C at a $1.5B valuation — building Agentic Change Management, the control layer for software changes created by humans and agents. As AI writes more of the world's code, the bottleneck moves from implementation to judgment and helping human judgment scale is exactly the problem we exist to solve.
About the Role
We're looking for a hardcore offensive security engineer/researcher to join our security team — someone who thinks like an attacker and builds like an engineer. You'll spend your time finding ways to break our own systems before anyone else does, then work directly with engineering to fix what you find.
If you've disclosed vulnerabilities, hunted bug bounties, or get genuinely excited about a new CVE writeup, this role is built for you.
What You'll Do
Plan and execute scoped offensive security assessments, red team operations and adversary-emulation exercises across enterprise, application, cloud, and network environments — simulating real attacker behavior, not checklist-based audits
Identify, exploit, and responsibly document vulnerabilities across web applications, APIs, network infrastructure, wireless, mobile, and cloud-native attack surfaces
Assess AI and agentic-system attack surfaces, including prompt injection, tool/function-calling abuse, agent privilege boundaries, RAG/vector-store poisoning, model/system-prompt leakage, data exfiltration paths, and abuse of connectors or automation workflows.
Develop and refine proof-of-concept exploits, custom tooling, and scripts (Python, Go, or similar) to support engagements and scale offensive capabilities
Work as part of a team to explore systems methodically, taking time to avoid detection — the goal is reaching the objective quietly, not finding every possible vulnerability
Turn findings into durable fixes: partner with engineering on root cause, remediation design, secure-by-default patterns, tests, logging, detection opportunities, and fix validation.
Continuously evolve tactics, techniques, and procedures (TTPs) to reflect emerging adversary behavior, including AV/EDR evasion and detection-bypass techniques
Collaborate with the Security Incident Response Team (SIRT) and infrastructure security to translate red team findings into improved detection and defensive posture
Stay current on emerging attack techniques, CVEs, security advisories, and the broader offensive security research community
Help shape the security program via vulnerability management, bug bounty or responsible disclosure triage etc.
Occasionally support blue-team efforts during live incidents — log analysis, triage, pattern recognition
You'll Be a Strong Fit If You Have
6-8 years of hands-on experience in penetration testing, red teaming, exploit development, vulnerability research, bug bounty hunting, or equivalent demonstrated work.
Practical familiarity with tools such as Burp Suite or Caido, Nmap, ffuf, Nuclei, sqlmap, Metasploit, Wireshark, Semgrep, CodeQL, BloodHound, Impacket, cloud security tooling, and Linux-based offensive workflows.
A track record of finding real vulnerabilities: CVEs, public advisories, bug bounty credits, responsible disclosures, internal high-impact findings, or open-source offensive/security tooling.
Strong scripting/programming ability (Python preferred; C/C++/Go a plus) to build or modify exploits and tooling rapidly, even under tight timelines
Strong cloud and infrastructure security fundamentals across at least one major cloud provider, with practical understanding of IAM abuse, logging, and secrets management.
Familiarity with the MITRE ATT&CK framework and ability to map findings to known adversary tactics
Ability to reason through attack chains end to end: reconnaissance, initial access, privilege escalation, persistence where in scope, lateral movement, data access/exfiltration, impact analysis, reporting, remediation, and retest.
Experience working at a cybersecurity-native company, security consultancy, or a tech company with a mature internal red team
Excellent written and verbal communication skills — ability to explain complex attack chains clearly to both engineers and non-technical stakeholders
OSCP or equivalent practical certification is a strong plus
Nice to Have
Experience with cloud-native attack surfaces (GCP/AWS/Azure)
Experience securing or attacking AI/ML, LLM, RAG, multi-agent, or agentic workflow systems, including OWASP Top 10 for LLM Applications and emerging AI red-team practices.
Exposure to incident response or SIEM, threat hunting, forensics
Active participation in bug bounty, CTFs, security research, conference talks, open-source security tools, or responsible disclosure communities.
Familiarity with AI/ML system attack surfaces (prompt injection, confused sub-agents etc.) — emerging but increasingly relevant
Our Values
Collaborative Humans : Prioritizing collective intelligence
Fearless Innovators : Turning obstacles into growth opportunities
Persistent, Passionate Developers : Thriving on complex, long-term challenges
Impact-Driven Creators : Crafting intuitive tools for developers
Rapid Learners and Un-learners : Adapting quickly in our fast-paced technological world
What We Offer
Work on cutting-edge technology with real-world impact
Collaborative and innovative environment
Competitive salary, equity, and benefits
Professional development opportunities
To apply, submit your resume and relevant project samples or GitHub profiles. CodeRabbit is an equal-opportunity employer committed to diversity and inclusion.
- ...development. Hands-on experience working in cloud environments such as AWS, GCP, or Azure. Knowledge of professional software engineering practices across coding standards, code reviews, source control, build processes, testing, and operations. Experience using AI-...SuggestedFull timeHybrid workWork at office
- ...product integrations, and performance optimizations using large-scale structured and unstructured data. Collaborate with software engineering, product management, operations, and data science partners to identify opportunities, prioritize AI/ML requirements, make...SuggestedFull time
- Tesco India • Bengaluru, Karnataka, India • Hybrid • Full-Time • Working hours 45• Apply by 28-Oct-2026SuggestedFull timeHybrid work
- ...Full stack Developer– Python+Angular Position: Senior Software Engineer Experience: 5-7Years Category: Software Development/... ...planning, and technical discussions. • Follow coding standards, security practices, and software development best practices. • Contribute...SuggestedFull timeLocal area
- Role : SAP ABAP with Forms.Key Responsibilities :- Design and implement complex document output solutions using Adobe Forms, Smart Forms, and SAP Scripts to meet evolving business requirements for global clients.- Lead the technical migration and conversion of legacy SAP Scripts...SuggestedHybrid work
- Job Description :Experienced SAP SAC Planning Consultant with strong expertise in SAP Analytics Cloud (SAC) Planning, SAP Datasphere, and SAP Integrated Planning (SAP IP).The consultant will be responsible for designing, developing, implementing, and supporting end-to-end SAP...
- Role : Senior Manager (Offensive Security Services-VAPT)Mode of work : Hybrid (2 days)Key Skills : VA, PT, Consulting and Customer Success, hybrid Solution Advisor + Client Advisory + Delivery/People Management + Pre-Sales roleOffice Address : UV Cyber, PRESTIGE BLUE CHIP SOFTWARE...Hybrid work
- ...approaches. You will have a strong understanding of key agile engineering practices to guide teams on improvement opportunities in their... ...continuous integration, scalability of applications, and application security- Familiar with the Agile software development methodology and...Work at office
- Full Stack GenAI Engineer :We are looking for a skilled Full Stack Engineer to design and develop end-to-end GenAI applications.Responsibilities :- Build LLM, RAG and Agentic AI solutions using LangChain/LangGraph.- Develop scalable APIs and backend services using Python, FastAPI...
- ...Overview :We are seeking a forward-looking Software Development Engineer to design, build, and scale next-generation applications leveraging... ...new features.- Implement best practices for cloud architecture, security, and performance.- Automate deployment, monitoring, and...
- Job Description :We are looking for an experienced SAP CI (Convergent Invoicing) Senior Consultant with strong hands-on experience in SAP BRIM CI implementation and AMS support. The candidate should be comfortable working in highly customized SAP landscapes and possess cross...
- ...We are seeking a highly skilled and experienced Senior Software Engineer to join our innovative team at McKesson Compile India Private Limited... ...development lifecycle, ensuring high-quality, scalable, and secure applications.Key Responsibilities :- Design and implement...Full time
- Gen AI Engineer + CI/CD + PythonJob Description :Key Responsibilities :- Design and implement robust AI models and Python-based applications that solve critical business challenges and improve operational efficiency for our global client base.- Engineer and maintain automated...
- Position : Senior Data Engineer PyTorch / ML Data PlatformsCompany : CodeWalnutEmployment Type : Full-Time with SupersourcingExperience : 5+ YearsLocation : BangaloreWork Mode : Work From Office 5 Days a WeekFunction : Data & AI EngineeringRole Overview : We are looking for...Full timeWork at office
- ...strong expertise in LLM-based application development, prompt engineering, AI pipelines, and production deployment, along with good software... ..., and technical solutions to ensure quality, scalability, security, and maintainability.- Work closely with Data Scientists, Architects...
- ...Our client, a consulting major, is looking for strong technical application development expertise.Position Overview :As an Applied AI Engineer, you will actively engage in your engineering craft, taking a hands-on approach to building and enhancing high-visibility, full-stack...Full timeFlexible hours
- Role : Java Developer with ReactJob Description :We are looking for an experienced Java Developer with React to join our development team. The ideal candidate should have strong hands-on experience in Java backend development along with React.js and a good understanding of modern...Immediate start
- ...scalable applications- Develop and optimize SQL databases, including schema design, query optimization, and data modeling- Implement secure Authentication & Authorization mechanisms such as OAuth2, JWT, RBAC, and SSO- Build high-performance communication layers using gRPC /...
- Role Overview : - 10+ years of experience in Site Reliability Engineering, DevOps, Platform Engineering, or Infrastructure Operations.- Deep... ...& Influence : - Partner with Delivery, Architecture, Security, and Risk teams to embed reliability and resilience into design...Hybrid work
- ...of quality and performance.Responsibilities : Hands-on Software Engineering : - Design, develop, test and maintain enterprise-grade applications... ...using Java, J2EE, Spring Boot and related frameworks.- Build secure, scalable and resilient microservices, REST APIs and event-...
- Software Engineer (Data & AI):Location: IndiaYour Role:Data and AI are fundamentally reshaping how global organizations operate and this... ...ownership of data platforms ensuring cost efficiency, governance, security, and compliance across the full data lifecycle. Partnering...Full timeWork at office
- Job Description :Must Have Technical Skills :- Hands-on experience in C and C++ programming language.- Excellent in programming - translating a high level problem to an implementation proposal and the final implementation.- Design, Implementation and debugging of Linux device...
- ...architecture, application components, data models, integration flows, security controls, and implementation roadmaps.- Design and develop... ...: - Bachelor's or Master's degree in Computer Science, Engineering, Information Technology, or a related discipline.- 10+ years of...
- ...analytics requirements.- Support data governance, quality, and security initiatives.- Participate in testing, debugging, and documenting... ...adopt emerging tools, frameworks, and best practices in data engineering and cloud technologies.Desired Profile :- Bachelors degree in computer...Temporary workInternship
- (Senior) AI Engineer - Data & AI Organization (all genders) 1AI EngineerLocation : IndiaYour Role : Within the Data & AI Organization, a... ...Foundry, and Snowflake.Embedding explainability, transparency, and security into every AI solution is a core expectation of this role. You...
- ...leveraging cloud-native architectures, AI/ML capabilities, and modern engineering practices.The individual owns technical decisions and direction... ...bottlenecks, ensuring applications run efficiently at scale.- Security: Implement security best practices to protect data and...
- ...develop API-based integrations.- Support AI data enablement requirements.- Configure and troubleshoot integration workflows.- Ensure secure, scalable, and reliable integration solutions.- Collaborate with application, platform, and business teams.Tech Stack & Requirements :...
- ...Databricks and Azure Synapse skills will be preferred.- Excellent E-Mail and phone communication skills.- Experience in guiding BI Support Engineers.- Experience in a global environment.- Ability to read code and support applications, reports and processes.- Excellent analytical...Immediate start
- ...closely with Product, Design, and the founding team to turn ambiguous problem statements into clear, scalable infrastructure.- Raise the engineering bar through clean code, thorough design reviews, mentorship, and platform-level improvements.What It Takes : - 6-8 years of...Long term contractHybrid work
- ...Systems, Computer Science, Cybersecurity, Business Analytics, Engineering, or a related field.- Relevant professional certifications in business... ...improve the quality, accessibility, and usability of critical security information.- The team is focused on enabling data-driven...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
