Skip to content

Open nowPosted 22 hours agoWe saw it 56 min after it went up

AI Security Researcher/Senior AI Security Researcher

Agoda295 open roles

Where
Bangkok, Thailand
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAI Security Researcher/Senior AI Security ResearcherAgoda · Bangkok, Thailand
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Agoda's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Agoda postings stay open a median of 5 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.9%7 days
  4. 14.2%14 days
  5. 34.1%30 days
This job: posted 22 hours ago

Agoda median: 5 days open

The posting

About Agoda

At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world.

Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide.

No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.

The Opportunity: AI Security Researcher

We are looking for an AI Security Researcher with a strong offensive security mindset, published CVEs, and the ability to use AI as a hacking tool. The core of this role is finding real exploitable issues before attackers do, prioritizing external (internet-facing) exploits, then internal ones.

You will build autonomous agents that research and hack on the fly by interacting with AI, and you will jailbreak AI systems.

The ideal candidate has a strong offensive security background, has already shifted to using AI to find bugs, and is already hands-on and comfortable working this way.

Key Responsibilities

- Proactively find, exploit, and document real-world vulnerabilities, prioritizing external (internet-facing) attack paths, then internal ones. - Discover these issues before attackers do, with working proofs of concept and demonstrated impact. - Build autonomous agents that hunt, attack, and iterate on the fly by interacting with AI models and tools. - Use and develop AI-driven offensive workflows (multi-model setups, tool-calling, notebooks, orchestration) for continuous hunting. - Apply deep offensive security skills (API abuse, authentication and access control, secrets, misconfiguration, red teaming) with AI in the loop. - Produce CVE-quality research outcomes and drive findings through to engineering fixes. - Design, execute, and document jailbreaks, prompt injection attacks, model evasion, data exfiltration, and other offensive techniques against AI systems. - Assess and attempt to compromise Model Context Protocol (MCP)–based systems and other tool-calling / plugin ecosystems. - Build and automate security testing workflows involving multiple models, APIs, and tools (e.g., Jupyter notebooks, orchestration frameworks). - Perform offensive security testing and red teaming of AI-driven products, including API manipulation and integration abuse. - Research security weaknesses in models and the infrastructure around them. - Contribute to in-house guardrail design: define, implement, and test safety and security guardrails for models and AI automations. - Propose and evaluate defensive controls: input/output filtering, policy enforcement, monitoring, anomaly detection, and non-AI controls to secure AI systems. - Translate research findings into practical engineering requirements and collaborate closely with product and engineering teams to implement fixes and mitigations. - Work with multiple teams, explain risk and impact clearly, and present findings to different teams and C-level stakeholders. - Produce clear technical documentation, proof-of-concepts, and knowledge sharing on AI security practices and new attack/defense techniques.

What you'll Need to Succeed:

Must have - Bachelor's in Computer Science or related degree. - 2–7 years in offensive cybersecurity. - Published CVE(s). - Strong offensive security knowledge: API security testing and manipulation; prior red teaming, penetration testing, or adversarial testing. - Hands-on jailbreak experience (prompt injection, role confusion, data leakage, safety bypasses, and similar). - Ability to work with multiple teams, explain risk and impact, and present to different teams and C-level stakeholders. - Good communication skills in English. - Experience handling and maintaining production-level code.

Strongly recommended - Proven exploits or write-ups that used AI (models/agents) to find or exploit bugs. - Experience building autonomous agents that interact with AI to attack or test systems on the fly. - Already using AI in day-to-day offensive work to find bugs, and comfortable with that shift. - Bug bounty / HackerOne or similar track record. - Conference presentations.

Please review our Hiring Process Guidelines before your interview — click here to learn how interviewing at Agoda works.

Discover more about working at Agoda

  • Agoda Careers https://careersatagoda.com
  • Facebook https://www.facebook.com/agodacareers/
  • LinkedIn https://www.linkedin.com/company/agoda
  • YouTube https://www.youtube.com/agodalife

Equal Opportunity Employer

At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.

We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy.

Disclaimer

We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Agoda's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Agoda's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Agoda's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.