Skip to content

Open nowPosted 14 hours ago

Offensive Security Engineer

Artemis22 open roles

Where
New York City
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowOffensive Security EngineerArtemis · New York City
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Artemis's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 14 hours ago

The posting

Artemis is building the future of AI-driven defense - helping companies detect and defend themselves effectively in an era where AI is fighting AI on the cyber battlefield.

We're backed by First Round Capital, Brightmind, and a group of the cybersecurity industry's most prominent Operators.

Our founders, Shachar (ex-Palo Alto Networks, AWS, Demisto) and Dan (ex-Abnormal Security, Twitter) have previously built, launched, and scaled cybersecurity products loved and trusted by tens of thousands of customers, and have the customer, technology, and security know-hows to deliver this vision.

Our exceptionally strong team includes software engineers, AI researchers, security engineers, and product designers hailing from Google, Abnormal AI, Wiz, Meta, AWS, CERN, SentinelOne, and more.

We are growing our team and looking for passionate builders to join us and support our expanding customer base.

RESPONSIBILITIES

- Build scalable adversary emulation – Develop reusable scenarios and automation that reproduce attacker behaviors and multi-stage attack chains across cloud, identity, endpoint, SaaS, AI, and data environments. Prioritize work using threat intelligence, customer risk, and detection coverage gaps.

- Validate detections end to end – Trace emulated activity through collection, normalization, enrichment, detection, and investigation. Verify expected findings and evidence, identify missed detections and visibility gaps, and distinguish successful prevention from successful detection.

- Research attacks against AI systems – Investigate prompt injection, MCP and tool abuse, retrieval poisoning, excessive agent privileges, and unauthorized actions. Chain weaknesses across applications, agents, and integrations to establish realistic impact and identify detection opportunities.

- Research attacks against data planes – Explore abuse of service identities, integration tokens, permissions, and data access across databases, warehouses, object storage, and AI retrieval systems. Turn access, staging, export, and cross-platform attack paths into repeatable scenarios.

- Reproduce emerging exploits – Assess relevant vulnerability disclosures and exploit research in isolated labs. Establish prerequisites, practical impact, and observable behavior, then translate findings into detection hypotheses and bounded emulations.

- Enable safe testing in customer environments – Build authorized emulations and control checks with clear scope, preflight checks, least-privilege access, execution limits, stop controls, and verified cleanup. Document prerequisites, expected effects, and which scenarios require an isolated lab.

- Build continuous validation – Integrate scenarios with detector tests and engineering workflows. Develop AI evaluation harnesses with attack variations, multi-turn tests, and benign controls, measuring outcomes as models, tools, permissions, and detections change.

- Turn research into defensive improvements – Contribute detections, hunt logic, telemetry requirements, and regression tests. Partner with engineering and customer owners to drive findings through remediation and retesting, verifying fixes against malicious and benign behavior.

- Partner with the SOC and customers – Run purple-team exercises, explain findings and limitations, and give analysts the evidence and guidance needed to investigate emulated behaviors. Use AI to accelerate research and tooling while independently verifying generated actions and conclusions.

QUALIFICATIONS

- 5+ years of hands-on cybersecurity experience, with substantial offensive security, red teaming, adversary emulation, or security research work; equivalent demonstrated expertise is welcome.

- Strong Python skills and a track record building reusable security tools with APIs, SDKs, Git, code review, and automated testing.

- Deep practical expertise in at least one cloud or identity ecosystem, with an understanding of permissions, service identities, sessions, and data access.

- Practical web/API security knowledge and experience chaining weaknesses across authorization boundaries into meaningful attack paths.

- Experience reproducing attacks in controlled environments and connecting the resulting behavior to audit logs, detection logic, and investigation evidence.

- Experience assessing AI applications or agent workflows, or demonstrated offensive research into these systems.

- Sound judgment in sensitive environments: define scope, anticipate side effects, limit impact, protect data, and verify cleanup.

- Clear communication and the ability to own work from research through implementation, operational use, and verified outcomes.

BONUS

- Experience with Atomic Red Team, MITRE ATT&CK and ATLAS, purple teaming, or continuous security validation.

- Experience with SQL, detection-as-code, and cloud, identity, SaaS, or endpoint telemetry.

- Hands-on work with MCP servers, RAG systems, model gateways, or repeatable AI evaluations.

- Experience assessing data warehouses, object storage, Kubernetes, CI/CD systems, or software supply chains.

- Contributions to offensive tooling, emulation frameworks, detection content, or published security research.

- Experience building isolated labs and enabling customers to operate security tooling.

WHY WORK AT ARTEMIS?

- Make a real-world impact. Your tools and research will directly improve how real companies detect and defend against emerging threats.

- Build at the intersection of AI and security. Work with security and AI engineers to test emerging attack surfaces and turn discoveries into practical defenses.

- Own what you build. Take ideas from research to working capabilities used across the platform and customer environments.

- Work closely with practitioners. Partner with detection engineers, researchers, and analysts who can put your work into use and help measure its impact.

COMPENSATION

We offer a competitive compensation of $180,000 – $220,000 per year, and a top-of-market equity component. A variety of factors are considered when determining the compensation, including a candidate’s professional experience. Final offer amounts may vary from the amounts listed.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Artemis's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Artemis's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Artemis's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.