Skip to content
All jobs

Senior Offensive AI Security Engineer

  • Zoom
  • Remote (US), United States of America
  • Full time

What You Can Expect This role sits at the intersection of offensive security and applied AI, focused on surfacing critical risks across Zoom's products, applications, services, and infrastructure before they become incidents. Day to day, you will combine deep target knowledge, threat analysis, and cutting edge models to form hypotheses about where complex systems are likely to fail, validate exploitability, and trace attack paths that standard testing would miss. This is not a vulnerability-scanning or prompt-engineering role: a strong hands-on research craft is the foundation, and success is measured by whether your findings change how Zoom understands its risk, not by finding volume. Research directions are chosen in collaboration with the Security Assurance teams (Offensive Security, Vulnerability Management, Bug Bounty, PSIRT), but most work is self-directed, with high autonomy and no predetermined outcome. About the Team Zoom's Offensive Security team conducts vulnerability research across products, applications, and infrastructure, concentrating on high-impact issues that escape standard secure development processes or wouldn't surface through routine testing. The team is actively evolving towards AI-native research, where models extend how much ground experienced security engineers can cover and how quickly, paired with real target knowledge, a sound research strategy, and rigorous verification. Responsibilities Leverage AI to conduct vulnerability research across Zoom's products, applications, services, and infrastructure, with a focus on high-impact issues, subtle vulnerabilities, confirmed exploitability, and attack paths that cross component and trust boundaries. Use experience, threat analysis, architecture knowledge, source code, and observed system behavior to choose targets and guide investigations. Apply frontier and open-weight models, agents, and other AI capabilities across the research lifecycle: reconnaissance, code analysis, hypothesis generation, exploit development, and verification. Design and tune research harnesses that give models the right context, tools, execution environments, and feedback to investigate real targets. Develop custom tooling, including analysis utilities, fuzzers, agents, test harnesses, proofs of concept, and full exploits, when it helps answer the research question. Convert promising model output into defensible security evidence: reproduce findings, rule out false claims, establish preconditions, and distinguish a possible weakness from a demonstrated vulnerability with real impact. Improve the reliability and reach of AI-driven research by tackling false positives, false negatives, context limits, nondeterminism, and reproducibility. Work directly with Engineering and Product Security to communicate findings, support remediation, surface related risks, and verify fixes. Share tools, techniques, and lessons learned so Security Assurance and the broader Security org can enhance their processes through the use of AI. What We're Looking For 5+ years of hands-on vulnerability research, offensive security, application security, or penetration testing, with a demonstrated track record of choosing targets, forming and revising hypotheses, and establishing exploitability and impact in complex software or production systems. Hands-on experience running offensive workflows with frontier and open-weight models, including model selection where refusal behavior would otherwise block legitimate exploit development. Experience assessing the quality of AI-driven research processes, including identifying false positives, missed vulnerabilities, unstable results, and reproducibility gaps, as well as sound judgment on agent architecture trade-offs: when constrained, orchestrated pipelines deliver reproducible results and when open-ended tool-using agents are worth the nondeterminism. Deep technical expertise in at least one security domain: web applications and APIs, Java applications, cloud or service infrastructure, client software, operating systems, or reverse engineering. Strong programming and debugging skills: ability to read unfamiliar code, build research tooling, write proofs of concept, and trace behavior across system boundaries. Strong intuition for attack surfaces, trust boundaries, exploitability, and security impact, combined with the persistence to work independently on open-ended research with no guaranteed path or outcome. Ability to communicate findings clearly to both technical and nontechnical audiences, covering what the evidence shows, what remains uncertain, and why it matters. Salary Range or On Target Earnings: Minimum: $124,000.00 Maximum: $271,200.00 In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value. Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location based compensation structure; there may be a different range for candidates in this and other locations At Zoom, we offer a window of at least 5 days for you to apply because we believe in giving you every opportunity. Below is the potential closing date, just in case you want to mark it on your calendar. We look forward to receiving your application! Anticipated Position Close Date: 10/14/26 Ways of Working Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting. Benefits As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information. About Us Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment. Our Commitment At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step. If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed. Our interviews are supported by BrightHire, a tool that helps us create a consistent and thoughtful interview experience and may include recordings. Please refer to our candidate privacy statement for more information of how we use your data. #LI-Remote