Offensive Security Engineer
Artemis · New York City · United States · On-site
Pay: USD 180,000 – 220,000 a year
Posted Oct 7, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Artemis is building the future of AI-driven defense - helping companies detect and defend themselves effectively in an era where AI is fighting AI on the cyber battlefield.
We're backed by First Round Capital, Brightmind, and a group of the cybersecurity industry's most prominent Operators.
Our founders, Shachar (ex-Palo Alto Networks, AWS, Demisto) and Dan (ex-Abnormal Security, Twitter) have previously built, launched, and scaled cybersecurity products loved and trusted by tens of thousands of customers, and have the customer, technology, and security know-hows to deliver this vision.
Our exceptionally strong team includes software engineers, AI researchers, security engineers, and product designers hailing from Google, Abnormal AI, Wiz, Meta, AWS, CERN, SentinelOne, and more.
We are growing our team and looking for passionate builders to join us and support our expanding customer base.
RESPONSIBILITIES
- Build scalable adversary emulation – Develop reusable scenarios and automation that reproduce attacker behaviors and multi-stage attack chains across cloud, identity, endpoint, SaaS, AI, and data environments. Prioritize work using threat intelligence, customer risk, and detection coverage gaps.
- Validate detections end to end – Trace emulated activity through collection, normalization, enrichment, detection, and investigation. Verify expected findings and evidence, identify missed detections and visibility gaps, and distinguish successful prevention from successful detection.
- Research attacks against AI systems – Investigate prompt injection, MCP and tool abuse, retrieval poisoning, excessive agent privileges, and unauthorized actions. Chain weaknesses across applications, agents, and integrations to establish realistic impact and identify detection opportunities.
- Research attacks against data planes – Explore abuse of service identities, integration tokens, permissions, and data access across databases, warehouses, object storage, and AI retrieval systems. Turn access, staging, export, and cross-platform attack paths into repeatable scenarios.
- Reproduce emerging exploits – Assess relevant vulnerability disclosures and exploit research in isolated labs. Establish prerequisites, practical impact, and observable behavior, then translate findings into detection hypotheses and bounded emulations.
- Enable safe testing in customer environments – Build authorized emulations and control checks with clear scope, preflight checks, least-privilege access, execution limits, stop controls, and verified cleanup. Document prerequisites, expected effects, and which scenarios require an isolated lab.
- Build continuous validation – Integrate scenarios with detector tests and engineering workflows. Develop AI evaluation harnesses with attack variations, multi-turn tests, and benign controls, measuring outcomes as models, tools, permissions, and detections change.
- Turn research into defensive improvements – Contribute…