Ovii Job Board

Security Engineer

CodeRabbit

Bengaluru, India • Onsite - Bengaluru, India • Full-Time • 6-8 years

Posted 2026-07-02 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

CodeRabbit seeks a senior offensive security engineer to lead red‑team assessments, develop exploits, and harden AI‑driven code‑review platforms. The role blends hands‑on vulnerability research with close collaboration across engineering and incident response teams.

Role Snapshot

  • Offensive security assessments
  • Red‑team and adversary‑emulation operations
  • Exploit and tooling development
  • AI/ML attack surface research
  • Collaboration with engineering for remediation
  • Vulnerability management and bug bounty triage

Must-Have Requirements

  • Penetration testing / red teaming
  • Exploit development
  • Vulnerability research
  • Bug bounty hunting
  • Python scripting ability
  • Cloud security fundamentals
  • MITRE ATT&CK familiarity
  • Offensive security tooling familiarity
  • penetration testing
  • red teaming
  • exploit development
  • vulnerability research
  • bug bounty hunting

Nice-to-Have Signals

  • OSCP or equivalent certification
  • Experience with cloud‑native attack surfaces
  • AI/ML attack surface expertise
  • Incident response / SIEM exposure
  • C/C++ or Go programming
  • Participation in CTFs or security conferences
  • cloud‑native attack surfaces
  • AI/ML attack surface research
  • incident response
  • SIEM
  • OSCP or equivalent practical certification
  • AI/ML security

Work Setup

  • Location: Bengaluru, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Application Requirements

  • Portfolio required
  • GitHub required

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Education requirement
  • Certifications
  • Travel
  • Security clearance
  • Coding test

What You'll Likely Work On

  • Plan and execute scoped red‑team and adversary‑emulation exercises across enterprise, cloud, and network environments
  • Identify, exploit, and document vulnerabilities in web apps, APIs, mobile, wireless, and cloud‑native attack surfaces
  • Assess AI and agentic system attack vectors such as prompt injection and model‑prompt leakage
  • Build proof‑of‑concept exploits and custom tooling in Python, Go, or similar languages
  • Partner with engineering to design secure‑by‑default fixes, tests, and detection mechanisms
  • Evolve TTPs to include AV/EDR evasion and detection‑bypass techniques
  • Collaborate with the Security Incident Response Team to improve detection and defensive posture
  • Stay current on emerging CVEs, attack techniques, and the offensive security research community

Good Fit If You Have

  • Enjoys hunting bugs, CVEs, and participating in bug bounty programs
  • Thrives in fast‑paced, research‑driven environments
  • Communicates complex attack chains clearly to technical and non‑technical audiences

Skills

  • Penetration testing & red teaming
  • Exploit development & vulnerability research
  • Python scripting (Go, C/C++ a plus)
  • Cloud security fundamentals (AWS/GCP/Azure)
  • MITRE ATT&CK framework familiarity
  • Offensive security tooling (Burp Suite, Nmap, Metasploit, etc.)
  • AI/ML attack surface analysis
  • Bug bounty hunting experience