
Job Description
Ovii's Interpretation of the Role
CodeRabbit seeks a senior offensive security engineer to lead red‑team assessments, develop exploits, and harden AI‑driven code‑review platforms. The role blends hands‑on vulnerability research with close collaboration across engineering and incident response teams.
Role Snapshot
- Offensive security assessments
- Red‑team and adversary‑emulation operations
- Exploit and tooling development
- AI/ML attack surface research
- Collaboration with engineering for remediation
- Vulnerability management and bug bounty triage
Must-Have Requirements
- Penetration testing / red teaming
- Exploit development
- Vulnerability research
- Bug bounty hunting
- Python scripting ability
- Cloud security fundamentals
- MITRE ATT&CK familiarity
- Offensive security tooling familiarity
- penetration testing
- red teaming
- exploit development
- vulnerability research
- bug bounty hunting
Nice-to-Have Signals
- OSCP or equivalent certification
- Experience with cloud‑native attack surfaces
- AI/ML attack surface expertise
- Incident response / SIEM exposure
- C/C++ or Go programming
- Participation in CTFs or security conferences
- cloud‑native attack surfaces
- AI/ML attack surface research
- incident response
- SIEM
- OSCP or equivalent practical certification
- AI/ML security
Work Setup
- Location: Bengaluru, India
- Work mode: ONSITE
- Employment type: Full-Time
Application Requirements
- Portfolio required
- GitHub required
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Travel
- Security clearance
- Coding test
What You'll Likely Work On
- Plan and execute scoped red‑team and adversary‑emulation exercises across enterprise, cloud, and network environments
- Identify, exploit, and document vulnerabilities in web apps, APIs, mobile, wireless, and cloud‑native attack surfaces
- Assess AI and agentic system attack vectors such as prompt injection and model‑prompt leakage
- Build proof‑of‑concept exploits and custom tooling in Python, Go, or similar languages
- Partner with engineering to design secure‑by‑default fixes, tests, and detection mechanisms
- Evolve TTPs to include AV/EDR evasion and detection‑bypass techniques
- Collaborate with the Security Incident Response Team to improve detection and defensive posture
- Stay current on emerging CVEs, attack techniques, and the offensive security research community
Good Fit If You Have
- Enjoys hunting bugs, CVEs, and participating in bug bounty programs
- Thrives in fast‑paced, research‑driven environments
- Communicates complex attack chains clearly to technical and non‑technical audiences
Skills
- Penetration testing & red teaming
- Exploit development & vulnerability research
- Python scripting (Go, C/C++ a plus)
- Cloud security fundamentals (AWS/GCP/Azure)
- MITRE ATT&CK framework familiarity
- Offensive security tooling (Burp Suite, Nmap, Metasploit, etc.)
- AI/ML attack surface analysis
- Bug bounty hunting experience