
About the Role
As a Principal Security Research Engineer on the Threat Research and Detection Engineering (TRaDE) team, you will shape the detection capabilities of Elastic Security. You will work hands-on with detection engineering and threat research, focusing on enhancing defenses for AI security.
What You Will Be Doing
- Security Testing: Design and execute security tests for GenAI applications, agentic systems, and LLM-backed products (e.g., prompt injection, indirect injection, retrieval poisoning, tool misuse, and unsafe delegation).
- Threat Research: Investigate multi-domain threat vectors and translate findings into actionable security protections and detection rules.
- Knowledge Sharing: Present findings to enhance team knowledge and community awareness.
- AI-Assisted Development: Utilize AI-assisted techniques to expand coverage, accelerate validation, and optimize detection engineering workflows.
What You Bring
- Experience with endpoint data and detection engineering within GenAI environments.
- Hands-on experience with LLM tools (context windows, tool use, RAG, agentic chaining) and AI testing frameworks (e.g., Garak, PyRIT, PromptBench, Inspect AI).
- Proficiency in AI-assisted development tools and modern AI/ML frameworks.
- Ability to work autonomously in a distributed team using asynchronous communication.
- Experience with Elastic Security Solution and query languages (EQL, KQL, ESQL) is a bonus.
- Background in penetration testing, vulnerability assessments, or Red Team operations (OWASP Top 10, OWASP LLM Top 10, MITRE ATLAS).
Benefits
- Competitive pay with stock program eligibility.
- Company-matched 401k (up to 6%).
- Flexible locations and schedules.
- Generous vacation policy and parental leave (minimum 16 weeks).
- Donation matching and volunteer time off.
Timezone overlap
UTC-8–-4
Benefits
Open to
US
Sign in to track applications and earn points.