You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Zoom

Senior Offensive AI Security Engineer

  • Remote
  • 6+ years

Salary

$124,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

What You Can Expect

This role sits at the intersection of offensive security and applied AI, focused on surfacing critical risks across Zoom's products, applications, services, and infrastructure before they become incidents. Day to day, you will combine deep target knowledge, threat analysis, and cutting edge models to form hypotheses about where complex systems are likely to fail, validate exploitability, and trace attack paths that standard testing would miss. This is not a vulnerability-scanning or prompt-engineering role: a strong hands-on research craft is the foundation, and success is measured by whether your findings change how Zoom understands its risk, not by finding volume. Research directions are chosen in collaboration with the Security Assurance teams (Offensive Security, Vulnerability Management, Bug Bounty, PSIRT), but most work is self-directed, with high autonomy and no predetermined outcome.

Zoom's Offensive Security team conducts vulnerability research across products, applications, and infrastructure, concentrating on high-impact issues that escape standard secure development processes or wouldn't surface through routine testing. The team is actively evolving towards AI-native research, where models extend how much ground experienced security engineers can cover and how quickly, paired with real target knowledge, a sound research strategy, and rigorous verification.

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars.

We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

Our Commitment

At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step.

If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed.

Our interviews are supported by BrightHire, a tool that helps us create a consistent and thoughtful interview experience and may include recordings. Please refer to our candidate privacy statement for more information of how we use your data.

LI-Remote

Responsibilities

  • Leverage AI to conduct vulnerability research across Zoom's products, applications, services, and infrastructure, with a focus on high-impact issues, subtle vulnerabilities, confirmed exploitability, and attack paths that cross component and trust boundaries.
  • Use experience, threat analysis, architecture knowledge, source code, and observed system behavior to choose targets and guide investigations.
  • Apply frontier and open-weight models, agents, and other AI capabilities across the research lifecycle: reconnaissance, code analysis, hypothesis generation, exploit development, and verification.
  • Design and tune research harnesses that give models the right context, tools, execution environments, and feedback to investigate real targets.
  • Develop custom tooling, including analysis utilities, fuzzers, agents, test harnesses, proofs of concept, and full exploits, when it helps answer the research question.
  • Convert promising model output into defensible security evidence: reproduce findings, rule out false claims, establish preconditions, and distinguish a possible weakness from a demonstrated vulnerability with real impact.
  • Improve the reliability and reach of AI-driven research by tackling false positives, false negatives, context limits, nondeterminism, and reproducibility.
  • Work directly with Engineering and Product Security to communicate findings, support remediation, surface related risks, and verify fixes.
  • Share tools, techniques, and lessons learned so Security Assurance and the broader Security org can enhance their processes through the use of AI.

Requirements

  • 5+ years of hands-on vulnerability research, offensive security, application security, or penetration testing, with a demonstrated track record of choosing targets, forming and revising hypotheses, and establishing exploitability and impact in complex software or production systems.
  • Hands-on experience running offensive workflows with frontier and open-weight models, including model selection where refusal behavior would otherwise block legitimate exploit development.
  • Experience assessing the quality of AI-driven research processes, including identifying false positives, missed vulnerabilities, unstable results, and reproducibility gaps, as well as sound judgment on agent architecture trade-offs: when constrained, orchestrated pipelines deliver reproducible results and when open-ended tool-using agents are worth the nondeterminism.
  • Deep technical expertise in at least one security domain: web applications and APIs, Java applications, cloud or service infrastructure, client software, operating systems, or reverse engineering.
  • Strong programming and debugging skills: ability to read unfamiliar code, build research tooling, write proofs of concept, and trace behavior across system boundaries.
  • Strong intuition for attack surfaces, trust boundaries, exploitability, and security impact, combined with the persistence to work independently on open-ended research with no guaranteed path or outcome.
  • Ability to communicate findings clearly to both technical and nontechnical audiences, covering what the evidence shows, what remains uncertain, and why it matters.

Conditions

Minimum:

$124,000.00

Maximum:

$271,200.00&xa;&xa;

In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value.

Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience.

We also have a location based compensation structure; there may be a different range for candidates in this and other locations

At Zoom, we offer a window of at least 5 days for you to apply because we believe in giving you every opportunity. Below is the potential closing date, just in case you want to mark it on your calendar. We look forward to receiving your application!

Anticipated Position Close Date:

10/14/26

Ways of Working

Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting.

Benefits

  • As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information.

Where you’d work

Fully remote

You can work from

  • United States

About the company

Zoom

  • Industry: SaaS

Also hiring in San Jose, United States, Seattle, United States, United States and 4 more places

9 of their 28 open roles are remote

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 22 checks run
  • 2 red flags

Still hiring?

15 checks

1 red flag

How crowded?

7 checks

1 red flag

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details12 facts · Role, Location, Compensation, Employment, Company
Seniority
Senior
Type
Full-time
Equity
Equity offered
Industry
SaaS
Specialty
Security
Region
United States
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
5+ years

Location

Work model
Remote
Region
United States
Remote from
  • United States

Compensation

Salary
$124,000 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
SaaS

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason