We hire for what you have broken.
Not years served, not certifications, not the last logo on your badge. Show us something you took apart that its builders were sure was closed, and how you proved it. That is the filter.
Senior offensive security operator.
You lead adversarial testing against production systems: models, agents, pipelines, applications, and the rest of the software stack, including the authority boundaries between them. AI is where we go deepest. You scope the work with the client, run the attack, prove the finding, and stay for the part where it gets fixed.
Singapore preferred. Strong APAC-remote candidates considered.
Run engagements end to end
Scope, attack, findings, hardening, retest. You are the senior name on the work, not a pair of hands inside someone else’s method.
Attack the system properly
Direct and indirect prompt injection, agent tool-abuse, authority-boundary and confused-deputy escalation, RAG and model supply chain, plus the applications, APIs, and infrastructure around them. Not commodity jailbreak prompts.
Close the loop into defense
Findings become concrete design and control changes the client’s engineers can ship, verified under the same pressure that broke them.
Build the workbench with us
Encode what you know as attack packs mapped to a coverage taxonomy, so the next engagement starts ahead of where the last one finished.
The bar.
- Real offensive delivery against production systems. Red team or penetration testing that someone paid for and acted on.
- Depth in attacking AI systems, or the demonstrated ability to get there fast. Agents holding real authority are the interesting part.
- Cloud and Kubernetes literacy. The AI infrastructure attack surface is most of the surface.
- Evidence-grade work. You prove findings and you do not inflate severity. A finding you cannot reproduce is not a finding.
- Senior communication. You can sit across from a CTO or CISO and be the person who signs off.
- Reverse-engineering depth: binaries, toolchains, vendor components on the AI path.
- Experience with agent frameworks, fine-tuning, or building your own tooling.
- Published research, CVEs, advisories, or serious CTF results in pwn and RE.
- Singapore or APAC network and market knowledge.
We still read it.
If you are early but the instinct is obviously there: a homebrew release, a from-scratch reversing writeup, a glitch or coldboot result, a fuzzer you built because the existing one annoyed you. Send it. We would rather see one thing you broke properly than a CV that lists ten tools.
We work with people who publish responsibly. Research ethos, not piracy and nothing done to systems you had no permission to touch.
Show the work.
Send a note to hello@serpio.ai with three things: what you broke, how you proved it, and why adversarial testing of production systems is where you want to spend the next few years.
Links beat prose. A writeup, a repo, an advisory, a video of the thing failing. No cover-letter theatre, and you will get a real answer either way.
hello@serpio.ai →