This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Software Developer - Offensive AI (Global Security) based in Canada.
As a Senior Software Developer, you will build AI-powered capabilities that enhance offensive security operations in complex and critical environments. You will design and develop agentic workflows, production-grade services, APIs, and automation that support Red Team activities from reconnaissance through reporting and post-exploitation. The role combines modern AI engineering with software architecture, cloud technologies, and cybersecurity. You will apply RAG, vector search, and retrieval techniques to make offensive research and operational knowledge more accessible to security practitioners. You will also help evaluate and improve the reliability, observability, explainability, and safety of AI-enabled systems used in live operations. Working closely with Red Team operators, researchers, and defensive security teams, you will turn emerging ideas into practical tools that strengthen organizational resilience.
Accountabilities:
- Design, build, and maintain agentic workflows and AI-enabled tooling supporting Red Team operations, including reconnaissance, analysis, reporting, and post-exploitation activities.
- Translate operator requirements, security research, and prototypes into production-grade services, APIs, automation pipelines, and reusable engineering solutions.
- Apply Retrieval-Augmented Generation (RAG), vector search, and retrieval-based approaches to make offensive security knowledge and research accessible and actionable in real time.
- Instrument and evaluate agentic systems using observability and AI evaluation tooling to ensure outputs are reliable, explainable, measurable, and safe for operational use.
- Continuously test, tune, and validate agent behavior against real-world security use cases, incorporating feedback from operators and researchers.
- Partner directly with Red Team professionals to identify opportunities where AI and automation can reduce manual effort, accelerate workflows, or enable new offensive tradecraft.
- Support Purple Team exercises by developing tooling that helps translate offensive findings into actionable detection and defensive security improvements.
- Communicate technical designs, capabilities, limitations, and implementation considerations clearly to Red Team leadership and internal stakeholders.
- Contribute to software architecture and engineering practices that promote scalability, maintainability, reliability, and secure production deployment.
Requirements
- Bachelor’s degree in Computer Science or a related technical discipline.
- 4+ years of professional software development experience, with a strong understanding of software design patterns, architecture, and the software development lifecycle.
- Hands-on experience building agentic workflows or working with frameworks such as LangGraph, Google ADK, or OpenAI Agents SDK.
- Experience with AI evaluation, monitoring, and observability platforms such as LangSmith, Langfuse, or Weights & Biases.
- Practical experience with RAG, vector search, embeddings, or other retrieval-based AI systems.
- Strong backend development experience and experience building REST APIs using frameworks such as FastAPI, Flask, Spring, or equivalent technologies.
- Experience with event-driven architectures, message queues, asynchronous processing, or similar distributed workflow patterns.
- Comfortable working with cloud platforms such as AWS and Azure, CI/CD pipelines including GitHub Actions, and container technologies such as Docker and Kubernetes.
- Commitment to writing clean, maintainable, scalable, and production-grade code.
- Strong critical-thinking and problem-solving skills, with the ability to work effectively in ambiguous and rapidly evolving environments.
- Experience in Red Team operations, penetration testing, adversary emulation, vulnerability research, or other cybersecurity functions is highly desirable.
- Genuine interest in ethical hacking, offensive security, malware, Red Teaming, and emerging offensive cyber operations.
- Relevant technical and offensive security certifications such as OSCP, OSCE, OSED, OSEE, GXPN, GPEN, or GWAPT are considered an advantage.
- Financial industry experience is a strong asset but is not required.
- Strong communication, collaboration, decision-making, and stakeholder-management abilities.
Benefits
- Comprehensive Total Rewards Program including bonuses and flexible benefits.
- Competitive compensation, with commissions and stock opportunities where applicable.
- Dedicated annual budget for professional training and conference attendance.
- Access to industry-leading offensive security, AI, cloud, and technical training opportunities.
- Exposure to advanced topics such as AI Red Teaming, adversary simulation, vulnerability research, identity security, and offensive tradecraft.
- Coaching, mentorship, and career development support from experienced leaders.
- Opportunity to work alongside offensive, defensive, and threat-hunting security professionals.
- Hybrid-remote working environment supporting flexibility and work-life balance.
- Opportunity to work on challenging projects in complex and critical technology environments.
- Ability to make a meaningful and lasting impact on cybersecurity and organizational resilience.
- Opportunities to take on progressively greater responsibilities and expand your technical scope.
- Dynamic, collaborative, progressive, and high-performing team environment.
- Full-time, regular salaried position based in Toronto, Canada, with a standard 37.5-hour work week.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1