Sobre este puesto de Senior AI Security Researcher en Agoda
About Agoda
At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world.
Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide.
No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.
The Opportunity: AI Security Researcher
We are looking for an AI Security Researcher with a strong offensive security mindset, published CVEs, and the ability to use AI as a hacking tool. The core of this role is finding real exploitable issues before attackers do, prioritizing external (internet-facing) exploits, then internal ones.
You will build autonomous agents that research and hack on the fly by interacting with AI, and you will jailbreak AI systems.
The ideal candidate has a strong offensive security background, has already shifted to using AI to find bugs, and is already hands-on and comfortable working this way.
Key Responsibilities
- Proactively find, exploit, and document real-world vulnerabilities, prioritizing external (internet-facing) attack paths, then internal ones.
- Discover these issues before attackers do, with working proofs of concept and demonstrated impact.
- Build autonomous agents that hunt, attack, and iterate on the fly by interacting with AI models and tools.
- Use and develop AI-driven offensive workflows (multi-model setups, tool-calling, notebooks, orchestration) for continuous hunting.
- Apply deep offensive security skills (API abuse, authentication and access control, secrets, misconfiguration, red teaming) with AI in the loop.
- Produce CVE-quality research outcomes and drive findings through to engineering fixes.
- Design, execute, and document jailbreaks, prompt injection attacks, model evasion, data exfiltration, and other offensive techniques against AI systems.
- Assess and attempt to compromise Model Context Protocol (MCP)–based systems and other tool-calling / plugin ecosystems.
- Build and automate security testing workflows involving multiple models, APIs, and tools (e.g., Jupyter notebooks, orchestration frameworks).
- Perform offensive security testing and red teaming of AI-driven products, including API manipulation and integration abuse.
- Research security weaknesses in models and the infrastructure around them.
- Contribute to in-house guardrail design: define, implement, and test safety and security guardrails for models and AI automations.
- Propose and evaluate defensive controls: input/output filtering, policy enforcement, monitoring, anomaly detection, and non-AI controls to secure AI systems.
- Translate research findings into practical engineering requirements and collaborate closely with product and engineering teams to implement fixes and mitigations.
- Work with multiple teams, explain risk and impact clearly, and present findings to different teams and C-level stakeholders.
- Produce clear technical documentation, proof-of-concepts, and knowledge sharing on AI security practices and new attack/defense techniques.
What you'll Need to Succeed:
Must have
- Bachelor's in Computer Science or related degree.
- 2–7 years in offensive cybersecurity.
- Published CVE(s).
- Strong offensive security knowledge: API security testing and manipulation; prior red teaming, penetration testing, or adversarial testing.
- Hands-on jailbreak experience (prompt injection, role confusion, data leakage, safety bypasses, and similar).
- Ability to work with multiple teams, explain risk and impact, and present to different teams and C-level stakeholders.
- Good communication skills in English.
- Experience handling and maintaining production-level code.
Strongly recommended
- Proven exploits or write-ups that used AI (models/agents) to find or exploit bugs.
- Experience building autonomous agents that interact with AI to attack or test systems on the fly.
- Already using AI in day-to-day offensive work to find bugs, and comfortable with that shift.
- Bug bounty / HackerOne or similar track record.
- Conference presentations.
Please review our Hiring Process Guidelines before your interview — click here to learn how interviewing at Agoda works.
Discover more about working at Agoda
- Agoda Careers https://careersatagoda.com
- Facebook https://www.facebook.com/agodacareers/
- LinkedIn https://www.linkedin.com/company/agoda
- YouTube https://www.youtube.com/agodalife
Equal Opportunity Employer
At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.
We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy.
Disclaimer
We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.