Offensive Security Engineer
Paris-based AI company building frontier models, AI applications, developer tools, and compute infrastructure for enterprise and public-sector deployments.
About Mistral AI
Mistral AI develops open-weight and commercial language models and provides a full-stack AI platform spanning agents, application development, custom-model training, APIs, and AI cloud infrastructure.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will hunt for vulnerabilities across agentic applications, cloud infrastructure, and foundational models. You will conduct penetration testing, run red and purple team exercises, automate offensive tooling, communicate findings, and contribute attacker-informed input to threat modeling, risk assessment, and architectural decisions.
Requirements
- 7+ years of offensive security experience or equivalent exceptional expertise
- Knowledge of AI/ML security risks, including prompt injection, data leakage, model manipulation, and dynamic UI abuse
- Experience with Kubernetes and containerized environments
- Experience with AWS, GCP, or Azure cloud-native architectures
- Experience with CI/CD pipelines and GitHub security best practices
- Knowledge of macOS/Linux internals
- Experience with Python and React-based applications
- Experience with data science toolchains and AI/ML infrastructure
- Ability to build tools and automate offensive workflows
- Knowledge of trust boundaries and risk assessment
- Communication skills for conveying technical risks
Responsibilities
- Hunt for vulnerabilities in agentic applications, cloud infrastructure, and foundational models
- Design and execute red and purple team exercises
- Partner with defensive functions to improve detection engineering and incident response
- Conduct penetration testing across AI workflows, infrastructure, and user-facing interfaces
- Build and automate offensive security tooling
- Communicate risks and mitigations to technical and non-technical stakeholders
- Contribute attacker-informed perspectives to threat modeling, risk assessment, and architecture
Benefits
- Healthcare coverage
- Parental leave
- Retirement plans
- Relocation support
- Wellness programs
- Meal allowances
- Transportation allowances
- Location-specific perks
