Lead Offensive Secuirty Engineer
About this role
About Us:
webAI is pioneering the future of artificial intelligence by establishing the first distributed AI infrastructure dedicated to personalized AI. We recognize the evolving demands of a data-driven society for scalability and flexibility, and we firmly believe that the future of AI lies in distributed processing at the edge, bringing computation closer to the source of data generation. Our mission is to build a future where a company's valuable data and intellectual property remain entirely private, enabling the deployment of large-scale AI models directly on standard consumer hardware without compromising the information embedded within those models. We are developing an end-to-end platform that is secure, scalable, and fully under the control of our users, empowering enterprises with AI that understands their unique business. We are a team driven by truth, ownership, tenacity, and humility, and we seek individuals who resonate with these core values and are passionate about shaping the next generation of AI.
About the Role:
We are building the next generation of decentralized, on-edge AI infrastructure. Our platform enables intelligent systems to operate securely across distributed environments without relying on centralized cloud architectures.
We are seeking a Lead Offensive Security Engineer to think like an adversary and build defenses before attackers find the gaps. This is not a traditional application security or AI prompt security role. We're looking for an engineer who understands how complex distributed systems fail—from networking protocols and cryptographic trust models to peer-to-peer communication and decentralized architectures.
The ideal candidate has a deep offensive security background paired with expertise in distributed systems, protocol security, or cryptographic infrastructure. They thrive in unfamiliar technical environments, rapidly identify attack surfaces through first-principles thinking, and influence secure architecture across the entire engineering organization.
If you've broken, defended, or designed secure distributed protocols, decentralized infrastructure, P2P networks, or cryptographic systems, you'll be solving exactly the kinds of problems we're tackling.
Responsibilities:
Lead offensive security strategy across the software development lifecycle, championing secure-by-design engineering practices.
Perform threat modeling and security architecture reviews for decentralized AI systems, peer-to-peer networking, distributed protocols, and edge computing environments.
Conduct hands-on offensive security assessments, adversary emulation, logic probing, and exploit research across complex software systems.
Analyze distributed protocols for consensus failures, trust assumptions, network attacks, identity abuse, cryptographic weaknesses, and resiliency gaps — e.g., gossip/P2P overlay networks, replicated state, and capability- or identity-based authorization models.
Partner with engineering teams to review, harden, and guide the secure design of Rust networking libraries and distributed infrastructure.
Perform security-focused code reviews emphasizing exploitability, protocol correctness, and secure implementation.
Design and implement secure coding standards, automated security testing, and developer security tooling.
Evaluate and improve authentication, authorization, PKI, key management, secure communications, and cryptographic protocols.
Contribute offensive-security expertise to incident response and root-cause investigations, translating findings into long-term architectural improvements.
Research emerging attack techniques targeting distributed AI infrastructure, decentralized networking, cryptography, software supply chains, and modern distributed systems.
Serve as the technical leader for offensive security, influencing architecture decisions across engineering.
Qualifications:
Proven ability to rapidly master unfamiliar distributed systems and reason about their failure modes from first principles. Because our architecture is novel, there's no off-the-shelf playbook — independent, first-principles analysis matters more than deep familiarity with any single stack or tool.
10+ years of experience in Offensive Security, Product Security, Application Security, Secure Systems Engineering, or related cybersecurity disciplines.
Proven experience performing offensive security assessments against modern software platforms, including adversary emulation and real-world exploit path analysis.
Strong understanding of secure software development and SDLC security practices.
Experience securing distributed systems, peer-to-peer architectures, decentralized platforms, networking protocols, or large-scale infrastructure.
Deep knowledge around Cryptography, Authentication & Authorization, Secure Communications Protocols, Key Management Systems, Threat Modeling, Secure Code Review, Penetration Testing.
Experience or knowledge with systems programming languages such as Rust, Go, C/C++.
Excellent communication skills with the ability to influence engineers and technical leadership.
Offensive security certifications are a plus but not required: OSWE, OSCE/OSEP, GXPN, GWAPT, etc.
We at webAI are committed to living out the core values we have put in place as the foundation on which we operate as a team. We seek individuals who exemplify the following:
Truth - Emphasizing transparency and honesty in every interaction and decision.
Ownership - Taking full responsibility for one’s actions and decisions, demonstrating commitment to the success of our clients.
Tenacity - Persisting in the face of challenges and setbacks, continually striving for excellence and improvement.
Humility - Maintaining a respectful and learning-oriented mindset, acknowledging the strengths and contributions of others.
Benefits:
We strive to provide competitive benefits to all employees. The benefits listed in this posting generally apply to U.S.-based employees. For employees hired outside the United States, benefits may vary based on local law, country-specific requirements, and the employment platform or entity through which the employee is hired.
Competitive salary
Comprehensive health, dental, and vision benefits package
401(k) match
Equity options
$200/month Health & Wellness stipend
Continuing Education support
$500/year Function Health subscription
Free parking for in-office employees
Flexible Time Off (FTO)
Parental leave for eligible employees
Supplemental life insurance
webAI is an Equal Opportunity Employer and does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. We adhere to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, it is the policy of webAI to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works.
