Startups · AI

Software Engineer - Offensive Security

GhostEye · New York, NY, US · On-site

← All jobs
About GhostEye

Your always-on red team. Backed by Y Combinator.

About the role

Attackers already use synthetic voice and video, and the volume is climbing fast. They call help desks and sound like your CFO. They join video calls as an executive who never joined. Most companies have no idea whether their people hold up against this. The only honest way to find out is to run it against them.

What they're looking for

  • You've shipped applied AI to production, not just prototyped it. Real users, real latency budgets, real failure modes
  • Depth in one of: real-time speech (recognition, synthesis, voice conversion, streaming audio), generative video or face synthesis, or LLM engineering with retrieval, tool use, and evaluation
  • You're good at latency. Real-time pipelines, WebRTC, or low-latency inference count for more here than model training
  • You can evaluate systems with fuzzy success criteria and design experiments that give reproducible answers
  • You treat data as infrastructure. You've owned an annotation pipeline, an eval set, or a feedback loop, and you know label quality drives model quality more than architecture does
  • You work without much direction. You'll pick the problems as often as you're handed them
More about this role

Most security programs tell companies whether they appear compliant. GhostEye tells them whether they can withstand a real attack. We're building the always-on red team for modern enterprises. GhostEye emulates the attacks adversaries use today, including help-desk vishing, deepfaked executives, MFA fatigue, and the technical payloads that follow. We identify what is actually exploitable, help customers close the gaps, and retest until the fixes hold.

Our founder previously led red-team work at BlackRock and conducted offensive cyber operations at MITRE. We're bringing that experience to one of cybersecurity's hardest problems: helping organizations continuously test their defenses against the attacks they actually face.

Attackers already use synthetic voice and video, and the volume is climbing fast. They call help desks and sound like your CFO. They join video calls as an executive who never joined. Most companies have no idea whether their people hold up against this. The only honest way to find out is to run it against them.

That's what you'll build. You'll own the AI behind our social engineering simulations: voice agents that can hold a live help-desk call, synthetic video...

Read the full posting on GhostEye's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.