Join Artemis: Shape the Future of AI-Driven Cyber Defense
Artemis is at the vanguard of AI-driven defense, empowering companies to outmaneuver the most sophisticated threats in an era where AI battles AI on the cyber battlefield. We are pioneering a new paradigm in security, backed by titans like First Round Capital, Brightmind, and an impressive roster of the cybersecurity industry's most influential Operators.
Our co-founders, Shachar (ex-Palo Alto Networks, AWS, Demisto) and Dan (ex-Abnormal Security, Twitter), bring a proven track record of building, launching, and scaling cybersecurity products trusted by tens of thousands of customers. Their profound expertise across customer needs, cutting-edge technology, and deep security insights fuels our ambitious vision.
You'll join an exceptionally strong team of software engineers, AI researchers, security engineers, and product designers from elite institutions and companies including Google, Abnormal AI, Wiz, Meta, AWS, CERN, and SentinelOne. We are expanding rapidly and seeking passionate builders to fortify our growing customer base and redefine cyber resilience.
What You'll Do: Responsibilities That Define the Future
Spearhead Scalable Adversary Emulation: Design and develop reusable scenarios and automation to meticulously reproduce attacker behaviors and multi-stage attack chains across cloud, identity, endpoint, SaaS, AI, and data environments. Prioritize your work using real-world threat intelligence, customer risk profiles, and critical detection coverage gaps.
Validate Detections End-to-End: Meticulously trace emulated activity through every stage: collection, normalization, enrichment, detection, and investigation. Verify expected findings and evidence, pinpoint missed detections and visibility gaps, and accurately distinguish between successful prevention and successful detection.
Uncover Emerging AI System Attacks: Deeply investigate vulnerabilities such as prompt injection, MCP and tool abuse, retrieval poisoning, excessive agent privileges, and unauthorized actions within AI systems. Chain weaknesses across applications, agents, and integrations to establish realistic impact and identify robust detection opportunities.
Map Sophisticated Data Plane Attack Paths: Explore and exploit abuses of service identities, integration tokens, permissions, and data access across databases, warehouses, object storage, and AI retrieval systems. Translate access, staging, export, and cross-platform attack paths into repeatable, actionable scenarios.
Dissect and Reproduce Emerging Exploits: Assess relevant vulnerability disclosures and exploit research in isolated lab environments. Establish prerequisites, practical impact, and observable behavior, then translate these findings into powerful detection hypotheses and bounded emulations.
Engineer Safe Customer Environment Testing: Develop authorized emulations and control checks with crystal-clear scope, robust preflight checks, least-privilege access, execution limits, essential stop controls, and verified cleanup. Document prerequisites, expected effects, and delineate scenarios requiring isolated lab execution.
Drive Continuous Security Validation: Integrate advanced emulation scenarios with detector tests and core engineering workflows. Develop sophisticated AI evaluation harnesses incorporating attack variations, multi-turn tests, and benign controls, measuring outcomes as models, tools, permissions, and detections evolve.
Translate Research into Tangible Defenses: Contribute directly to the development of new detections, hunt logic, critical telemetry requirements, and comprehensive regression tests. Partner closely with engineering and customer owners to drive findings through remediation, retesting, and verification against both malicious and benign behaviors.
Forge Strong Purple-Team Partnerships: Lead purple-team exercises with SOC teams and customers, clearly explaining findings and limitations, and equipping analysts with the evidence and guidance needed to investigate emulated behaviors effectively. Leverage AI to accelerate research and tooling, while independently verifying generated actions and conclusions.
What You'll Bring: Core Qualifications
5+ years of hands-on cybersecurity experience, with substantial offensive security, red teaming, adversary emulation, or security research work; equivalent demonstrated expertise is welcome.
Strong Python skills and a proven track record of building reusable security tools leveraging APIs, SDKs, Git, code review, and automated testing practices.
Deep practical expertise in at least one cloud or identity ecosystem, coupled with a nuanced understanding of permissions, service identities, sessions, and data access.
Practical web/API security knowledge and experience chaining weaknesses across authorization boundaries into meaningful, impactful attack paths.
Demonstrated experience reproducing complex attacks in controlled environments and effectively connecting the resulting behavior to audit logs, detection logic, and investigation evidence.
Experience assessing AI applications or agent workflows, or a strong portfolio of offensive research into these cutting-edge systems.
Sound judgment in sensitive environments: the ability to define scope, anticipate side effects, limit impact, protect data, and meticulously verify cleanup.
Clear and concise communication skills, with the ability to own projects from initial research through implementation, operational use, and verified outcomes.
Bonus Points For:
Experience with Atomic Red Team, MITRE ATT&CK and ATLAS, purple teaming, or continuous security validation.
Proficiency with SQL, detection-as-code methodologies, and cloud, identity, SaaS, or endpoint telemetry.
Hands-on work with MCP servers, RAG systems, model gateways, or repeatable AI evaluations.
Experience assessing data warehouses, object storage, Kubernetes, CI/CD systems, or software supply chains.
Public contributions to offensive tooling, emulation frameworks, detection content, or published security research.
Experience building isolated labs and enabling customers to effectively operate security tooling.
Why Join Artemis? Elevate Your Impact.
Ignite Real-World Impact: Your tools and research will directly harden enterprises against sophisticated, emerging threats, making a tangible difference in the fight against cybercrime.
Pioneer the AI-Security Frontier: Work shoulder-to-shoulder with brilliant security and AI engineers to test and define emerging attack surfaces, turning groundbreaking discoveries into practical, resilient defenses.
End-to-End Ownership: Take true ownership of your ideas, driving them from initial research and conceptualization to working capabilities deployed across our platform and within customer environments.
Collaborate with Elite Practitioners: Partner directly with industry-leading detection engineers, researchers, and analysts who will integrate your work, measure its profound impact, and amplify its reach.
Compensation
We offer a highly competitive compensation package ranging from $180,000 – $220,000 per year, complemented by a top-of-market equity component. Compensation is determined by a variety of factors, including a candidate’s professional experience, skills, and market conditions. Final offer amounts may vary from the amounts listed.