Agoda
Company
AI Security Researcher
Job Description
About Agoda
At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world.
Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide.
No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.
• Assess and attempt to compromise Model Context Protocol (MCP)–based systems and other tool-calling / plugin ecosystems.
• Build and automate security testing workflows involving multiple LLM models, APIs, and tools (e.g., Jupyter notebooks, orchestration frameworks).
• Perform offensive security testing and red teaming of AI-driven products, including API manipulation and integration abuse.
• Research and analyze security weaknesses in Large Language Models (LLMs), Generative AI systems, and their surrounding infrastructure.
• Contribute to in-house guardrail design: define, implement, and test safety and security guardrails for LLMs and AI automations.
• Propose and evaluate defensive controls: input/output filtering, policy enforcement, monitoring, anomaly detection, and non-AI controls to secure AI systems.
• Translate research findings into practical engineering requirements and collaborate closely with product and engineering teams to implement fixes and mitigations.
• Stay current with the OWASP Top 10 for LLM / GenAI and other emerging AI security standards, frameworks, and threat models.
• Produce clear technical documentation, proof-of-concepts, and internal knowledge sharing on AI security best practices and new attack/defense techniques.
- Bachelors in Computer Science or related degree.
- Experience 2-5 years in offensive cybersecurity.
- Good communication skills in English to communicate security risks to other teams.
- Deep understanding of LLMs and Generative AI (architectures, prompt processing, context windows, system prompts, tool use, fine-tuning, RAG, etc.).
- Hands-on experience with jailbreaking and red-teaming chatbots and AI agents (e.g., prompt injection, role confusion, data leakage, safety bypasses).
- Strong offensive security background:
- Experience with API security testing and manipulation.
- Prior red teaming, penetration testing, or adversarial testing experience.
- Bug bounty / HackerOne or similar track record is a strong plus.
- Scripting knowledge (Python, PowerShell) and working with no-code flows for automation.
Discover more about working at Agoda
- Agoda Careers https://careersatagoda.com
- Facebook https://www.facebook.com/agodacareers/
- LinkedIn https://www.linkedin.com/company/agoda
- YouTube https://www.youtube.com/agodalife
Equal Opportunity Employer
At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.
We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy.
Disclaimer
We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.
Agoda
28 jobs posted
About the job
Similar Jobs
Discover more opportunities that match your interests
- 28 days ago
Causal AI Researcher
Dell Technologies
Eldorado Do Sul, BrazilView details - 28 days ago
Causal AI Researcher
Dell Technologies
Eldorado Do Sul, BrazilView details - 26 days ago
AI Security Architect
Salesforce
California - San FranciscoView details - 23 days ago
AI Security Architect
Salesforce
California - San Francisco$231K - $352KView details - 27 days ago
Anthropic AI Security Fellow
Anthropic
RemoteView details - 12 hours ago
AI Researcher — Summer Intern
Snorkel AI
Redwood City, CA (Hybrid); San Francisco, CA (Hybrid)View details - 16 days ago
Cybersecurity Engineer, Product/AI Security
Visa
Bellevue, WA, USView details - 21 days ago
Causal AI Researcher (Brazil, Remote)
Dell Technologies
Sao Paulo, BrazilView details - 21 days ago
Causal AI Researcher (Brazil, Remote)
Dell Technologies
Sao Paulo, BrazilView details - 30 days ago
AI Strategist
Distyl
San FranciscoView details
Looking for something different?
Browse all AI jobs