Jobs / United States / Elasticsearch INC

GenAI Security - Principal Security Research Engineer

Elasticsearch INC · 🇺🇸 United States

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 20 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 8 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Elasticsearch INC paid sponsored hires in similar roles1 certified filing for “Security Research Engineer” (Information Technology Project Managers) in IL: $118k–$118k, median $118k. Most were filed at wage level I (100%) — 1 lottery entry, ≈15% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Elasticsearch INC

20 H-1B filings certified since Oct 2025

The US Department of Labor certified 20 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 8 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Elasticsearch INC →

About the role

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI. What is The Role As a Principal Security Research Engineer on the Threat Research and Detection Engineering (TRaDE) team, you'll play a key role in shaping the detection capabilities of Elastic Security. You'll work hands-on with detection engineering and threat research, focusing on enhancing our defenses, particularly in the areas of AI security. This position invites you to apply your solid security background and keen interest in offensive security validating detection methods, helping to create effective and reliable detection content that benefits the wider community. What You Will Be Doing • Design and carry out security tests for GenAI applications, agentic systems, and LLM-backed products. These tests will check for various attack types. They include prompt injection, indirect injection, retrieval poisoning, tool misuse, sensitive data extraction, and unsafe delegation to with the core purpose of building security protections • Investigate new multi-domain threat vectors and attack methodologies to stay ahead of emerging risks and translating these into new security protections (e.g. detection rules) • Create and present findings to enhance team knowledge and community awareness • Apply AI-assisted techniques to expand coverage and accelerate validation. This may include developing new capabilities and Elastic AI workflows to streamline our threat research and detection engineering processes What You Bring • You should have experience working with endpoint data and understand detection engineering GenAI pitfalls working with existing telemetry • You should have hands-on experience using LLM tools for security testing, research, or daily tasks. You need to understand how LLMs work. This includes context windows, tool use, RAG, and agentic chaining. Knowledge of AI testing tools or frameworks, such as Garak, PyRIT, PromptBench, Inspect AI, or similar (including personal research or experiments) is a plus. • You should have experience using AI-assisted development tools and modern AI/ML frameworks. These tools help you accelerate up feature development. They also help you debug complex systems and optimize existing codebases. You will generate telemetry, conduct threat research, and assist with detection engineering workflows. • Proven ability to seamlessly transition between different projects, codebases, or scrum teams based on dynamic business priorities. • You work autonomously and can drive decisions and results in a distributed team by leveraging asynchronous, direct, and transparent communication. • Previous successes in presenting findings and insights to technical audiences • Experience with Elastic Security Solution and proficiency in writing or validating detections using a query language (e.g. EQL, KQL, ESQL) is a bonus • Experience running penetration tests or vulnerability assessments on web applications, or APIs. Experience as a Red Team operator is also valuable. You should understand the OWASP Top 10 and have some exposure to the OWASP LLM Top 10 or MITRE ATLAS. Additionally, you need to be able to triage findings. You should communicate risks clearly to both technical and

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-08-21 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities