
AI Security Lead – Offensive
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Spain.
• Spearhead initiatives for AI-driven penetration testing, merging conventional offensive security techniques with AI-enhanced capabilities.
• Develop and refine offensive security services, methodologies, assessment frameworks, and delivery models.
• Evaluate web applications, APIs, cloud environments, and AI-powered systems to uncover vulnerabilities and security threats.
• Assess the security of LLM-based applications and AI agents, focusing on concerns such as prompt injection, data leakage, excessive permissions, and insecure tool execution.
• Assist organizations in transforming their penetration testing programs by enhancing assessment capacity and decreasing delivery times while maintaining quality.
• Promote Secure SDLC and DevSecOps initiatives by integrating security measures into engineering workflows and CI/CD pipelines.
• Create automation, tools, and prototypes that enhance efficiency and can be reused across various engagements.
• Serve as a trusted advisor to CISOs, architects, engineering teams, and security leaders.
• Mentor and cultivate a multidisciplinary team of specialists in offensive security, application security, and DevSecOps.
• Over 7 years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing.
• Proven experience leading technical teams or managing complex security engagements.
• Extensive hands-on experience with web application and API security assessments.
• Strong grasp of authentication, authorization, business logic vulnerabilities, and exploit validation.
• Demonstrated experience in implementing or enhancing Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows.
• Practical experience utilizing LLMs, AI agents, or AI-based security tools to boost testing and automation efforts.
• Experience in integrating security within CI/CD pipelines and contemporary cloud environments.
• Familiarity with application security tools such as SAST, DAST, Software Composition Analysis, and Secrets Scanning.
• Proficient programming or scripting skills, preferably in Python or PowerShell.
• Experience with offensive security tools like Burp Suite, Nmap, or equivalent technologies.
• Understanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution.
• Exceptional communication skills, capable of conveying technical findings to both technical and non-technical audiences.
• Proficiency in both Spanish and English.
• Certifications such as OSCP, OSWE, CRTO, or GIAC are advantageous.
• Experience in developing security methodologies, frameworks, or internal security services is a plus.
• Background in consulting or client-facing security engagements is beneficial.
• Experience leading security transformation initiatives is desirable.
• Knowledge of Azure and GitHub security ecosystems is a bonus.
• Flexible schedule of 35 hours per week.
• Option for fully remote work.
• Flexible compensation options (restaurant, transport, and childcare support).
• Comprehensive health insurance at no cost, with a co-payment for dental services.
• Individual budget allocated for training or equipment, along with free Microsoft certifications.
• English language lessons provided.
• One day off for birthdays.
• Monthly bonus to cover home electricity and internet expenses.
• Discounts on gym memberships and sports activities.
• Annual team-building event known as Plain Camp.
• Additional perks including attendance at events and speakers, welcome pack, baby basket, Christmas basket, and an employee discount portal.
• Selection process involves a phone screen followed by two interviews with the team.
GSB Solutions
GSB Solutions
Deep Fission
Veeam Software
Get handpicked remote jobs straight to your inbox weekly.