Lead Security Engineer – Penetration Testing, AI Security

Posted Sep 9

This is a fully remote position, open to applicants in India.

📋 Description

• Spearhead Application Security programs across web, mobile, API, microservices, and cloud-native products.

• Perform architecture assessments, threat modeling, secure design and code evaluations, and practical security audits.

• Detect vulnerabilities in authentication, authorization, tenant isolation, business logic, data protection, and API security.

• Establish security standards, requirements, guidelines, and reusable secure engineering frameworks.

• Enhance security testing within CI/CD pipelines utilizing SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.

• Lead risk-based vulnerability prioritization and resolution efforts with engineering teams.

• Create security automation and foster secure coding practices through guidance, documentation, and training.

• Oversee security assessments of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.

• Evaluate AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.

• Execute adversarial testing for prompt injection, jailbreaking, sensitive data disclosure, system-prompt leakage, output manipulation, insecure tool usage, excessive agency, and model abuse.

• Analyze risks related to data poisoning, model inversion, training data extraction, adversarial evasion, and model exfiltration.

• Examine guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.

• Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using Garak, PyRIT, or similar frameworks.

• Assess security and supply-chain risks tied to third-party models, AI platforms, and AI-enabled SaaS products.

• Generate security reports detailing evidence, risk ratings, business impact, and actionable remediation advice.

• Convey security risks effectively to developers, architects, product leaders, and executive stakeholders.

• Collaborate with external consultants, researchers, and bug bounty programs for specialized evaluations.

• Mentor engineers and contribute to cultivating a security-aware engineering culture.

• Stay updated with developments in Application Security, AI Security, and adversarial testing.


⛳️ Requirements

• Over 8 years of cybersecurity experience, with extensive hands-on knowledge in Application Security, product security, penetration testing, or security engineering.

• Experience in conducting threat modeling, architecture reviews, secure code evaluations, penetration testing, and vulnerability validation.

• 1 to 3 years of experience in AI Security, focusing on AI/ML security, adversarial testing of AI systems, or applied AI research with a security emphasis.

• Profound understanding of web, mobile, API, and cloud-native security, including OWASP guidelines and business logic vulnerabilities.

• Strong comprehension of OAuth 2.0, OIDC, JWT, SAML, and contemporary access-control models.

• Practical experience in DevSecOps with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.

• Hands-on knowledge of Docker, Kubernetes, microservices, and cloud security.

• Proven experience in assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.

• Understanding of prompt injection, jailbreaking, data leakage, insecure tool usage, excessive agency, model misuse, and AI supply-chain risks.

• Familiarity with OWASP guidelines for LLM applications, MITRE ATLAS, NIST AI RMF, and associated AI security practices.

• Proficiency in programming or scripting languages such as Python, Go, JavaScript, Bash, or a similar language.

• Excellent written and verbal communication abilities.

• Preferred: experience in building or scaling Application Security practices within a SaaS or product-led technology organization.

• Preferred: hands-on experience in red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.

• Preferred: experience in developing security automation, internal testing tools, or reusable security guardrails.

• Preferred: contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.

• Preferred: relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.


🏝️ Benefits

• Remote work available in India.

• Global, remote-first work environment.

• Equal Employment Opportunity Employer.

• Opportunity to collaborate with a global team across 15+ countries.

People also viewed

Robots & Pencils1 day ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$56 – $77/hour
ApplyView job
Latitude IT Solutions | SDVOSB1 day ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$102k – $118k/year
ApplyView job
Latitude IT Solutions | SDVOSB1 day ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119k – $137k/year
ApplyView job
11:11 SYSTEMS2 days ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
11:11 SYSTEMS2 days ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
11:11 SYSTEMS2 days ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers