
Lead Security Engineer – Penetration Testing, AI Security
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in India.
• Spearhead Application Security programs across web, mobile, API, microservices, and cloud-native products.
• Perform architecture assessments, threat modeling, secure design and code evaluations, and practical security audits.
• Detect vulnerabilities in authentication, authorization, tenant isolation, business logic, data protection, and API security.
• Establish security standards, requirements, guidelines, and reusable secure engineering frameworks.
• Enhance security testing within CI/CD pipelines utilizing SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
• Lead risk-based vulnerability prioritization and resolution efforts with engineering teams.
• Create security automation and foster secure coding practices through guidance, documentation, and training.
• Oversee security assessments of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
• Evaluate AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.
• Execute adversarial testing for prompt injection, jailbreaking, sensitive data disclosure, system-prompt leakage, output manipulation, insecure tool usage, excessive agency, and model abuse.
• Analyze risks related to data poisoning, model inversion, training data extraction, adversarial evasion, and model exfiltration.
• Examine guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
• Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using Garak, PyRIT, or similar frameworks.
• Assess security and supply-chain risks tied to third-party models, AI platforms, and AI-enabled SaaS products.
• Generate security reports detailing evidence, risk ratings, business impact, and actionable remediation advice.
• Convey security risks effectively to developers, architects, product leaders, and executive stakeholders.
• Collaborate with external consultants, researchers, and bug bounty programs for specialized evaluations.
• Mentor engineers and contribute to cultivating a security-aware engineering culture.
• Stay updated with developments in Application Security, AI Security, and adversarial testing.
• Over 8 years of cybersecurity experience, with extensive hands-on knowledge in Application Security, product security, penetration testing, or security engineering.
• Experience in conducting threat modeling, architecture reviews, secure code evaluations, penetration testing, and vulnerability validation.
• 1 to 3 years of experience in AI Security, focusing on AI/ML security, adversarial testing of AI systems, or applied AI research with a security emphasis.
• Profound understanding of web, mobile, API, and cloud-native security, including OWASP guidelines and business logic vulnerabilities.
• Strong comprehension of OAuth 2.0, OIDC, JWT, SAML, and contemporary access-control models.
• Practical experience in DevSecOps with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
• Hands-on knowledge of Docker, Kubernetes, microservices, and cloud security.
• Proven experience in assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
• Understanding of prompt injection, jailbreaking, data leakage, insecure tool usage, excessive agency, model misuse, and AI supply-chain risks.
• Familiarity with OWASP guidelines for LLM applications, MITRE ATLAS, NIST AI RMF, and associated AI security practices.
• Proficiency in programming or scripting languages such as Python, Go, JavaScript, Bash, or a similar language.
• Excellent written and verbal communication abilities.
• Preferred: experience in building or scaling Application Security practices within a SaaS or product-led technology organization.
• Preferred: hands-on experience in red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.
• Preferred: experience in developing security automation, internal testing tools, or reusable security guardrails.
• Preferred: contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.
• Preferred: relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.
• Remote work available in India.
• Global, remote-first work environment.
• Equal Employment Opportunity Employer.
• Opportunity to collaborate with a global team across 15+ countries.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.