
Senior Security Engineer – Red Team
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in India.
• Conduct advanced penetration tests and red team operations.
• Innovate new attack strategies and testing methodologies.
• Perform penetration testing on web applications, mobile applications, AI/LLM systems, and APIs.
• Evaluate Coupa's AI and LLM integrations for vulnerabilities such as prompt injection, jailbreaking, data poisoning, and model evasion.
• Create, implement, and manage AI agents for ongoing autonomous security assessments and vulnerability detection.
• Detect network and system vulnerabilities, providing recommendations for countermeasures or mitigating strategies.
• Execute penetration testing and remediation processes, along with reporting and advanced penetration methodologies.
• Advise development teams on secure coding practices, particularly concerning AI/ML model security.
• Act as an escalation point during significant security incidents, leading root-cause analysis and threat hunting efforts.
• Maintain, support, and enhance application security tools, standards, and processes, including SAST, DAST, WAF, and AI-based security analysis platforms.
• 3 to 8 years of experience in a comparable security-focused role, with hands-on AI-driven security testing.
• Bachelor's or Master's degree in Computer Science (or equivalent), or relevant experience.
• Practical experience in developing or utilizing autonomous, agent-based systems for security penetration testing.
• Proven ability to build and sustain cross-functional relationships.
• Extensive experience in web/API security, including attacks targeting AI/ML systems.
• Familiarity with AWS, Azure, or GCP cloud platforms.
• Direct experience managing and handling bug bounty programs.
• Proficient in one or more scripting languages, with a strong preference for Python in AI/ML development.
• Knowledge of OWASP Top 10, SANS Top 25, and OWASP Top 10 for Large Language Models.
• Understanding of PTES, OSSTMM, NIST, OSINT, and OWASP frameworks.
• Capability to translate technical security findings into actionable business risks for non-technical stakeholders and executives.
• Ability to collaborate effectively in a team setting.
• Relevant security certifications such as CEH, OSCP, GPEN, LPT, or EWPTX are advantageous, but not mandatory.
• Two paid wellness days off for all employees each year.
• A paid day off on your birthday or any other day within your birthday month.
• 40 hours of annual paid volunteer time off.
• Access to a free, confidential, 24/7/365 Employee Assistance Program for counseling and resources.
• Business travel medical, safety, pre-trip planning, and emergency support provided by Zurich Travel Assist.
• Monetary bonuses for successful employee referrals.
• Location-specific benefits packages, which include medical/dental insurance, retirement/pension plans, and life or accident protection.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.