5 дней назад
Offensive Security Engineer (AI)
42 800 - 60 500€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Offensive Security Engineer (AI) (Application Security/Cybersecurity): Perform penetration testing across applications, APIs, infrastructure, and AI-powered features while improving vulnerability remediation and secure development practices with an accent on web application security, vulnerability research, and AI risk analysis. Focus on building security automations, CI/CD controls, and practical defenses against LLM, agent, data exposure, and tool-permission risks.
Location: Barcelona, Spain; office-first hybrid setup with on-site work 80% of the week and remote work 20%.
Salary: €42,800–€60,500 annual base compensation, plus 7–10% variable performance pay paid quarterly and an ESOP plan.
Company
builds AI-powered business management software that centralizes HR, Finance, Talent, Operations, and IT workflows for companies of all sizes.
What you will do
- Perform proactive penetration testing across applications, APIs, infrastructure, and AI-powered features.
- Reproduce and validate vulnerability reports from bug bounty programs, internal testing, automated controls, and external research.
- Work with development teams to remediate findings and improve secure coding practices.
- Hunt recurring and legacy vulnerability patterns using root-cause analysis, incident history, and security findings.
- Build security automations, agents, tools, and CI/CD controls that help engineering teams identify and fix issues earlier.
- Assess AI security risks involving LLMs, agents, data access, tool permissions, prompt injection, RAG, and abuse scenarios.
Requirements
- At least 3 years of professional experience in Application Security, Offensive Security, or Penetration Testing.
- Mandatory experience with web application penetration testing.
- Degree in Engineering or Computer Science, with strong knowledge of web applications, databases, network protocols, operating systems, cybersecurity fundamentals, CVSS, testing methodologies, and security tooling.
- Fluency in scripting or programming languages used for security testing and automation, such as Python or Bash.
- Technical curiosity, critical reasoning, fast learning, and the ability to work across different security problems.
- Fluent English is required.
Nice to have
- BSCP or eWPTX certification.
- Experience with Ruby or Ruby on Rails applications.
- Knowledge of AI security topics, including LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoption.
Culture & Benefits
- Office-first, flexible working model with regular in-person collaboration and limited remote work.
- Private health insurance through Alan.
- Wellhub fitness benefits, Cobee expense savings, language classes, and office breakfast and fruit.
- Food discounts, pet-friendly offices, and a multicultural environment.
- Career Path framework with transparent progression expectations and salary ranges.
Hiring process
- Introductory call with a Talent Partner.
- Hiring Manager interview followed by a collaborative technical interview based on real-life problems.
- Final coffee chat with the CTO and VP of Engineering; the process is conducted remotely by videoconference.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →