Назад
Company hidden
5 дней назад

Red Team Engineer (AI)

Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Red Team Engineer (AI) (Fintech/Cybersecurity): Conducting deep penetration tests across web applications, APIs, cloud services, and AI-integrated features with an accent on exploit development, multi-tenant SaaS security, and offensive automation. Focus on proving complex attack paths, assessing prompt injection and agentic abuse risks, and building repeatable validation tooling that drives remediation.

Location: On-site at 999 Peachtree Street Northeast, Suite 2750, Atlanta, Georgia, United States

Company

hirify.global is a global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related technology services through a large multi-tenant SaaS portfolio.

What you will do

  • Conduct manual and automated penetration tests of web applications, REST and GraphQL APIs, microservices, and high-risk application changes.
  • Test authentication, authorization, session management, OAuth/OIDC, JWT, MFA, tenant isolation, business logic, and injection vulnerabilities.
  • Assess AI-integrated features, LLM-powered applications, chatbots, and agentic systems for prompt injection, data leakage, model manipulation, excessive agency, and insecure output handling.
  • Test AWS and Azure environments, including serverless functions, containers, managed services, IAM configurations, API gateways, WAFs, and network segmentation.
  • Build offensive security tooling, AI-assisted attack workflows, automated validation tests, scanners, exploit scripts, and CI/CD-integrated security checks.
  • Produce evidence-based reports, validate remediation, support bug bounty triage, and participate in purple team exercises with AppSec, development, detection engineering, and SOC teams.

Requirements

  • Hands-on experience with web application, API, cloud, and offensive security testing.
  • Ability to identify and prove vulnerabilities involving authentication, authorization, privilege escalation, injection, business logic, and cross-tenant access.
  • Experience with source-code-assisted testing and cloud security across AWS and Azure.
  • Ability to use AI tools and assess AI-integrated applications for offensive security risks.
  • Experience building custom security tooling, exploit scripts, automated tests, and clear penetration testing reports.
  • Comfort with an on-site presence in Atlanta to support collaboration, team leadership, and cross-functional partnership.

Culture & Benefits

  • AI-first security organization focused on building with AI and securing AI.
  • Medical, dental, vision, life, and disability insurance.
  • Paid time off, holidays, paid sick time, maternity and paternity leave, and Employee Assistance Program support.
  • 401(k) with immediate vesting, HSA and FSA options, commuter benefits, and employee discounts.
  • Fertility benefits, wellness resources, Calm app subscription, legal plan options, and pet insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →