Назад
Company hidden
8 дней назад

Lead Offensive AI Security (AI)

Формат работы
remote (только Spain)
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Offensive AI Security (AI): Leading AI-powered penetration testing, application security, and DevSecOps initiatives for web applications, APIs, cloud environments, and AI-enabled systems with an accent on LLM security, automation, and technical leadership. Focus on evaluating prompt injection and unsafe tool execution, building reusable security tooling, integrating controls into CI/CD pipelines, and mentoring multidisciplinary specialists.

Location: Spain; remote work

Company

hirify.global is a global technical consultancy delivering custom software projects, specialized technical consulting, and training for clients.

What you will do

  • Lead AI-powered penetration testing initiatives that combine offensive security techniques with AI-assisted capabilities.
  • Design offensive security services, methodologies, assessment frameworks, and delivery models.
  • Assess web applications, APIs, cloud environments, and AI-enabled systems for vulnerabilities and security risks.
  • Evaluate LLM-based applications and AI agents for prompt injection, data leakage, excessive permissions, and unsafe tool execution.
  • Drive Secure SDLC and DevSecOps initiatives, including security integration into engineering workflows and CI/CD pipelines.
  • Build reusable automation, tooling, and prototypes while mentoring a multidisciplinary security team and advising clients.

Requirements

  • 7+ years of experience in offensive security, application security, adversarial testing, or penetration testing.
  • Experience leading technical teams or complex security engagements.
  • Strong hands-on experience with web application and API security assessments, including authentication, authorization, business logic vulnerabilities, and exploit validation.
  • Experience with Secure SDLC, threat modeling, secure code reviews, vulnerability management, remediation workflows, CI/CD pipelines, and modern cloud environments.
  • Hands-on experience with LLMs, AI agents, AI-powered security tools, application security tooling, and offensive security tools such as Burp Suite or Nmap.
  • Fluent Spanish and English required. Strong programming or scripting skills, preferably Python or PowerShell, are also required.

Nice to have

  • OSCP, OSWE, CRTO, or GIAC certifications.
  • Experience building security methodologies, frameworks, or internal security services.
  • Consulting or client-facing security experience and experience leading security transformation initiatives.
  • Knowledge of Azure and GitHub security ecosystems.

Culture & Benefits

  • Flexible schedule of 35 hours per week and fully remote work.
  • Health insurance, with a co-payment for dental services.
  • Training or equipment budget, free Microsoft certifications, and English lessons.
  • Flexible compensation for restaurant, transport, and childcare expenses.
  • Birthday day off, home electricity and Internet allowance, gym discounts, and additional employee perks.
  • Flat, collaborative, multidisciplinary teams with an emphasis on technical excellence, Agile practices, knowledge sharing, and innovation.

Hiring process

  • Phone screen.
  • Two interviews with the team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →