Pentest Automation Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Pentest Automation Engineer (AI): Designing, running, and maintaining always-on automated pentesting programs applying to public bug bounty environments and open-source projects with an accent on end-to-end automation, compliance, target prioritization, and results analysis. Focus on building reconnaissance infrastructure, safety validation, attack execution pipelines, triage tooling, and company-wide dashboards.
Location: Europe (Remote) or US remote; all team members remote with regular in-person collaboration travel supported.
Company
AI-powered offensive security platform autonomously discovering and exploiting vulnerabilities, founded by GitHub Copilot creator Oege de Moor and backed by Sequoia and Altimeter.
What you will do
- Own and execute continuous testing program against public bug bounty programs like HackerOne.
- Own and execute testing program in collaboration with open-source projects (launching Q2).
- Ensure targets are in scope, prioritize based on attack surface and business impact.
- Incorporate pre-release capabilities into testing workflows.
- Build full end-to-end automation of attack pipeline: reconnaissance, safety/compliance checks, target selection, attack dispatch, and management.
- Develop tooling for findings triage/analysis and company-wide dashboards for testing visibility.
Requirements
- Professional experience with Typescript in automation tooling.
- Professional experience with AWS.
- Professional expertise in Linux, CI/CD pipelines (especially GitHub Actions), and Infrastructure & DevOps tooling.
Nice to have
- Professional experience with Go or Python in automation tooling.
- Professional experience with additional cloud providers (GCP, Azure).
- Professional experience with DevOps and IaC technologies (Kubernetes, Docker, Terraform).
Culture & Benefits
- Competitive salary and generous equity package.
- Shape your role and lead the function with career growth opportunities.
- Work on meaningful, technically complex challenges alongside world-class AI and security experts.
- Fully remote team with support for regular in-person collaboration travel.
- Focus on mission fit, capability, and impact over seniority titles.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →