Lead Penetration Tester (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Penetration Tester (AI): Owns and advances the penetration testing methodology across web, API, cloud, mobile, identity, and AI/LLM applications with an accent on complex offensive-security assessments and AI-augmented testing. Focus on leading high-impact engagements, evaluating adversarial AI risks, standardizing evidence quality, and translating technical vulnerabilities into business risk.
Location: Remote nationwide within the United States; occasional travel to offices for training or meetings may be required.
Salary: $142,300–$195,700 per year, plus eligibility for a bonus incentive plan.
Company
is a U.S. healthcare company providing health insurance and healthcare services to millions of people.
What you will do
- Set and govern penetration testing methods, playbooks, scoping standards, reporting practices, and evidence-quality requirements.
- Lead the most complex end-to-end assessments across web applications, APIs, cloud, mobile, Active Directory/Entra ID, and AI/LLM systems.
- Operate and mature agentic AI offensive-security tooling to improve test coverage, triage speed, evidence quality, and repeatability.
- Lead adversarial testing of AI applications, including prompt injection, jailbreaks, and other techniques mapped to OWASP, MITRE ATLAS, and NIST AI frameworks.
- Mentor testers, identify gaps in coverage and controls, and advise leadership on the penetration testing function’s strategy.
- Present technical findings as business risk to application owners, security teams, executives, and internal customers while supporting PCI-DSS testing.
Requirements
- 7+ years of experience in penetration testing, ethical hacking, or offensive security operations.
- Approximately 2 years leading complex testing programs or technical workstreams, including setting methods and standards followed by other practitioners.
- Hands-on depth in web applications, APIs, cloud environments such as AWS, Azure, or GCP, and Active Directory/Entra ID.
- Hands-on experience testing AI/LLM applications, including prompt injection, jailbreaks, or adversarial techniques.
- Ability to evaluate AI-assisted findings for accuracy, exploitability, and business risk and communicate complex findings clearly to executives.
- Ability to work from a dedicated home workspace with internet speeds of at least 25 Mbps download and 10 Mbps upload while protecting PHI/HIPAA information.
Nice to have
- OSCP, OSWE, OSCE3, CPTS, CWEE, or equivalent advanced certifications.
- Offensive tooling, scripting, exploit development, mobile security, application-security research, or published security research.
- Adversarial ML experience, including model extraction, model inversion, membership inference, data poisoning, PyRIT, or Garak.
- Security automation, CI/CD pipeline security testing, or DevSecOps experience.
Culture & Benefits
- 100% remote work on a specialized offensive-security team, with occasional office travel for training or meetings.
- Dedicated Fridays for research and development.
- Hack The Box Pro Labs, role-based learning paths, discretionary certification funding, and a conference/training budget.
- Medical, dental, and vision coverage, 401(k), paid time off, holidays, parental and caregiver leave, disability coverage, and life insurance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →