Назад
Company hidden
8 часов назад

Lead Penetration Tester (AI)

142 300 - 195 700$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Lead Penetration Tester (AI): Owns and advances the penetration testing methodology across web, API, cloud, mobile, identity, and AI/LLM applications with an accent on complex offensive-security assessments and AI-augmented testing. Focus on leading high-impact engagements, evaluating adversarial AI risks, standardizing evidence quality, and translating technical vulnerabilities into business risk.

Location: Remote nationwide within the United States; occasional travel to hirify.global offices for training or meetings may be required.

Salary: $142,300–$195,700 per year, plus eligibility for a bonus incentive plan.

Company

hirify.global is a U.S. healthcare company providing health insurance and healthcare services to millions of people.

What you will do

  • Set and govern penetration testing methods, playbooks, scoping standards, reporting practices, and evidence-quality requirements.
  • Lead the most complex end-to-end assessments across web applications, APIs, cloud, mobile, Active Directory/Entra ID, and AI/LLM systems.
  • Operate and mature agentic AI offensive-security tooling to improve test coverage, triage speed, evidence quality, and repeatability.
  • Lead adversarial testing of AI applications, including prompt injection, jailbreaks, and other techniques mapped to OWASP, MITRE ATLAS, and NIST AI frameworks.
  • Mentor testers, identify gaps in coverage and controls, and advise leadership on the penetration testing function’s strategy.
  • Present technical findings as business risk to application owners, security teams, executives, and internal customers while supporting PCI-DSS testing.

Requirements

  • 7+ years of experience in penetration testing, ethical hacking, or offensive security operations.
  • Approximately 2 years leading complex testing programs or technical workstreams, including setting methods and standards followed by other practitioners.
  • Hands-on depth in web applications, APIs, cloud environments such as AWS, Azure, or GCP, and Active Directory/Entra ID.
  • Hands-on experience testing AI/LLM applications, including prompt injection, jailbreaks, or adversarial techniques.
  • Ability to evaluate AI-assisted findings for accuracy, exploitability, and business risk and communicate complex findings clearly to executives.
  • Ability to work from a dedicated home workspace with internet speeds of at least 25 Mbps download and 10 Mbps upload while protecting PHI/HIPAA information.

Nice to have

  • OSCP, OSWE, OSCE3, CPTS, CWEE, or equivalent advanced certifications.
  • Offensive tooling, scripting, exploit development, mobile security, application-security research, or published security research.
  • Adversarial ML experience, including model extraction, model inversion, membership inference, data poisoning, PyRIT, or Garak.
  • Security automation, CI/CD pipeline security testing, or DevSecOps experience.

Culture & Benefits

  • 100% remote work on a specialized offensive-security team, with occasional office travel for training or meetings.
  • Dedicated Fridays for research and development.
  • Hack The Box Pro Labs, role-based learning paths, discretionary certification funding, and a conference/training budget.
  • Medical, dental, and vision coverage, 401(k), paid time off, holidays, parental and caregiver leave, disability coverage, and life insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →