23 ago
|
Ingeniosi
|
México
We are looking for a Senior Penetration Tester (Red Team – AI Security) with a strong hands-on offensive security background and practical exposure to AI Security .
This role focuses on security testing of LLMs, chatbots, AI agents and Generative AI applications , combined with traditional Web Application and API Penetration Testing .
We are specifically looking for someone whose primary function is Red Team / Offensive Security. We are not looking for a cybersecurity generalist whose experience is mainly focused on SOC, GRC, Vulnerability Management, Security Architecture or Security Operations.
What You'll Do
- Perform hands-on Red Team and Penetration Testing activities.
- Test LLMs, chatbots, AI agents, web applications and APIs .
- Design and execute attack scenarios involving:
- Prompt Injection / Indirect Prompt Injection
- Jailbreaks
- Sensitive Information Disclosure
- Instruction Manipulation
- Agent / Tool Abuse
- Data & Model Poisoning
- Identify vulnerabilities based on the OWASP Top 10 for LLM Applications .
- Assess authentication, authorization, sessions, business logic and information exposure.
- Develop Proofs of Concept and reproduce real attack scenarios.
- Automate security testing using Python, Bash, PowerShell or similar technologies .
- Document findings, evidence, impact, risk and remediation recommendations.
- Present technical results and collaborate with international teams.
What We're Looking For
- 6+ years of hands-on Penetration Testing / Offensive Security experience.
- 3+ years of hands-on Red Team experience.
- Red Team / Offensive Security must be a primary area of responsibility in current or recent professional experience.
- Strong experience performing Web Application and API Penetration Testing .
- Experience designing and executing attack scenarios, not only vulnerability scanning or vulnerability management.
- Practical knowledge or hands-on exposure to LLMs, Chatbots, AI Agents and Generative AI applications .
- Knowledge of Prompt Injection, Indirect Prompt Injection and OWASP Top 10 for LLM Applications .
- Experience with tools such as Burp Suite, Nmap, Metasploit, Kali Linux or similar .
- Scripting experience with Python, Bash, PowerShell or similar .
- Ability to develop PoCs and clearly communicate technical risks.
- Professional conversational and technical English (B2+).
AI Security Experience A formal AI Security Engineer or AI Red Team Specialist title is not required. AI Security experience may come from professional engagements, AI Red Team exercises, labs, research, GitHub projects, CTFs or personal security projects , as long as the candidate can demonstrate practical knowledge.
Nice to Have
- Hands-on AI Red Teaming / LLM Security experience.
- MITRE ATT&CK; / MITRE ATLAS.
- AWS, Azure or GCP.
- OSCP, OSWE, CRTO, GPEN, eWPTX or equivalent.
- Mobile or Network Penetration Testing.
Profile We're Looking For The idóneo candidate is first and foremost a hands-on Red Team / Offensive Security professional , with strong penetration testing experience and growing or demonstrated experience applying offensive security techniques to AI systems. Please ensure your CV clearly reflects your hands-on Red Team and Penetration Testing activities, including approximate years of experience and key activities performed.
📌 Senior Penetration Tester (Red Team – AI Security) (México)
🏢 Ingeniosi
📍 México