Security Pen tester
Core
Conduct offensive security assessments on web applications, APIs, cloud environments, and AI/LLM features to identify and exploit vulnerabilities.
Role type
Senior IC penetration tester (Red Team)
Builds
Security posture of SaaS platform and emerging AI features
Domain
Cybersecurity / Supply chain software
Deliverable
production ML models | product features
Required skills
manual vulnerability discovery and exploitation, OWASP Top 10, REST and GraphQL API testing, web technologies (HTML, JavaScript, SQL), cloud infrastructure testing (AWS, OCI, Azure), modern authentication (OAuth, JWT, SSO, SAML), custom exploit development
Preferred skills
AI/LLM security testing (prompt injection, jailbreaks, RAG attacks, model extraction), security automation scripting
Technologies
Burp Suite Pro, Nmap, Nikto, SQLMap, Postman/Insomnia, Metasploit, Python, Bash, PowerShell, Microsoft Copilot, Claude
Responsibilities
Conduct in-depth penetration tests on web applications, APIs, microservices, and internal SaaS components; Perform manual vulnerability discovery and exploitation following OWASP methodologies; Simulate adversarial attack scenarios and participate in RED Team exercises; Conduct cloud-focused penetration tests and configuration reviews; Test LLM/AI features for prompt injection, jailbreaking, data leakage, and model manipulation; Develop custom proof-of-concept exploits; Create clear, detailed technical reports with reproduction steps and exploit evidence; Present findings to technical and leadership teams
Seniority
Senior, hands-on IC