AVP, Penetration Tester (LLM)
Core
Conduct advanced manual and automated penetration testing for Large Language Models (LLM), agentic applications, and APIs to identify security weaknesses before production deployment.
Role type
Senior IC offensive security penetration tester (LLM/AI focus)
Builds
Secure LLM, agentic, and API applications for LPL Financial's wealth management platform
Domain
Financial services / AI Security / Cybersecurity
Deliverable
production ML models | product features
Required skills
Manual penetration testing, API security testing, LLM/GenAI vulnerability assessment, custom tooling development with AI models, risk rating and remediation strategy design, network/infrastructure assessment, retesting and validation
Preferred skills
SDLC security integration, MCP server security, cloud-native security (Kubernetes, serverless), programming in Python/JavaScript/.NET, Linux/Windows/AWS/Azure environments
Technologies
Burp Suite, Promptfoo, HexStrike, Claude, CAI, Garak, Pyrit, Kali Linux, Nessus, Metasploit, Cobalt Strike, Mitre Atlas, OWASP Top 10 for LLM
Responsibilities
Partner with Security Architects during SDLC to identify LLM/AI security weaknesses; conduct tactical penetration tests against OWASP Top 10 threats for LLMs and APIs; develop custom tooling using AI models like Claude to solve new testing needs; document findings, risk ratings, and remediation recommendations; present testing results and threat analysis to IT stakeholders; oversee communication and reporting of testing findings; lead execution of AI/LLM penetration testing initiatives; develop tools for agentic-assisted LLM pentesting
Seniority
Senior, hands-on IC