HighLevel logo
HighLevel

Lead Security Engineer - Penetration Testing & AI Security

🕐 6 dias atrás📍 India🌍 Remoto

What You’ll Be Doing

  • Application Security, Secure SDLC & DevSecOps

    • Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products.
    • Conduct architecture reviews, threat modeling, secure design and code reviews, and hands-on security assessments.
    • Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.
    • Define practical security standards, requirements, guardrails, and reusable secure engineering patterns.
    • Improve security testing across CI/CD pipelines using SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
    • Drive risk-based vulnerability triage and remediation in partnership with engineering teams.
    • Develop security automation and promote secure coding through developer guidance, documentation, and training.
  • AI Security Assessment & Adversarial Testing

    • Lead security reviews of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
    • Assess AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.
    • Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse.
    • Evaluate applicable risks involving data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.
    • Test security controls such as guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
    • Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks.
    • Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products.
  • Reporting, Collaboration & Leadership

    • Produce clear security reports containing evidence, risk ratings, business impact, and actionable remediation guidance.
    • Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders.
    • Partner with external consultants, researchers, and bug bounty programs for specialized assessments where required.
    • Mentor engineers and help establish a security-conscious engineering culture.
    • Stay current with developments in Application Security, AI Security, and adversarial testing.

What You’ll Bring

  • 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.
  • Experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
  • 1-3 years of AI Security experience, with AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.
  • Strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.
  • Strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
  • Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
  • Practical knowledge of Docker, Kubernetes, microservices, and cloud security.
  • Demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
  • Understanding of AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
  • Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
  • Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
  • Strong written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.

Preferred Qualifications

  • Experience building or scaling Application Security practices within a SaaS or product-led technology organization.
  • Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.
  • Experience developing security automation, internal testing tools, or reusable security guardrails.
  • Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.
  • Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.

🇧🇷 Essa vaga exige inglês. Você está pronto?

A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.

Conheça a DevSpeak Academy