Security Engineer – Pentesting
Job Title: Security Engineer – PentestingLocation: San Jose, CA (4 days Onsite) Role summaryWe are seeking a highly skilled Security Engineer specializing in Penetration Testing to strengthen our o ensive security capabilities. This role is responsible for identifying vulnerabilities across applications, infrastructure, cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pentesting expertise with hands-on experience in AI security, enabling proactive defense against sophisticated and evolving threats.Key Responsibilities: Application & API Security Testing Perform black-box, gray-box, and white-box penetration testing of:Web applications, APIs (REST/GraphQL), and mobile platforms• Identify vulnerabilities including: Authentication/authorization flawsInjection attacksBusiness logic vulnerabilitiesSession ManagementInformation GatheringData Validation, Governance and TransferConfiguration Management• Conduct secure code reviews and validate SAST/DAST findings Infrastructure & Network Penetration Testing• Execute penetration testing across: Enterprise networks (internal/external)Cloud platforms (AWS, Azure, GCP)Hybrid environments• Perform: Privilege escalation and lateral movementActive Directory assessments (Kerberos, NTLM, etc.)• Identify misconfigurations and control weaknesses AI/ML & GenAI Security Testing • Conduct security assessments on: LLM-based applications and AI copilotsMachine learning models and pipelines• Perform: Prompt injection and jailbreak testingData leakage and model abuse scenariosAdversarial ML attacks (evasion, poisoning)• Assess: RAG (Retrieval-Augmented Generation) pipelinesModel APIs, plugins, and agent frameworksE ectiveness of AI guardrails and controlsRed Teaming & Adversary Simulation • Simulate real-world attack scenarios across: Applications, infrastructure, and AI systems• Develop multi-stage attack chains combining:Traditional and AI-specific techniques• Support purple team exercises with SOC and detection teams Automation & AI-Driven Security Testing • Leverage AI tools to:Automate vulnerability discoveryGenerate test cases and attack payloadsDevelop custom tools/scripts using:Python, Bash, PowerShell, or Go• Enhance scalability and repeatability of pentesting processes Reporting & Stakeholder Engagement • Deliver: Executive-level summaries (CIO/CISO ready)Detailed technical reports with reproduction steps• Provide: Risk-based prioritization aligned to business impactActionable remediation guide• Collaborate with: Engineering, Cloud, SOC, and DevOps teams Required Qualifications Experience • 5+ years in penetration testing, red teaming, or offensive security• Proven experience testing:Web applications, APIs, and infrastructure• Hands-on exposure to cloud security and enterprise environmentsTechnical Skills • Strong knowledge of: OWASP Top 10 / API Top 10OWASP Top 10 LLMNetwork and infrastructure pentestingIdentity and Active Directory exploitation• Experience with tools such as: Burp Suite, Metasploit, NmapBloodHound, Mimikatz, Nessus AI Security • Understanding of: LLM architectures and GenAI use casesRAG pipelines, embeddings, and vector databases• Experience with:Prompt injection testingAI red teaming or model security assessments• Exposure to: LangChain, Semantic Kernel, or similar frameworksProgramming • Proficiency in:Python (required)Scripting (Bash/PowerShell) • Ability to develop: Custom testing tools and exploit scripts Preferred Qualifications • Certifications: OSCP, OSEP, or OSCEGPEN, GWAPT, or CRTOCloud security certifications (AWS/Azure) • Experience with: AI security research or toolingBug bounty programs or red team operationsKey Competencies Strong attacker mindset and creative problem solvingAbility to translate technical findings into business riskExcellent collaboration across engineering and security teamsFocus on scalable, repeatable security processes