Lead Security Engineer - Penetration Testing & AI Security
Penetration TestingAI SecurityThreat ModelingVulnerability ManagementSecure SDLCDevSecOpsDockerKubernetesPythonJavaScript
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Security Engineer - Penetration Testing & AI Security based in India. This role offers an opportunity to lead application and AI security initiatives across a highly scalable, cloud-native technology environment. You will focus on protecting modern applications, APIs, microservices, and AI-enabled systems against evolving security threats. The position combines hands-on penetration testing, threat modeling, secure SDLC improvements, vulnerability management, and adversarial AI security testing. You will assess LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations. Working closely with Engineering, Product, Infrastructure, and AI/ML teams, you will turn security findings into practical improvements and reusable safeguards. This is a Lead-level individual contributor role with significant technical influence and opportunities to mentor engineers. You will help shape security practices for a global, remote-first organization operating at significant scale. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Security Engineer - Penetration Testing & AI Security based in India. This role offers an opportunity to lead application and AI security initiatives across a highly scalable, cloud-native technology environment. You will focus on protecting modern applications, APIs, microservices, and AI-enabled systems against evolving security threats. The position combines hands-on penetration testing, threat modeling, secure SDLC improvements, vulnerability management, and adversarial AI security testing. You will assess LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations. Working closely with Engineering, Product, Infrastructure, and AI/ML teams, you will turn security findings into practical improvements and reusable safeguards. This is a Lead-level individual contributor role with significant technical influence and opportunities to mentor engineers. You will help shape security practices for a global, remote-first organization operating at significant scale. Accountabilities: Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products, ensuring security is embedded throughout the development lifecycle. Conduct architecture reviews, threat modeling, secure design and code reviews, penetration testing, and hands-on application security assessments. Identify and validate weaknesses involving authentication, authorization, tenant isolation, business logic, data protection, and API security. Define practical security standards, requirements, guardrails, and reusable secure engineering patterns for development teams. Strengthen CI/CD security through SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning. Drive risk-based vulnerability triage and remediation in partnership with engineering teams. Develop security automation and promote secure coding practices through developer guidance, documentation, and training. Lead security reviews and adversarial testing of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations. Assess AI architectures covering model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains. Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse. Evaluate risks related to data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration. Test AI security controls including guardrails, input and output filtering, access controls, human approvals, logging, monitoring, and abuse detection. Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks. Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products. Produce clear security reports that document evidence, risk ratings, business impact, and actionable remediation recommendations. Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders. Partner with external consultants, security researchers, and bug bounty programs when specialized assessments are required. Mentor engineers and contribute to building a strong, security-conscious engineering culture. Stay current with emerging developments in Application Security, AI Security, penetration testing, and adversarial testing. Requirements: You have 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering. You have experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation. You have 1–3 years of experience in AI Security, AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus. You have strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks. You have a strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models. You have hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, container security, and Infrastructure as Code. You have practical knowledge of Docker, Kubernetes, microservices, and cloud security. You have demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products. You understand AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks. You are familiar with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices. You have programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language. You have strong written and verbal communication skills and can influence both technical and non-technical stakeholders. Experience building or scaling Application Security practices within a SaaS or product-led technology organization is preferred. Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products is preferred. Experience developing security automation, internal testing tools, or reusable security guardrails is advantageous. Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure are valued. Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential are preferred. Benefits: Remote-first working environment with opportunities to collaborate across a global organization. Professional development and opportunities to deepen expertise in Application Security, AI Security, penetration testing, and emerging technologies. Opportunities to contribute to security research, automation, secure engineering practices, and AI security initiatives. Opportunities to mentor engineers and influence security practices across technical teams. Exposure to large-scale cloud-native applications, APIs, microservices, AI systems, and modern security technologies. Collaborative culture focused on creativity, innovation, teamwork, and meaningful technical impact. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
India
Job type
Full-time
Category
Security Engineering
Experience
8+ years
Posted
Today
Job Highlights
- 8+ years level role
- 100% Remote — open to candidates in India
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.