Job Description & Details
This is a specialized security role focused on the intersection of offensive testing and generative AI systems. If you know how to break things and understand how LLMs, agents, and cloud architectures fail under pressure, this gig lets you push the boundaries of AI safety in real production environments.
What You'll Actually Be Doing
You will spend your days actively trying to break AI models, agents, MCP integrations, and their underlying cloud infrastructure through adversarial testing and exploit chaining. Beyond just finding vulnerabilities like prompt injections and jailbreaks, you'll need to map attack surfaces, validate remediation efforts, and translate heavy technical risk into practical guardrails that application teams can actually implement without losing their minds.
The Core Tech Stack
You need a solid foundation in enterprise offensive security combined with hands-on fluency in AI and ML systems, specifically around LLM security and prompt safety. Familiarity with cloud platforms is mandatory, with AWS being the sweet spot, while major certs like OSCP or CCSP will definitely help you stand out from the crowd.
Interview Expectations
Expect the hiring team to ask you how you would systematically approach testing an autonomous LLM agent that has API tool-calling capabilities and direct access to internal databases. They aren't looking for a textbook definition of an API vulnerability; they want to hear your threat-modeling process for chaining minor prompt alignment issues into a critical remote code execution or data exfiltration path. Another favorite will likely revolve around how you handle false positives and developer pushback when your adversarial testing breaks a critical application pipeline.
Application Advice
Skip the generic cybersecurity buzzwords and focus heavily on proving your direct experience with AI model-serving architectures and LLM-specific vulnerabilities. Make sure your resume explicitly highlights past projects involving prompt safety testing, red teaming cloud-hosted AI APIs, or securing generative SaaS platforms so you easily clear the ATS filters for these niche skills.