AI Security Lead Offensive

Hace 2 días

Vigo, Galicia, España Plain Concepts Jornada completa

Overview

In this role you will lead AI-powered penetration testing initiatives and shape offensive security services and delivery models. You'll guide a growing team, work with clients on cutting-edge security challenges, and advance Secure SDLC and DevSecOps integration. You will apply hands-on security expertise to assess web apps, APIs, cloud, and AI systems, while leveraging AI tools to boost testing efficiency. This is a chance to drive innovation at the intersection of offensive security and AI in a fast-growing practice.

Compensaciones / Beneficios Fully remote work
Flexible schedule
Health insurance
Budget for training or equipment and Microsoft certifications
English lessons
Birthday day off

Responsabilidades

Lead AI-powered penetration testing initiatives blending traditional techniques with AI-assisted capabilities
Design and evolve offensive security services, methodologies, assessment frameworks, and delivery models
Assess web applications, APIs, cloud environments, and AI-enabled systems for vulnerabilities and risks
Evaluate security of LLM-based applications and AI agents (prompt injection, data leakage, excessive permissions)
Transform clients pentesting programs to increase capacity and reduce delivery times without compromising quality
Drive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD
Build automation, tooling, and prototypes for reusable engagement-wide improvements
Advise CISOs, architects, and security leaders as a trusted advisor
Mentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists

Requisitos principales 7+ years in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing
Experience leading technical teams or complex security engagements
Hands-on security assessments of web apps and APIs
Strong understanding of authentication, authorization, business logic vulnerabilities, and exploit validation
Experience implementing or improving Secure SDLC practices (threat modeling, secure code reviews, vulnerability management)
Hands-on experience with LLMs, AI agents, or AI-powered security tools to enhance testing and automation
Experience integrating security into CI/CD pipelines and modern cloud environments
Knowledge of SAST, DAST, SCA, and Secrets Scanning
Strong programming/scripting skills (Python or PowerShell)
Experience with offensive security tools (Burp Suite, Nmap)
Excellent communication to explain findings to technical and non-technical audiences
Fluent in Spanish and English
Excellent communication
Leadership and mentoring
Client-facing advisory mindset
Offensive security and adversarial testing
Web and API security assessments
Secure SDLC and DevSecOps