Lead Security Engineer - Penetration Testing & AI Security in India at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Security Engineer - Penetration Testing & AI Security based in India.
This role offers an opportunity to lead application and AI security initiatives across a highly scalable, cloud-native technology environment. You will focus on protecting modern applications, APIs, microservices, and AI-enabled systems against evolving security threats. The position combines hands-on penetration testing, threat modeling, secure SDLC improvements, vulnerability management, and adversarial AI security testing. You will assess LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations. Working closely with Engineering, Product, Infrastructure, and AI/ML teams, you will turn security findings into practical improvements and reusable safeguards. This is a Lead-level individual contributor role with significant technical influence and opportunities to mentor engineers. You will help shape security practices for a global, remote-first organization operating at significant scale.
- Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products, ensuring security is embedded throughout the development lifecycle.
- Conduct architecture reviews, threat modeling, secure design and code reviews, penetration testing, and hands-on application security assessments.
- Identify and validate weaknesses involving authentication, authorization, tenant isolation, business logic, data protection, and API security.
- Define practical security standards, requirements, guardrails, and reusable secure engineering patterns for development teams.
- Strengthen CI/CD security through SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
- Drive risk-based vulnerability triage and remediation in partnership with engineering teams.
- Develop security automation and promote secure coding practices through developer guidance, documentation, and training.
- Lead security reviews and adversarial testing of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
- Assess AI architectures covering model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.
- Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse.
- Evaluate risks related to data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.
- Test AI security controls including guardrails, input and output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
- Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks.
- Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products.
- Produce clear security reports that document evidence, risk ratings, business impact, and actionable remediation recommendations.
- Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders.
- Partner with external consultants, security researchers, and bug bounty programs when specialized assessments are required.
- Mentor engineers and contribute to building a strong, security-conscious engineering culture.
- Stay current with emerging developments in Application Security, AI Security, penetration testing, and adversarial testing.
- You have 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.
- You have experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
- You have 1–3 years of experience in AI Security, AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.
- You have strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.
- You have a strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
- You have hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, container security, and Infrastructure as Code.
- You have practical knowledge of Docker, Kubernetes, microservices, and cloud security.
- You have demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
- You understand AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
- You are familiar with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
- You have programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
- You have strong written and verbal communication skills and can influence both technical and non-technical stakeholders.
- Experience building or scaling Application Security practices within a SaaS or product-led technology organization is preferred.
- Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products is preferred.
- Experience developing security automation, internal testing tools, or reusable security guardrails is advantageous.
- Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure are valued.
- Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential are preferred.
- Remote-first working environment with opportunities to collaborate across a global organization.
- Professional development and opportunities to deepen expertise in Application Security, AI Security, penetration testing, and emerging technologies.
- Opportunities to contribute to security research, automation, secure engineering practices, and AI security initiatives.
- Opportunities to mentor engineers and influence security practices across technical teams.
- Exposure to large-scale cloud-native applications, APIs, microservices, AI systems, and modern security technologies.
- Collaborative culture focused on creativity, innovation, teamwork, and meaningful technical impact.