Remote Opportunity

Senior Application Security Tester & AI Red Team Subject Matter Expert

Join C-Serv as a senior professional working remotely from Worldwide. Explore the role, benefits, and apply in one place.

Full Time
$150,000 - $250,000*
17 hours ago
Worldwide
AI Security & Privacy
Senior
OWASP ZAP
Nmap
Postman
+5 more

Job Description

The Senior Application Security Tester & AI Red Team Subject Matter Expert is a senior-level offensive security role for a tester who has mastered modern web and API security and is now defining how Evolve Security tests AI-enabled applications, large language models, and agentic systems. This role wears two hats: hands-on senior application penetration tester for our most complex client engagements, and the firm-wide subject matter expert who builds, scales, and represents Evolve Security’s AI red team practice. The senior tester executes assessments with full autonomy, owns the technical relationship with client security and engineering leadership, mentors mid-level engineers and OSOC analysts, and is the recognized internal authority on offensive AI/ML testing methodology, tooling, and threat modeling. Typical Experience: 5–8+ years of offensive security experience with a deep concentration in web application and API penetration testing, plus demonstrable hands-on work testing AI/ML systems — LLM-backed applications, RAG pipelines, fine-tuned models, multi-agent systems, or production ML inference. A track record of dozens of completed assessments, published research, conference talks, CVEs, or open-source contributions is expected. Domain Expertise: Mastery of web application and API security beyond the OWASP Top 10 — business logic abuse, complex authentication and authorization flows (OAuth 2.0 / OIDC, SAML, JWT, mTLS), SSRF chains, deserialization, request smuggling, prototype pollution, and modern SPA / GraphQL attack surface. Equally fluent in the OWASP Top 10 for LLM Applications and OWASP ML Top 10 — prompt injection (direct, indirect, multi-modal), jailbreaks and safety bypasses, insecure output handling, training data poisoning and extraction, model denial of service, supply chain vulnerabilities in model and plugin ecosystems, excessive agency in agentic systems, sensitive data leakage from system prompts and embeddings, and vector store / RAG poisoning. Technical Skills: Expert with the modern offensive toolchain — Burp Suite Pro (including custom extensions), OWASP ZAP, Nuclei, Postman, Nmap, Metasploit, BloodHound — and able to build bespoke tooling when the off-the-shelf option falls short. Comfortable with AI red-teaming tooling such as Garak, PyRIT, Promptfoo, Giskard, and adversarial ML libraries, and confident designing custom evaluation harnesses against client-specific LLM and agent stacks. Strong scripting and small-tool development in Python, with working knowledge of JavaScript / TypeScript, Bash, and PowerShell. Familiar with the components of modern AI applications: vector databases (Pinecone, Weaviate, pgvector), embedding models, retrieval pipelines, agent frameworks (LangChain, LlamaIndex, CrewAI), and tool-use protocols including MCP. Soft Skills: Excellent written and verbal communication — produces publication-quality reports with no editorial rework, leads CISO and engineering-leader briefings, and de-escalates contested findings with technical rigor. Mentors mid-level engineers and OSOC analysts through code review, paired testing, and methodology coaching. Comfortable representing Evolve Security externally — webinars, podcasts, conference CFPs, and client thought-leadership content. Certifications (Preferred, not required): OSWE, OSCP, OSEP, GWAPT, GXPN, Burp Suite Certified Practitioner; AI/ML-adjacent credentials and contributions such as AI Red Team certifications, published prompt injection research, MITRE ATLAS contributions, or SANS SEC545/SEC595. Expertise that aligns to our approach Lead end-to-end web application and API penetration tests as the senior technical owner, scoping the engagement, executing the assessment, and presenting findings to client security and engineering leadership. Apply structured testing techniques aligned to OWASP WSTG and OWASP API Security Top 10 to assess authentication, session management, access control (vertical and horizontal privilege escalation), input validation, error handling, and business logic flaws. Design and execute AI red team engagements against LLM-backed applications, RAG systems, and agentic workflows — covering prompt injection (direct, indirect, multi-modal), jailbreak resilience, system prompt and tool-use exfiltration, training data and embedding leakage, insecure output handling, and excessive agency in tool-using agents. Map AI findings to the OWASP Top 10 for LLM Applications, OWASP ML Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework so client stakeholders can defend severity and remediation calls internally. Test the full AI application surface: model endpoints, prompt and response pipelines, retrieval augmentation, vector stores, fine-tuning pipelines, plugin / tool integrations (including MCP servers), guardrail and safety layers, and supporting cloud infrastructure. Demonstrate proficiency in manual exploit development for both classical web vulnerabilities (XSS, SQLi, SSRF, IDOR, CSRF, deserialization) and LLM-specific attacks (jailbreak chains, indirect prompt injection via RAG content, agent hijacking via crafted tool outputs). Validate authentication mechanisms — OAuth, OIDC, SAML, MFA implementations, and JWT — and how they extend into AI-specific surfaces such as agent identity, per-user tool scoping, and prompt-level authorization. Assess session management, secrets handling, and data-flow controls in AI applications, including how user data ends up in prompts, logs, vector stores, and model fine-tunes. Execute client-side testing using browser dev tools and proxy-based inspection, evaluating DOM-based vulnerabilities, insecure local storage, and AI-driven client behaviors (e.g., embedded copilots and in-page agents). Test REST and GraphQL APIs using a combination of dynamic, manual, and automated methods; extend the same rigor to model and agent APIs. Perform code-assisted (grey-box) and full source review when available, identifying logic flaws, insecure configurations, and dangerous patterns specific to AI integrations (untrusted-content-into-prompt, unbounded tool use, missing output sanitization). Build, maintain, and contribute to Evolve Security’s AI red team methodology, payload libraries, evaluation harnesses, and reporting templates — and serve as the firm-wide reviewer for AI-related findings. Mentor mid-level penetration testing engineers and OSOC analysts through paired testing, technical review, knowledge-sharing sessions, and contributions to internal training and the academy. Represent Evolve Security externally through conference talks, blog posts, webinars, and client thought-leadership content on application security and AI red teaming. Communicate findings clearly, with strong emphasis on business impact, reproducibility, and strategic remediation guidance that engineering teams can actually ship. Success in the first 6 months looks like: Published, version-controlled AI red team methodology covering LLM applications, RAG systems, and agentic workflows, adopted across Evolve Security engagements. A reusable AI red team toolkit (custom Garak/PyRIT probes, payload libraries, evaluation harnesses) ready for any tester to use on a client engagement. Senior technical ownership of at least one strategic, AI-focused client account. Mentorship cadence in place with mid-level engineers and OSOC analysts; demonstrable uplift in their AI-related findings and reporting quality. At least one piece of public thought leadership (talk, blog, or research) attributed to Evolve Security. Who is Evolve Security? Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions. In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies. We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent. Benefits Include Healthcare Benefits 401(k) Match Parental Leave Flexible Paid Time Off Annual vacation reimbursement

Requirements

  • 5–8+ years of offensive security experience
  • Deep concentration in web application and API penetration testing
  • Demonstrable hands-on work testing AI/ML systems
  • Mastery of web application and API security beyond the OWASP Top 10
  • Fluency in the OWASP Top 10 for LLM Applications and OWASP ML Top 10

Benefits

  • 401k Matching
  • Certification Support
  • Flexible Hours
  • Health Insurance
  • Home Office Budget
  • Learning Budget
  • Paid Time Off
  • Remote Work

Skills

OWASP ZAP
Nmap
Postman
Burp Suite Pro
Nuclei
Metasploit
BloodHound
Garak

About AI-Estimated Salary

The salary range shown was not provided by the employer. Our AI has estimated it based on the job title, required experience, location, and industry standards (confidence: 80%). This estimate should be used as a general guide only and may not reflect the actual compensation. Always confirm salary details directly with the employer during the application process.

Ready to Apply?

Join C-Serv today

Salary Range (AI-Estimated)*
$150,000 - $250,000
80% confidence
Posted 17 hours ago

More AI Security & Privacy roles you might like

Discover similar opportunities from companies that are also hiring remotely.

Full Time
$120,000 - $180,000*
14 hours ago
Worldwide
Americas
AI Security & Privacy
Senior
AI
Machine Learning
Cyber Security
+3 more
Full Time
$120,000 - $180,000*
1 day ago
Worldwide
AI Security & Privacy
Staff
Python
ISO 27001
ISO 27701
+4 more
Full Time
$120,000 - $180,000*
1 day ago
Worldwide
AI Security & Privacy
Staff
Python
ISO 27001
ISO 27701
+4 more

Explore more remote openings

Browse fresh listings from our global community of remote-friendly teams.

Full Time
$7048.161k - $1061.802k
13 hours ago
United States
Worldwide
AI Governance & Programs
Senior
Python
SQL
AI/ML
+4 more
Full Time
$135k - $150k
14 hours ago
Worldwide
AI Governance & Programs
Mid
Python
Machine Learning
LLM
+4 more
Full Time
$120,000 - $180,000*
20 hours ago
Worldwide
AI Governance & Programs
Senior
Data governance
AI Policy
Risk Management
+5 more
Full Time
$150k - $200k
21 hours ago
Worldwide
AI Governance & Programs
Mid
AI
Python
Clinical AI
+5 more
Full Time
$120,000 - $180,000*
1 day ago
Australia
Worldwide
AI Governance & Programs
Senior
Data governance
AI Ethics
Regulatory Compliance
+3 more
Full Time
$120,000 - $180,000*
1 day ago
Australia
Worldwide
AI Governance & Programs
Senior
Data governance
AI Ethics
Regulatory Compliance
+3 more
Full Time
$85k - $95k
1 day ago
United States
Model Risk Management & Validation
Senior
Model Risk Management
Quantitative Risk Management
Financial Modeling
+4 more
Full Time
$85k - $95k
1 day ago
United States
Model Risk Management & Validation
Senior
Model Risk Management
Quantitative Risk Management
Financial Modeling
+5 more
Full Time
$80,000 - $140,000*
1 day ago
United States
AI Risk & Controls
Mid
Excel
SQL
Python
+1 more
Full Time
$80,000 - $120,000*
1 day ago
United States
Model Risk Management & Validation
Mid
Excel
SQL
Python
+1 more
Full Time
$129k - $175k
1 day ago
Worldwide
AI Audit / Assurance / Controls Testing
Senior
API
Automation
Python
+3 more
Full Time
$129k - $175k
1 day ago
Worldwide
AI Audit / Assurance / Controls Testing
Senior
API
Automation
Python
+3 more
Full Time
$119.7k - $191.1k
1 day ago
Worldwide
AI Governance & Programs
Senior
Risk Management
Model Risk
Governance
+5 more
Full Time
$120,000 - $180,000*
1 day ago
Ireland
Worldwide
AI Compliance & Legal
Senior
Data Protection
AI Compliance
Regulatory Requirements
+3 more
Full Time
$100,000 - $150,000*
1 day ago
Worldwide
AI Governance & Programs
Mid
AI/ML Concepts
Tableau
JIRA
+1 more
Full Time
$204k - $255k
1 day ago
Worldwide
AI Policy, Enablement & Training
Senior
AI
Machine Learning
Policy Development
+4 more
Full Time
$120,000 - $180,000*
1 day ago
Worldwide
AI Security & Privacy
Staff
Python
Adversarial Machine Learning
AI Deployment Architectures
+4 more
Full Time
Up to PHP 150k
2 days ago
Worldwide
AI Security & Privacy
Senior
PyTorch
TensorFlow
Containerized Environments
+4 more
Full Time
Up to PHP 150k
2 days ago
Worldwide
AI Security & Privacy
Senior
PyTorch
TensorFlow
Gradient-based attacks
+4 more
Full Time
$209k - $309k
4 days ago
Worldwide
AI Security & Privacy
Senior
API
AI
Security
+1 more
Full Time
$239.5k - $351.5k
4 days ago
Worldwide
AI Security & Privacy
Senior
API
AI
Security
+1 more
Full Time
$230k - $280k
4 days ago
United States
Worldwide
AI Governance & Programs
Senior
OWASP
NIST AI RMF
AI/ML systems
+5 more
Full Time
$230k - $280k
4 days ago
Worldwide
AI Governance & Programs
Senior
Agentic Trust Framework
OWASP
NIST AI RMF
+5 more
Full Time
$120,000 - $180,000*
4 days ago
Worldwide
AI Security & Privacy
Senior
Python
Go
Git
+5 more
Full Time
$159.3k - $273.2k
5 days ago
Worldwide
AI Governance & Programs
Senior
Python
Machine Learning
Data Science
+5 more
Full Time
$120,000 - $180,000*
5 days ago
Worldwide
AI Security & Privacy
Staff
Python
Go
Threat modeling
+3 more
Full Time
$80,000 - $140,000*
5 days ago
Worldwide
AI Governance & Programs
Mid
Responsible AI
ISO/IEC 42001
ISO/IEC 27001
+2 more
Full Time
$120,000 - $180,000*
5 days ago
United States
Worldwide
AI Governance & Programs
Senior
AI Ethics
Risk Management
AI governance frameworks
+5 more
Full Time
$120,000 - $180,000*
5 days ago
Worldwide
AI Security & Privacy
Senior
Security Operations
Cybersecurity
NG-SIEM
+5 more
Full Time
$163k - $237k
6 days ago
Worldwide
AI Governance & Programs
Senior
API
Product Management
AI
+4 more
Full Time
$80,000 - $140,000*
6 days ago
United States
Worldwide
AI Governance & Programs
Mid
Python
Data Analysis
Financial Data
+3 more
Full Time
$80,000 - $140,000*
6 days ago
United States
Worldwide
AI Governance & Programs
Mid
Python
Data Analysis
Machine Learning
+2 more
Full Time
$80,000 - $140,000*
6 days ago
Worldwide
AI Governance & Programs
Mid
Python
Excel
Google Sheets
+4 more
Full Time
$120,000 - $180,000*
6 days ago
Australia
Worldwide
AI Governance & Programs
Senior
AI
Machine Learning
Data Science
+4 more
Full Time
$120,000 - $180,000*
6 days ago
Worldwide
AI Governance & Programs
Senior
AI Governance
Model Risk Management
Regulatory Compliance
+5 more
Full Time
$120,000 - $180,000*
6 days ago
Worldwide
AI Governance & Programs
Senior
Python
ML frameworks
LLM/GenAI tooling
+2 more