Customer Security Engineer (API & AI Security) - Akto at Qureos Inc
Worldwide
<h2><strong>About Akto</strong></h2><p>Akto is an enterprise-grade <strong>Agentic AI Security platform</strong> used by global organizations to discover APIs, continuously test them, and secure AI agents, MCPs, and GenAI applications. Our customers use Akto not for point-in-time reports, but for <strong>ongoing security outcomes across APIs and AI systems</strong>.</p><p>This role is critical to ensuring customers successfully adopt Akto for <strong>real-world API security testing and AI red teaming</strong>.</p><p></p><h2><strong>Role Overview</strong></h2><p>We are looking for a <strong>hands-on security engineer</strong> with a strong pentesting background who wants to move beyond traditional, report-driven penetration testing.</p><p>As a <strong>Security Engineer – Customer Success</strong>, you will own the security testing journey for Akto customers. You will work directly with customer AppSec, DevSecOps, and Platform teams to run API security testing and AI red teaming using Akto, validate findings, explain impact, and help customers improve their security posture over time.</p><p>This is a <strong>technical, customer-facing role</strong> with real ownership of outcomes.</p><p></p><h2><strong>Key Responsibilities</strong></h2><p></p><h3><strong>Customer Security Ownership</strong></h3><ul><li><p>Own assigned customer accounts from a <strong>security testing and adoption</strong> perspective</p></li><li><p>Act as the primary security expert for customers using Akto for API security and AI red teaming</p></li><li><p>Ensure customers are actively discovering APIs, running tests, and addressing real vulnerabilities</p></li></ul><p></p><h3><strong>API Security Testing</strong></h3><ul><li><p>Perform hands-on API security testing using Akto:</p><ul><li><p>API discovery (including shadow and undocumented APIs)</p></li><li><p>Automated and guided API testing</p></li><li><p>Validation of findings such as IDORs, auth issues, business logic flaws, SSRF, and data exposure</p></li></ul></li><li><p>Go beyond tool output to:</p><ul><li><p>Verify findings</p></li><li><p>Explain impact</p></li><li><p>Recommend practical remediation steps</p></li></ul></li></ul><p></p><h3><strong>AI Red Teaming & Agent Security</strong></h3><ul><li><p>Run AI red teaming exercises using Akto for:</p><ul><li><p>AI agents</p></li><li><p>MCPs</p></li><li><p>GenAI applications and LLM-powered workflows</p></li></ul></li><li><p>Understand and test for AI-specific threats such as:</p><ul><li><p>Prompt injection</p></li><li><p>Data leakage and exfiltration</p></li><li><p>Tool misuse and privilege escalation via agents</p></li></ul></li><li><p>Translate AI security risks into actionable insights for customers</p></li></ul><p></p><h3><strong>Customer Collaboration & Enablement</strong></h3><ul><li><p>Work closely with customer security and engineering teams to:</p><ul><li><p>Explain findings clearly</p></li><li><p>Prioritize risks</p></li><li><p>Improve secure development practices</p></li></ul></li><li><p>Join customer calls to walk through results, answer technical questions, and guide next steps</p></li></ul><p></p><h3><strong>Adoption & Product Feedback</strong></h3><ul><li><p>Proactively identify gaps in product usage or adoption</p></li><li><p>Recommend better configurations, additional tests, or expanded use cases</p></li><li><p>Provide structured feedback to Product and Engineering teams based on real customer usage</p></li></ul><p></p><h2><strong>Required Qualifications</strong></h2><ul><li><p>3+ years of hands-on experience in <strong>penetration testing, application security, or API security</strong></p></li><li><p>Strong understanding of:</p><ul><li><p>API security concepts (REST, auth mechanisms, tokens, roles, rate limits)</p></li><li><p>Common web and API vulnerabilities</p></li><li><p>Business logic and authorization flaws</p></li></ul></li><li><p>Experience testing APIs using tools such as Postman, Burp, or similar</p></li><li><p>Ability to validate vulnerabilities and explain risk clearly</p></li><li><p>Comfortable working directly with customers in a technical role</p></li></ul><p></p><h2><strong>Preferred Qualifications</strong></h2><ul><li><p>Experience with <strong>API-first security tools</strong> or platforms</p></li><li><p>Exposure to <strong>AI / LLM security</strong>, red teaming, or agent-based systems</p></li><li><p>Familiarity with OpenAPI / Swagger specifications</p></li><li><p>Experience working in a customer-facing or consulting role</p></li><li><p>Strong written and verbal communication skills</p></li></ul><p></p><h2><strong>What Makes This Role Different</strong></h2><ul><li><p>You will <strong>own security outcomes</strong>, not just generate reports</p></li><li><p>You will work on <strong>continuous API security and AI red teaming</strong>, not point-in-time tests</p></li><li><p>You will influence:</p><ul><li><p>Customer adoption</p></li><li><p>Product direction</p></li><li><p>Long-term customer success</p></li></ul></li><li><p>You will be at the forefront of <strong>API and Agentic AI Security</strong>, an emerging and high-impact space</p></li></ul><p></p><h2><strong>Who Will Succeed in This Role</strong></h2><ul><li><p>A pentester who wants to see vulnerabilities actually fixed</p></li><li><p>A security engineer who enjoys working with real production systems</p></li><li><p>Someone curious about AI security and excited to learn fast</p></li><li><p>A practitioner who values clarity, impact, and ownership</p></li></ul><p></p>
Apply Now