Security Engineer Pentesting
Full Time
On-site
50+


Strategic Resources International
Fitment
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- API
- Black-box Testing
- Burp Suite
- Cloud Computing
- Cloud Security
- Collaboration
- DevOps
- Amazon Web Services
- Generative Artificial Intelligence (AI)
- Good Clinical Practice
- Google Cloud Platform
- Artificial Intelligence
- LangChain
- Large Language Models (LLMs)
- Machine Learning (ML)
- Management
- Metasploit
- Microsoft Azure
- Nessus
- Network
- OSCP
- Authentication
- Authorization
- Enterprise Networks
- GraphQL
- Kerberos
- OWASP
- Penetration Testing
- Python
- Stakeholder Engagement
- System On A Chip
- Testing
- Scalability
- Scripting
- Security Analysis
- Security QA
- Semantics
- Test Cases
- Vector Databases
- Web Applications
- Web Testing
- White-box Testing
- Windows PowerShell
- Bash
- Active Directory
Summary
Role summary
We are seeking a highly skilled Security Engineer specializing in Penetration Testing to strengthen our pensive security capabilities. This role is responsible for identifying vulnerabilities across applications, infrastructure, cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pretesting expertise with hands-on experience in AI security, enabling proactive defense against sophisticated and evolving threats.
Key Responsibilities:
Application & API Security Testing
Perform black-box, gray-box, and white-box penetration testing of:Web applications, APIs (REST/GraphQL), and mobile platforms
Identify vulnerabilities including:
Authentication/authorization flawsInjection attacksBusiness logic vulnerabilitiesSession ManagementInformation GatheringData Validation, Governance and TransferConfiguration Management
Conduct secure code reviews and validate SAST/DAST findings
Infrastructure & Network Penetration TestingExecute penetration testing across:
Enterprise networks (internal/external)Cloud platforms (AWS, Azure, Google Cloud Platform)Hybrid environments
Perform:
Privilege escalation and lateral movementActive Directory assessments (Kerberos, NTLM, etc.)
Identify misconfigurations and control weaknesses
AI/ML & GenAI Security Testing
Conduct security assessments on:
LLM-based applications and AI copilotsMachine learning models and pipelines
Perform:
Prompt injection and jailbreak testingData leakage and model abuse scenariosAdversarial ML attacks (evasion, poisoning)
Assess:
RAG (Retrieval-Augmented Generation) pipelinesModel APIs, plugins, and agent frameworksE ectiveness of AI guardrails and controls
Red Teaming & Adversary Simulation
Simulate real-world attack scenarios across:
Applications, infrastructure, and AI systems
Develop multi-stage attack chains combining:
Traditional and AI-specific techniques
Support purple team exercises with SOC and detection teams
Automation & AI-Driven Security Testing
Leverage AI tools to:
Automate vulnerability discoveryGenerate test cases and attack payloadsDevelop custom tools/scripts using:Python, Bash, PowerShell, or Go
Enhance scalability and repeatability of pentesting processes
Reporting & Stakeholder Engagement
Deliver:
Executive-level summaries (CIO/CISO ready)Detailed technical reports with reproduction steps
Provide:
Risk-based prioritization aligned to business impactActionable remediation guide
Collaborate with:
Engineering, Cloud, SOC, and DevOps teams
Required Qualifications
Experience
5+ years in penetration testing, red teaming, or o ensive securityProven experience testing:
Web applications, APIs, and infrastructure
Hands-on exposure to cloud security and enterprise environments
Technical Skills
Strong knowledge of:
OWASP Top 10 / API Top 10OWASP Top 10 LLMNetwork and infrastructure pentestingIdentity and Active Directory exploitation
Experience with tools such as:
Burp Suite, Metasploit, NmapBloodHound, Mimikatz, Nessus
AI Security
Understanding of:
LLM architectures and GenAI use casesRAG pipelines, embeddings, and vector databases
Experience with:
Prompt injection testingAI red teaming or model security assessments
Exposure to:
LangChain, Semantic Kernel, or similar frameworks
Programming
Proficiency in:
Python (required)Scripting (Bash/PowerShell)
Ability to develop:
Custom testing tools and exploit scripts
Preferred Qualifications
Certifications:
OSCP, OSEP, or OSCEGPEN, GWAPT, or CRTOCloud security certifications (AWS/Azure)
Experience with:
AI security research or toolingBug bounty programs or red team operations
Key Competencies
Strong attacker mindset and creative problem solvingAbility to translate technical findings into business riskExcellent collaboration across engineering and security teamsFocus on scalable, repeatable security processes
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 10410507
- Position Id: 9075754
- Posted 3 hours ago
Company Info
Strategic Resources International is a leading service provider in the field of digital transformation. We empower organizations to integrate technologies in different aspects of their business, fundamentally changing how they operate, for better results. We aspire to deliver fully satisfied and loyal clients with quick-to-act and quick-to-implement solutions that support our company activities seamlessly and through time.
We are a unique team dedicated to constant innovation and the delivery of people-centered digital business solutions. We’re on the lookout for the next generation of creators and innovators..


Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs