Security Engineer Pentesting

San Jose, CA, US • Posted 3 hours ago • Updated 2 hours ago
Full Time
On-site
50+
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • API
  • Black-box Testing
  • Burp Suite
  • Cloud Computing
  • Cloud Security
  • Collaboration
  • DevOps
  • Amazon Web Services
  • Generative Artificial Intelligence (AI)
  • Good Clinical Practice
  • Google Cloud Platform
  • Artificial Intelligence
  • LangChain
  • Large Language Models (LLMs)
  • Machine Learning (ML)
  • Management
  • Metasploit
  • Microsoft Azure
  • Nessus
  • Network
  • OSCP
  • Authentication
  • Authorization
  • Enterprise Networks
  • GraphQL
  • Kerberos
  • OWASP
  • Penetration Testing
  • Python
  • Stakeholder Engagement
  • System On A Chip
  • Testing
  • Scalability
  • Scripting
  • Security Analysis
  • Security QA
  • Semantics
  • Test Cases
  • Vector Databases
  • Web Applications
  • Web Testing
  • White-box Testing
  • Windows PowerShell
  • Bash
  • Active Directory

Summary

Role summary 
We are seeking a highly skilled Security Engineer specializing in Penetration Testing to strengthen our pensive security capabilities. This role is responsible for identifying vulnerabilities across applications, infrastructure, cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pretesting expertise with hands-on experience in AI security, enabling proactive defense against sophisticated and evolving threats.
Key Responsibilities:
Application & API Security Testing
  • Perform black-box, gray-box, and white-box penetration testing of: 
    • Web applications, APIs (REST/GraphQL), and mobile platforms
  •  Identify vulnerabilities including: 
  • Authentication/authorization flaws
  • Injection attacks
  • Business logic vulnerabilities
  • Session Management
  • Information Gathering
  • Data Validation, Governance and Transfer
  • Configuration Management
  •  Conduct secure code reviews and validate SAST/DAST findings
Infrastructure & Network Penetration Testing
  •  Execute penetration testing across: 
  • Enterprise networks (internal/external)
  • Cloud platforms (AWS, Azure, Google Cloud Platform)
  • Hybrid environments
  •  Perform: 
  • Privilege escalation and lateral movement
  • Active Directory assessments (Kerberos, NTLM, etc.)
  •  Identify misconfigurations and control weaknesses
AI/ML & GenAI Security Testing
  •  Conduct security assessments on: 
  • LLM-based applications and AI copilots
  • Machine learning models and pipelines
  •  Perform: 
  • Prompt injection and jailbreak testing
  • Data leakage and model abuse scenarios
  • Adversarial ML attacks (evasion, poisoning)
  •  Assess: 
  • RAG (Retrieval-Augmented Generation) pipelines
  • Model APIs, plugins, and agent frameworks
  • E ectiveness of AI guardrails and controls
Red Teaming & Adversary Simulation
  •  Simulate real-world attack scenarios across: 
  • Applications, infrastructure, and AI systems
  • Develop multi-stage attack chains combining:
  • Traditional and AI-specific techniques
  •  Support purple team exercises with SOC and detection teams
Automation & AI-Driven Security Testing
  • Leverage AI tools to:
  • Automate vulnerability discovery
  • Generate test cases and attack payloads
    • Develop custom tools/scripts using: 
  • Python, Bash, PowerShell, or Go
  •  Enhance scalability and repeatability of pentesting processes
Reporting & Stakeholder Engagement
  •  Deliver: 
  • Executive-level summaries (CIO/CISO ready)
  • Detailed technical reports with reproduction steps
  •  Provide: 
  • Risk-based prioritization aligned to business impact
  • Actionable remediation guide
  •  Collaborate with: 
  • Engineering, Cloud, SOC, and DevOps teams
  
Required Qualifications
Experience
  •  5+ years in penetration testing, red teaming, or o ensive security
  • Proven experience testing:
  • Web applications, APIs, and infrastructure
  •  Hands-on exposure to cloud security and enterprise environments
Technical Skills
  •  Strong knowledge of: 
  • OWASP Top 10 / API Top 10
  • OWASP Top 10 LLM
  • Network and infrastructure pentesting
  • Identity and Active Directory exploitation
  •  Experience with tools such as: 
  • Burp Suite, Metasploit, Nmap
  • BloodHound, Mimikatz, Nessus
  
AI Security
  •  Understanding of: 
  • LLM architectures and GenAI use cases
  • RAG pipelines, embeddings, and vector databases
 
  • Experience with:
  • Prompt injection testing
  • AI red teaming or model security assessments
 
  •  Exposure to: 
  • LangChain, Semantic Kernel, or similar frameworks
  
Programming
  • Proficiency in:
  • Python (required)
  • Scripting (Bash/PowerShell)
 
  •  Ability to develop: 
  • Custom testing tools and exploit scripts
  
Preferred Qualifications
  •  Certifications: 
  • OSCP, OSEP, or OSCE
  • GPEN, GWAPT, or CRTO
  • Cloud security certifications (AWS/Azure)
 
  •  Experience with: 
  • AI security research or tooling
  • Bug bounty programs or red team operations
  
Key Competencies
  • Strong attacker mindset and creative problem solving
  • Ability to translate technical findings into business risk
  • Excellent collaboration across engineering and security teams
  • Focus on scalable, repeatable security processes
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10410507
  • Position Id: 9075754
  • Posted 3 hours ago

Company Info

About Strategic Resources International

Strategic Resources International is a leading service provider in the field of digital transformation. We empower organizations to integrate technologies in different aspects of their business, fundamentally changing how they operate, for better results. We aspire to deliver fully satisfied and loyal clients with quick-to-act and quick-to-implement solutions that support our company activities seamlessly and through time.

We are a unique team dedicated to constant innovation and the delivery of people-centered digital business solutions. We’re on the lookout for the next generation of creators and innovators..

About_Company_OneAbout_Company_Two
Contact the job poster
MD

Madhu Dara

Recruiter @ Strategic Resources International
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs