FocusKPI is seeking a Senior Offensive Security Engineer to join a high-tech SaaS company to proactively identify, exploit, and help eliminate security weaknesses across their web platforms and AI/ML systems. The role involves leading complex penetration tests, designing novel attack techniques, and influencing secure-by-design architecture at scale.
Requirements
- Conduct offensive security assessments on large-scale web applications, REST APIs, and cloud-backed services.
- Identify and validate vulnerabilities, including injection flaws, access control issues, authentication/authorization weaknesses, SSRF, deserialization, and logic bugs.
- Evaluate LLM-based systems and AI agents for prompt injection, data exfiltration, model abuse, and jailbreaks
- Design and execute red–team–style engagements that simulate real-world adversaries.
- Develop custom exploitation tools, PoCs, and fuzzers for web and AI attack surfaces.
- Identify systemic security weaknesses and collaborate with engineering teams to drive long-term mitigations.
- Review architectures and designs for new products from an attacker's perspective.
- Produce clear, actionable security reports and present findings to technical and executive stakeholders.
Benefits
- 12-month contract with potential to convert depending on the candidate's performance
- Pay Range: $85 - 100/hr