Artificial Intelligence Engineer

Astra Security

Bengaluru

On-site

INR 380,000 - 650,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Astra Security is seeking an experienced engineer to build and productionize harnesses for autonomous pentesting across web, API, mobile, and cloud targets. You will orchestrate models, define evaluation criteria, and drive reliable, scalable tooling aligned with security standards.

Ideal candidates ship code, prove robust through rigorous testing, and partner with researchers to turn insights into practical, cost-conscious solutions.

Qualifications

  • Experience shipping production ML tooling.
  • Strong knowledge of LLMs, prompts, and evaluation.
  • Security-minded approach to model outputs and risk.
  • Proficiency in Python and software engineering best practices.

Responsibilities

  • Build and productionize harnesses for autonomous pentesting and model orchestration.
  • Orchestrate models across frontier and open-weight variants for cost-effective scaling.
  • Define evaluation metrics and control false positives against ground truth.
  • Improve accuracy, coverage, latency, and cost with iterative releases.
  • Create guardrails to prevent hallucinations from reaching customers.
  • Collaborate with pentesters/researchers to translate judgment into tooling.

Skills

LLM Engineering
Prompting & tooling
Model orchestration
Production code

Education

Bachelor's degree in CS/Eng

Tools

Python
Docker
Kubernetes
Cloud platforms

Job description

Astra Security is a leader in the penetration testing space, recognized by G2 in the Pentest category. With headquarters in the US & India, Astra is the trusted security partner for leading brands including Muthoot Finance, Loom, CompTIA, NIIT, Goldcast, HackerRank, Sprinto, ITC & more. Its one-of-a-kind continuous pentest platform is trusted by 1,200+ companies across 100+ countries, from fast-growing startups to Fortune 100 giants.

Astra's autonomous pentest platform pairs AI agents with certified human pentesters to continuously pentest applications and infrastructure at scale. Vulnerabilities are discovered, validated, and chained the way a real attacker would. Beyond pentesting, Astra's suite includes a DAST Scanner, Cloud Vulnerability Scanner, and API Security Platform, giving teams continuous coverage across web apps, cloud environments, and APIs from a single dashboard. With over 18,000 vulnerabilities detected daily, Astra helps customers prevent millions in potential losses while saving thousands of developer hours. Last year alone, Astra uncovered more than 6.8 million vulnerabilities for its customers.

Astra's research team actively contributes to the OWASP community, including helping shape the OWASP Autonomous Penetration Testing Standard (APTS) and contributing to the OWASP Top 10 for LLM and Generative AI Security Risks. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV, reflecting its commitment to the highest standards of security testing.

We've been awarded by the President of France Mr. François Hollande at the La French Tech program and Prime Minister of India Shri Narendra Modi at the Global Conference on Cyber Security. Loom, MamaEarth, Muthoot Finance, Canara Robeco, ScripBox etc. are a few of Astra’s customers.

Why this role exists

A frontier model on its own is not a pentester. What turns a model into a capability you can run against a customer's app every day, and at scale, is the harness around it: how you feed it the target, scaffold its reasoning, give it tools, orchestrate cheap models against expensive ones, score what it produces, and stop it from shipping garbage. That harness is our core IP and our main lever on accuracy, coverage, and cost. You will own it.

What you'll do
  • Build and productionize harnesses for autonomous pentesting across web, API, mobile, cloud, and more, taking each from a working prototype to something reliable against real customer targets.
  • Orchestrate models against each other: use frontier models as the source of intelligence, then distill that into cheaper open-weight models so we can run at scale economically.
  • Own evaluation. Define what a true finding is, measure recall and precision against ground truth, penalize false positives hard, normalize for cost, and control for run-to-run variance. If it is not measured, it does not ship.
  • Push accuracy and coverage up, and cost and latency down, release over release.
  • Build the guardrails that keep a hallucinated finding from ever reaching a customer, because one false critical costs more trust than ten real findings earn.
  • Work shoulder to shoulder with our pentesters and researchers: turn their judgment into harness logic, and build tools that make them faster.
What we're looking for
  • An engineer who ships. You write clean, scalable, flexible code, get a working slice out fast, then harden it. Prototypes that never reach production are not the job.
  • Real LLM engineering: prompting and scaffolding, tool use and agents, orchestration across models, retrieval and context management, and a feel for where models break.
  • Enough security depth to judge the output. You do not need to be a career pentester, but you must look at a finding and tell real from plausible-but-wrong, and reason about severity. Slop resistance is a core skill here.
  • Evaluation rigor. You think in ground truth, baselines, false-positive rates, and cost per true finding, not vibes.
  • Production instincts: observability, cost control, reliability, and the discipline to measure before and after every change.
Nice to have
  • Hands-on pentesting or offensive security across web, API, mobile, or cloud, CTF, or vulnerability research.
  • Serving or fine-tuning open-weight models, or running them cheaply at scale.
  • Mobile (Android or iOS) security, static and dynamic analysis, or reverse engineering.
  • A track record of turning a messy research idea into something that shipped.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Product Manager - Cybersecurity SaaS Platform
Technical Product Manager - Cybersecurity SaaS Platform

Zoho • Bengaluru

On-site
INR 3,000,000 - 5,500,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Devops Engineer 1 - Cloud & Infra Automation
Devops Engineer 1 - Cloud & Infra Automation

Zoho • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Hybrid setup
Health insurance
Senior Security Engineer
Senior Security Engineer

Oolka • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Technical Product Manager
Technical Product Manager

Astra Security • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Health insurance
Annual trips to beaches or mountains
Opportunity to work with founders
AI Technical Lead
AI Technical Lead

Benchmarkit • Pune District

On-site
INR 4,000,000 - 7,000,000
Senior AI Engineer
Senior AI Engineer

Blaugarnet Inc. • Pune District

Hybrid
INR 3,000,000 - 5,000,000
AI Engineering Intern: Applied ML & Agentic Systems
AI Engineering Intern: Applied ML & Agentic Systems

Yodaplus Technologies Private Limited • India

Hybrid
INR 391,000 - 781,000
Stipend
PPO opportunity
Certificate
+1
Senior Security Engineer - Customer Engineering
Senior Security Engineer - Customer Engineering

Split Software • Bengaluru

On-site
INR 13,397,000 - 18,182,000
AI Engineer
AI Engineer

Andpayments • India

On-site
INR 1,800,000 - 3,000,000