AI Penetration Testing Specialist

International Turnkey Systems - ITS

Kuwait City

On-site

KWD 20,000 - 33,000

Full time

4 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

International Turnkey Systems - ITS in Kuwait seeks an AI Penetration Tester to join the VMPT team and lead hands-on security testing for LLM/GenAI, ML, and AI-enabled applications such as chatbots, RAG, AI agents, and model APIs.

The role blends traditional penetration testing with secure code review and vulnerability assessment, focusing on prompt injection and insecure output handling per OWASP Top 10 for LLM applications.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, software engineering, or related field.
  • 3–7 years in penetration testing / application security / red teaming.
  • Experience testing LLM/GenAI systems (prompt injection, jailbreaks, data exfiltration).
  • Strong Python for security automation and test harness development.
  • Practical experience with Azure security concepts (identity, networking, secrets, logging).
  • Strong report writing and remediation communication.

Responsibilities

  • Plan and execute AI penetration tests for LLM/GenAI and ML solutions across the bank.
  • Design tests aligned to OWASP Top 10 for LLM Applications (prompt injection, insecure output handling).
  • Perform adversarial testing using threat-informed techniques (MITRE ATLAS).
  • Validate security of agentic workflows and ensure least privilege.

Skills

Penetration testing
Secure code review
Threat modeling
Adversarial testing

Education

Bachelor’s degree in Computer Science / Cybersecurity / Software Engineering

Tools

Python
Git
CI/CD
Azure security concepts
Azure OpenAI / Foundry deployments

Job description

For a well-known Islamic Bank in Kuwait, we are hiring an AI Penetration Tester to join VMPT team and lead hands-on security testing for LLM/GenAI, ML, and AI-enabled applications (chatbots, RAG, AI agents, model APIs, and AI-assisted business workflows). The role blends traditional penetration testing + secure code review + vulnerability assessment with AI red teaming focused on modern AI risks such as prompt injection and insecure output handling as documented by OWASP’s Top 10 for LLM Applications.

Candidate is expected to have experience in assessing Python-based AI development and Azure AI / Azure OpenAI / Microsoft Foundry-hosted model endpoints.

Key Responsibilities
  • Plan and execute AI penetration tests for LLM/GenAI and ML solutions across the bank (AI apps, AI gateways, model endpoints, orchestration layers, RAG pipelines, plugins/tools).
  • Design test cases aligned to OWASP Top 10 for LLM Applications (e.g., prompt injection, insecure output handling, sensitive info disclosure, supply-chain risks).
  • Perform adversarial testing using threat-informed techniques and references such as MITRE ATLAS (adversary tactics/techniques for AI systems).
  • Validate security of agentic workflows (tool invocation, function calling, permissions, memory, connectors) and verify least privilege + authorization boundaries.
Automation & Tooling
  • Build Python-based test harnesses for repeatable AI security testing (fuzzing prompts, jailbreak suites, regression tests, evaluation scoring).
  • Use and extend PyRIT (Python Risk Identification Tool) or equivalent frameworks to probe for jailbreaks/harms and automate adversarial scanning.
  • Where applicable, leverage Microsoft Foundry capabilities such as the AI Red Teaming Agent (preview) that integrates PyRIT red teaming features.
Secure code review & AppSec
  • Conduct secure code review (particularly Python) for AI application layers: prompt templates, RAG retrieval logic, output post-processing, input validation, secrets handling, authZ checks, and logging.
  • Identify and help fix design flaws enabling data leakage, prompt manipulation, unsafe tool usage, or insecure output flows.
Traditional PT
  • Perform web/API/cloud penetration testing for AI-enabled applications (auth, session, API abuse, SSRF, injection, misconfigurations, secrets).
  • Run vulnerability assessments, triage findings, define severity, and validate remediation (re-test).
Education and Qualification
  • Bachelor’s degree in computer science, Cybersecurity, Software Engineering, or related discipline.
  • 3–7 years in penetration testing / application security / red teaming.
  • Demonstrated experience testing LLM/GenAI systems (prompt injection, jailbreaks, data exfiltration patterns, agent/tool abuse).
  • Strong hands-on Python for security automation and test harness development.
  • Practical experience with Azure security concepts (identity, networking, secrets, logging) and exposure to Azure AI / Azure OpenAI / Foundry style deployments.
  • Strong report writing, clear communication, ability to work with developers on remediation.
A Must Certificates (at least one)
  • GIAC GPEN
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • ISC2 CCSP
Strongly Preferred
  • OffSec OSWE (advanced web exploitation / white-box testing)
  • Microsoft Certified: Azure AI Engineer Associate (AI-102) (helps align with Azure AI implementation patterns).
Tools & Technologies Skills
  • Python, Git, CI/CD integration
  • Azure security controls (identity, key management, logging/monitoring)
  • AI red teaming tooling (e.g., PyRIT / Foundry scans)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GenAI & LLM Security Penetration Lead
GenAI & LLM Security Penetration Lead

International Turnkey Systems - ITS • Kuwait City

On-site
KWD 20,000 - 33,000
AI Security Governance & Policy Specialist
AI Security Governance & Policy Specialist

International Turnkey Systems - ITS • Kuwait City

On-site
KWD 24,000 - 36,000
Agentic AI Engineer
Agentic AI Engineer

DPSKW • Gouvernement Hawalli

On-site
KWD 18,000 - 30,000
AI Engineer AI Factory Free Trade Zone
AI Engineer AI Factory Free Trade Zone

CODED • Kuwait

On-site
KWD 17,000 - 23,000
Training culture
Exposure to production systems
Client visits Kuwait
AI Governance & Security Policy Architect
AI Governance & Security Policy Architect

International Turnkey Systems - ITS • Kuwait City

On-site
KWD 24,000 - 36,000
AI Engineer: Enterprise AI, RAG & Automation
AI Engineer: Enterprise AI, RAG & Automation

CODED • Kuwait

On-site
KWD 17,000 - 23,000
Training culture
Exposure to production systems
Client visits Kuwait
L2 Cybersecurity Specialist
L2 Cybersecurity Specialist

Amlak Al Arabia • Kuwait City

On-site
KWD 6,000 - 12,000
Senior Software Engineer - AI-Driven Cloud & API Apps
Senior Software Engineer - AI-Driven Cloud & API Apps

Menzies Aviation • Kuwait City

On-site
KWD 9,300 - 17,000
Senior Agentic AI Engineer: Production-Ready LLM Solutions
Senior Agentic AI Engineer: Production-Ready LLM Solutions

DPSKW • Gouvernement Hawalli

On-site
KWD 18,000 - 30,000
Senior .NET Cloud Developer — AI-Driven APIs
Senior .NET Cloud Developer — AI-Driven APIs

John Menzies • Kuwait City

On-site
KWD 12,000 - 18,000