Frontier AI Offensive Security Specialist

Hitachi Cyber

United States

On-site

USD 140,000 - 190,000

Full time

Just now
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Frontier AI focus
Specialized AI security training
Mentorship within global cyber team
Global cybersecurity organization

Job summary

Hitachi Cyber is seeking an experienced penetration tester for its Frontier AI Security practice. You will apply offensive security to AI systems, including LLMs, RAG pipelines, and AI agents.

Your role includes scoping, threat modeling (MITRE ATLAS/OWASP LLM Top 10), and adversarial testing across AI-powered applications. You will document findings and drive remediation with client engineering and security leadership.

Qualifications

  • 5+ years of hands-on experience conducting penetration testing engagements across web applications, APIs, mobile applications, cloud environments, or network infrastructures.
  • Bachelor's degree in a technical field or equivalent demonstrated experience.
  • Strong expertise in at least one offensive security domain: web/API, infrastructure and AD, mobile, or cloud configuration review.
  • Demonstrated ability to identify and bypass security controls and clearly articulate attack methodologies and findings.
  • Experience performing source-assisted testing, including architecture documentation review to identify attack paths.
  • Practical scripting experience with Python and strong Linux proficiency.
  • Experience delivering client-facing reports and presenting findings to technical and business stakeholders.
  • Excellent written communication skills and experience producing professional reports and deliverables.

Responsibilities

  • Lead the scoping and rules of engagement for AI security validation assessments.
  • Develop threat models for AI systems using MITRE ATLAS and OWASP LLM Top 10, and define testing objectives with clients.
  • Conduct adversarial testing against AI-powered systems, including prompt injection and RAG-related scenarios.
  • Execute adaptive attack campaigns and validate AI security controls and guardrails.
  • Assess and document effectiveness of AI security controls and remediation actions.
  • Prepare and present technical findings and prioritized remediation to client teams.

Skills

Penetration testing
Python scripting
Linux
Client-facing reports
Security testing

Education

Bachelor's degree in a technical field

Tools

Caido
Burp Suite
Python-based testing frameworks

Job description

Join Hitachi Cyber's Frontier AI Security practice and help organizations put their AI security controls to the test.

We are looking for an experienced penetration tester who wants to apply their expertise to one of the fastest-evolving areas of cybersecurity.

Our clients have integrated Large Language Models (LLMs) into customer-facing products, connected Retrieval-Augmented Generation (RAG) pipelines to sensitive data, and granted AI agents access to internal tools and business processes. While many have implemented security controls and guardrails to mitigate risk, they need experts who can determine whether those protections actually work.

As a Frontier AI Offensive Security Specialist, you will apply the same offensive security discipline used to assess web applications, APIs, cloud environments, and infrastructure to modern AI systems. Through threat modeling, adversarial testing, and adaptive attack campaigns, you will identify weaknesses, validate security controls, and provide clients with clear, evidence-based findings to help strengthen their defenses.

We are not looking for AI researchers. We are looking for experienced offensive security practitioners who want to apply their expertise to emerging AI technologies. Training on AI-specific technologies, frameworks, methodologies, and attack techniques will be provided.

Primary Responsibilities:
  • Lead the scoping and rules of engagement for AI security validation assessments.
  • Develop threat models for AI systems using frameworks such as MITRE ATLAS and the OWASP LLM Top 10, and collaborate with clients to define testing objectives.
  • Conduct adversarial testing activities against AI-powered systems, including prompt injection, jailbreak, system prompt extraction, data exfiltration, tool abuse, RAG poisoning, and autonomous agent exploitation scenarios.
  • Execute adaptive attack campaigns that evolve based on observed system behavior and validate the effectiveness of AI security controls and guardrails.
  • Assess and document the effectiveness of AI security controls by determining whether they successfully block, partially mitigate, or can be bypassed by real-world attack techniques.
  • Prepare and present technical findings, guardrail validation results, and prioritized remediation recommendations to client engineering and security leadership teams.
  • Develop and maintain offensive testing methodologies, payload libraries, and retest procedures to support the efficient validation of remediation efforts.
  • Collaborate with detection engineering teams to validate monitoring and detection capabilities through purple team exercises and real-world attack scenarios.
  • Contribute to the continuous improvement of AI security tooling, testing frameworks, and AI-assisted security validation capabilities.
What You'll Work With:
  • Advanced offensive security tooling, including Caido, Burp Suite, custom Python-based testing frameworks, and proprietary AI security assessment tools.
  • AI-powered applications, LLM APIs, AI agents, vector stores, and AI guardrail technologies deployed across AWS, Azure, and GCP environments.
  • Industry-leading frameworks and methodologies, including MITRE ATLAS, OWASP LLM Top 10, OWASP WSTG, OWASP MASTG, and NIST AI RMF.
Qualifications Required:
  • 5+ years of hands-on experience conducting penetration testing engagements across web applications, APIs, mobile applications, cloud environments, or network infrastructures.
  • Bachelor's degree in a technical field or equivalent demonstrated experience.
  • Strong expertise in at least one offensive security domain: web/API (OWASP WSTG / ASVS), infrastructure and Active Directory, mobile (MASTG), or cloud configuration review.
  • Demonstrated ability to identify and bypass security controls, such as web application firewalls (WAFs), input validation mechanisms, or content filtering solutions, and clearly articulate attack methodologies and findings.
  • Experience performing source-assisted testing, including reviewing architecture documentation, code changes, or technical designs to identify attack paths and support security assessments.
  • Practical scripting and automation experience, particularly with Python, and strong proficiency working in Linux-based environments.
  • Demonstrated experience delivering client-facing reports and presenting findings to technical and business stakeholders.
  • Excellent written communication skills and experience producing professional reports and technical deliverables.
Preferred qualifications (assets):
  • Hands-on time attacking or defending LLM-backed applications (chatbots, copilots, RAG systems, autonomous agents).
  • Familiarity with MITRE ATLAS, OWASP LLM Top 10 (2025), or NIST AI 600-1.
  • Adversarial ML exposure (evasion, extraction, poisoning) from research, CTF, or production work.
  • OSCP, GPEN, OSWE, CRT/CCT, or an equivalent practical offensive certification.
  • Previous consulting or client-delivery experience is highly desirable.
We offer:
  • Work at the forefront of AI security and innovation.
  • Specialized training and mentorship on AI technologies, frameworks, and security methodologies.
  • Collaboration with experienced offensive security, application security, detection engineering, and incident response professionals.
  • A sense of belonging within a globally recognized cybersecurity organization.

Thank you for your application. Only selected candidates will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Frontier AI Security Specialist
Frontier AI Security Specialist

Hitachi Cyber • United States

On-site
USD 140,000 - 210,000
Frontier AI Security Specialist
Frontier AI Security Specialist

Gexel Telecom International Inc. • Northern (KY)

Hybrid
USD 120,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software Technologies • City of Niagara Falls (NY)

On-site
USD 150,000 - 230,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Washington

On-site
USD 140,000 - 220,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Washington

On-site
USD 170,000 - 230,000
Application & AI Security Engineer
Application & AI Security Engineer

Hydrogen Group • United States

On-site
USD 140,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Seattle (WA)

On-site
USD 170,000 - 210,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • San Francisco (CA)

On-site
USD 150,000 - 210,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Austin (TX)

On-site
USD 140,000 - 210,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Denver (CO)

On-site
USD 150,000 - 230,000