Lead Offensive AI Security

Plain Concepts Group

United States

Remote

USD 150,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote work option
Health insurance (full)
Education budget
Microsoft certifications
English lessons
Birthday day off
Home utility allowance
Gym discount
Annual team-building event
Employee discount portal

Job summary

Plain Concepts Group is seeking a Lead Offensive AI Security to shape the future of AI-powered penetration testing, application security, and secure software development. This role blends technical leadership, hands-on expertise, and innovation while guiding a growing team.

You will design services, assess web apps, APIs, cloud environments, and AI-enabled systems; evaluate LLMS and agents; drive Secure SDLC and DevSecOps, and build tooling to accelerate engagements while advising CISOs and

Qualifications

  • 7+ years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing.
  • Experience leading technical teams or complex security engagements.
  • Strong hands-on experience with web application and API security assessments.
  • Solid understanding of authentication, authorization, business logic vulnerabilities, and exploit validation.
  • Experience implementing or improving Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows.
  • Hands-on experience using LLMs, AI agents, or AI-powered security tools to enhance testing and automation activities.
  • Experience integrating security into CI/CD pipelines and modern cloud environments.
  • Knowledge of application security tooling, including SAST, DAST, Software Composition Analysis, and Secrets Scanning.
  • Strong programming or scripting skills, preferably Python or PowerShell.
  • Experience with offensive security tools such as BurpSuite, Nmap, or similar technologies.
  • Understanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution.
  • Excellent communication skills, with the ability to explain technical findings to technical and non-technical audiences.
  • Fluent Spanish and English.

Responsibilities

  • Lead AI-powered penetration testing initiatives, combining traditional offensive security techniques with AI-assisted capabilities.
  • Design and evolve offensive security services, methodologies, assessment frameworks, and delivery models.
  • Assess web applications, APIs, cloud environments, and AI-enabled systems to identify vulnerabilities and security risks.
  • Evaluate the security of LLM-based applications and AI agents, including prompt injection, data leakage, excessive permissions, and insecure tool execution.
  • Help organizations transform their pentesting programs, increasing assessment capacity and reducing delivery times without compromising quality.
  • Drive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD pipelines.
  • Build automation, tooling, and prototypes that improve efficiency and can be reused across multiple engagements.
  • Act as a trusted advisor for CISOs, architects, engineering teams, and security leaders.
  • Mentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists.

Skills

Lead AI pentesting
Offensive security
Security leadership
CI/CD integration
Cloud security
Secure SDLC
AI security tooling
Web app security
API security
LLM security
Automation
Scripting/Python

Tools

BurpSuite
Nmap
LLMs/AI agents

Job description

AtPlainSecurityStudios,we'reredefininghoworganizationscombineOffensiveSecurity,AI,andDevSecOpstobuildmoresecureapplications.

We'relookingforaLeadOffensiveAISecuritytohelpshapethefutureofAIpoweredpenetrationtesting,applicationsecurity,andsecuresoftwaredevelopment.

Thisisauniqueopportunitytocombinetechnicalleadership,hands-onsecurityexpertise,andinnovation,whileleadingagrowingteamofspecialistsandworkingwithclientsoncutting-edgesecuritychallenges.

KeyResponsibilities
  • LeadAI-poweredpenetrationtestinginitiatives,combiningtraditionaloffensivesecuritytechniqueswithAI-assistedcapabilities.
  • Designandevolveoffensivesecurityservices,methodologies,assessmentframeworks,anddeliverymodels.
  • Assesswebapplications,APIs,cloudenvironments,andAIenabledsystemstoidentifyvulnerabilitiesandsecurityrisks.
  • EvaluatethesecurityofLLM-basedapplicationsandAIagents,includingpromptinjection,dataleakage,excessivepermissions,andinsecuretoolexecution.
  • Helporganizationstransformtheirpentestingprograms,increasingassessmentcapacityandreducingdeliverytimeswithoutcompromisingquality.
  • DriveSecureSDLCandDevSecOpsinitiatives,integratingsecuritycontrolsintoengineeringworkflowsandCI/CDpipelines.
  • Buildautomation,tooling,andprototypesthatimproveefficiencyandcanbereusedacrossmultipleengagements.
  • ActasatrustedadvisorforCISOs,architects,engineeringteams,andsecurityleaders.
  • Mentoranddevelopamultidisciplinaryteamofoffensivesecurity,applicationsecurity,andDevSecOpsspecialists.
  • 7+yearsofexperienceinOffensiveSecurity,ApplicationSecurity,AdversarialTesting,orPenetrationTesting.
  • Experienceleadingtechnicalteamsorcomplexsecurityengagements.
  • Stronghands-onexperiencewithwebapplicationandAPIsecurityassessments.
  • Solidunderstandingofauthentication,authorization,businesslogicvulnerabilities,andexploitvalidation.
  • ExperienceimplementingorimprovingSecureSDLCpractices,includingthreatmodeling,securecodereviews,vulnerabilitymanagement,andremediationworkflows.
  • Hands-onexperienceusingLLMs,AIagents,orAI-poweredsecuritytoolstoenhancetestingandautomationactivities.
  • ExperienceintegratingsecurityintoCI/CDpipelinesandmoderncloudenvironments.
  • Knowledgeofapplicationsecuritytooling,includingSAST,DAST,SoftwareCompositionAnalysis,andSecretsScanning.
  • Strongprogrammingorscriptingskills,preferablywithPythonorPowerShell.
  • ExperiencewithoffensivesecuritytoolssuchasBurpSuite,Nmap,orsimilartechnologies.
  • UnderstandingofAIapplicationsecurityrisks,includingpromptinjection,dataleakage,retrievalaccesscontrols,andunsafetoolexecution.
  • Excellentcommunicationskills,withtheabilitytoexplaintechnicalfindingstobothtechnicalandnon-technicalaudiences.
  • FluentSpanishandEnglish.
NicetoHave:
  • OSCP,OSWE,CRTO,orGIACcertifications.
  • Experiencebuildingsecuritymethodologies,frameworks,orinternalsecurityservices.
  • Backgroundinconsultingorclient-facingsecurityengagements.
  • Experienceleadingsecuritytransformationinitiatives.
  • KnowledgeofAzureandGitHubsecurityecosystems.
  • Salary determined by the market and your experience
  • Flexible schedule 35 Hours / Week
  • Fully remote work (optional)
  • Flexible compensation (restaurant, transport, and childcare)
  • Fully free health insurance, with a co-payment for dental services
  • Individual budget for training or equipment and free Microsoft certifications
  • English lessons
  • Birthday day off
  • Monthly bonus for electricity and Internet expenses at home
  • Discount on gym plan and sports activities
  • Plain Camp (annual team-building event)
  • Extra perks: events attendance and speakers, welcome pack, baby basket, Christmas basket, discount portal for employees The pleasure of always working with the latest technological tools!
Will you let us know you better?

The selection process: Simple, just 3 steps.

  • Phone screen
  • 2 interviews with the team
What is Plain Concepts?

Plain Concepts is a global company of over 500 people passionate about technology and innovation. Since our founding, we have grown through technical proficiency and confidence in ideas that others might consider risky, creating custom solutions for our clients. With offices in more than 6 countries, our mission is to continue to drive cuttingedge projects around the world.

We are highly committed to technical excellence. We are known for developing highly customized projects, offering specialized technical consultancy and training.

Thanks to the great work of our technicians, we have been recognized for our ability to lead innovative projects that generate value, from artificial intelligence to blockchain, driving solutions that help companies optimize their performance.

What we do at Plain Concepts?

We pride ourselves on being a 100% technical team, dedicated to crafting custom projects from scratch, offering expert technical consultancy, and providing top-tier training.

  • Our approach goes beyond traditional outsourcing; we focus on creating value together with our clients.
  • Our teams are diverse and multidisciplinary, operating in a flat, collaborative structure.
  • We live and breathe AGILE principles, ensuring flexibility and efficiency in everything we do.
  • Knowledge-sharing is at our core: from supporting each other internally to contributing to the broader tech community through conferences, events, and talks.
  • Innovation drives us — even the boldest ideas are welcome here.
  • Transparency underpins all our relationships, fostering trust and long-term partnerships.
Want to learn more?

Check out our website! https://www.plainconcepts.com/

At Plain Concepts, we certainly seek to provide equal opportunities. We want diverse applicants regardless of race, colour, gender, religion, national origin, citizenship, disability, age, sexual orientation, or any other characteristic protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Lead Offensive
AI Security Lead Offensive

Plain Concepts Group • Spain (TX)

On-site
EUR 110,000 - 140,000
Fully remote work (optional)
Flexible schedule
Training & certifications
+3
Portfolio Director
Portfolio Director

Plain Concepts • United States

Remote
USD 150,000 - 230,000
35-hour work week
Fully remote option
Flexible compensation
+10
AI Security Engineer / Offensive Security Engineer - Technology
AI Security Engineer / Offensive Security Engineer - Technology

Truelogic • New York (NY)

On-site
MXN 2,063,000 - 3,095,000
Remote work
USD pay
Paid time off
+2
Staff Offensive Security Engineer
Staff Offensive Security Engineer

Cloaked • New York (NY)

On-site
USD 180,000 - 240,000
Equity
401K
Health/Dental/Vision insurance
+3
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2
Principal Technical Consultant – Cloud and Application Security
Principal Technical Consultant – Cloud and Application Security

AHEAD • Northern (KY)

On-site
USD 250,000 - 300,000
Medical, Dental, Vision Insurance
401(k)
Paid holidays
+2
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor • Town of Gates (NY)

Remote
USD 120,000 - 170,000
12 weeks Gender Neutral Paid Parental/
LinkedIn Learning access
Diversity & Inclusion initiatives
+3
Senior Implementation Consultant
Senior Implementation Consultant

United States Digital Space LLC • United States

Remote
USD 110,000 - 150,000
Medical benefits
Dental benefits
Life and disability insurance
+2
Associate Security Consultant
Associate Security Consultant

IOActive, Inc. • United States

Hybrid
USD 46,000 - 58,000
Remote work flexibility
Travel opportunities
Competitive compensation
Senior DevSecOps Engineer
Senior DevSecOps Engineer

NT Concepts • Chantilly (VA), Reston (VA), Vienna (VA)

On-site
USD 120,000 - 181,000