Security Consultant II (AI/ML Penetration Tester)

NetSPI

United States

On-site

USD 80,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Collaborative workplace culture
Opportunities for professional growth

Job summary

A leading cybersecurity company in the United States is seeking a Security Consultant II specializing in AI/ML penetration testing. The role involves conducting tests on web applications and systems while enhancing security practices. The ideal candidate has 2-4 years of experience in penetration testing and a strong understanding of AI/ML technologies. This full-time position offers a collaborative environment and opportunities for professional growth.

Qualifications

  • 2-4 years of work experience in Penetration Testing required.
  • Proficiency in using offensive toolkits for penetration testing.
  • Familiarity with OWASP Top 10 and MITRE ATT&CK framework.

Responsibilities

  • Conduct Web Application and API testing independently.
  • Research and develop innovative testing techniques.
  • Present penetration test findings to clients.

Skills

Penetration Testing
AI/ML techniques
Communication
Problem-solving
Teamwork

Education

Bachelor's degree in IT, Computer Science, Engineering or Math

Tools

Kali Linux
Burp Suite
Metasploit
Nessus

Job description

Security Consultant II (AI/ML Penetration Tester)

Join to apply for the Security Consultant II (AI/ML Penetration Tester) role at NetSPI.

NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world‑class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep‑dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer‑first mindset to join our team. Learn more about our award‑winning workplace culture and get to know our A‑Team at www.netspi.com/careers.

Join the mission as a Security Consultant II. We’re seeking a technically skilled and analytical Web Application and AI/ML Penetration Tester to strengthen our cybersecurity defenses through advanced, cutting‑edge testing of AI and machine‑learning systems. As a Penetration Tester supporting AI/ML, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.

Responsibilities:

  • Conduct engagements on Web Applications and API’s independently, providing technical oversight as needed, including those that contain AI/ML components and features.
  • Perform prompt injection techniques against a variety of models, including text, voice, image, video, and multi‑modal processing models.
  • Present comprehensive penetration test findings to clients while emphasizing AI/ML risks, and collaborate on remediation strategies with model hardening, adversarial training, and threat mitigation.
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client‑specific processes, reporting standards, and access protocols to help improve their security posture.
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes.
  • Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts.
  • Perform administrative tasks related to day‑to‑day consulting activities to ensure smooth business and engagement operations.

Minimum Qualifications:

  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math, or equivalent experience.
  • Minimum of 2–4 years of work experience in Penetration Testing.
  • Familiarity with attack techniques utilized against text, voice, image, video, and multi‑modal models.
  • Proficiency in using and customizing offensive toolkits for network, application, and AI/ML penetration testing.
  • Understanding of Adversarial Machine Learning and its practical applications.
  • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus).
  • Familiarity with offensive and defensive IT concepts and protocols.
  • Extensive understanding of the OWASP Top 10 for both web applications and large language models, MITRE ATT&CK framework, and various security frameworks.
  • Working knowledge of Windows, Linux and MacOS operating systems internals.
  • Experience mentoring or coaching to growing team members.
  • Ability to work independently and as part of a team.
  • Proficient communication skills, both written and verbal.
  • This position requires an 8‑hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs.

Preferred Qualifications:

  • Ability to provide technical and QA oversight on AI/ML service line.
  • Comprehensive knowledge of secure AI/ML development protocols and architecture.
  • Strong problem‑solving skills and the ability to think like both an attacker and a defender.
  • A continuous learning mindset to keep up to date with the rapidly evolving AI/ML and cybersecurity landscapes.
  • Experience with model interpretability and explainability tools to understand model behavior and potential biases.
  • Experience in ML model development, feature engineering, and data pre‑processing.
  • Experience in one or more of the following programming or scripting languages: Ruby, Python, Perl, C, C++, Java, and C#.
  • Offensive Security Certifications (e.g., GXPN, GPEN, OSCP, GWAPT).

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Seniority level Mid‑Senior level

Employment type Full‑time

Job function Consulting

Industries Computer and Network Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 85,000 - 110,000
Senior Security Consultant (Network Penetration Tester)
Senior Security Consultant (Network Penetration Tester)

NetSPI • United States

On-site
USD 90,000 - 120,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 80,000 - 110,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 110,000 - 150,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 100,000 - 130,000
Senior Security Consultant (Mainframe Penetration Tester)
Senior Security Consultant (Mainframe Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Senior Security Consultant (Secure Code Review)
Senior Security Consultant (Secure Code Review)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Senior Security Consultant (Mainframe Penetration Tester)
Senior Security Consultant (Mainframe Penetration Tester)

NetSPI Inc. • Minneapolis (MN), Northern (KY)

Hybrid
USD 120,000 - 170,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 100,000 - 130,000