CybersecurityJobs.io
← Back to all jobs

Job Description

The Senior AI Penetration Tester will join Fitch Group’s Information Security team in New York, operating in a hybrid capacity to assess security for AI systems and leverage AI-driven tooling to streamline testing workflows. This role encompasses planning and executing penetration tests across networks, applications, and AI/LLM platforms.

Responsibilities

  • Conduct security assessments of AI implementations, including AI chatbots, MCP servers, and enterprise deployments of Claude, ChatGPT, and Azure OpenAI Studio; identify risks such as prompt injection, model abuse, and data exfiltration, while performing ongoing adversarial testing to validate guardrails against evolving vendor capabilities.
  • Plan, scope, and execute penetration testing across network infrastructure (servers, firewalls, endpoints, Active Directory) and perform comprehensive web application security assessments addressing OWASP Top 10, business logic flaws, authentication weaknesses, and API security, aligned with OWASP, MITRE ATT&CK, and related methodologies.
  • Utilize AI agents and AI-assisted tooling (eg, Claude and ChatGPT) to augment testing workflows, automate reconnaissance, and develop custom scripts and exploit code for attack-chain automation, payload generation, and post-exploitation tasks.
  • Document assessment outcomes with clear risk context and remediation guidance, and collaborate with Vulnerability Management, Application, and Infrastructure teams to ensure actionable remediation ownership.
  • Stay current with offensive security research, CVEs, exploitation techniques, and AI security threats; support red team exercises and threat simulations; maintain meticulous records of testing activities and evidence per internal standards.

Requirements

  • Hands-on AI red-teaming experience covering prompt injection (direct and indirect), jailbreaks, tool abuse, insecure output handling, training data exfiltration, and model DoS, with familiarity in OWASP Top 10 for LLMs and MITRE ATLAS.
  • Direct penetration testing experience across network infrastructure, web applications, and AI/LLM-based systems, with solid grounding in TCP/IP, DNS, HTTP/S, VPNs, and firewalls.
  • Proficient scripting in Python, Bash, or PowerShell; ability to craft custom exploits, build attack tooling, and adapt public PoCs; working knowledge of Metasploit, Burp Suite (including Burp AI extensions), Nmap, Nessus/OpenVAS, BloodHound, Cobalt Strike, and related tools.
  • Experience using AI tools such as Claude or ChatGPT for reconnaissance, vulnerability analysis, payload development, and exploit construction.
  • Ability to produce clear, structured assessment reports that translate findings and risk ratings into actionable remediation guidance for technical teams and senior stakeholders.
  • Educational background as a degree holder in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience; minimum of 2 years of relevant experience.

Technologies

  • MCP (Model Context Protocol) servers, Claude, ChatGPT, Azure OpenAI Studio
  • Active Directory, Metasploit, Burp Suite and Burp AI extensions
  • Nmap, Nessus, OpenVAS, BloodHound, Cobalt Strike
  • Python, Bash, PowerShell
  • AWS, Azure, Google Cloud Platform, Kubernetes

Benefits

  • Hybrid Work Environment: 2 to 3 days per week in the office, depending on role and location.
  • Learning and Mobility: Ongoing trainings, leadership development, and mentorship opportunities to support career growth.
  • Financial Wellbeing: Retirement planning, financial wellness programs, and tuition reimbursement available.
  • Health and Wellness: Comprehensive healthcare offerings to support physical and mental well-being.
  • Family Support: Global parental leave and family-friendly policies to help balance work and home life.
  • Community Engagement: Paid volunteer days and support for charitable initiatives.

What would make you stand out

  • Experience assessing AI systems and LLM deployments in enterprise environments (Claude, ChatGPT, Azure OpenAI Studio or similar), identifying risks including prompt injection, insecure tooling, MCP server misconfigurations, and risks in agentic workflows.
  • Experience testing AI systems in regulated or MNPI contexts, handling confidential or controlled data.
  • Familiarity with AI monitoring/observability platforms and a strong working knowledge of MITRE ATT&CK, including applying new TTPs to simulate real adversaries.
  • Cloud penetration testing experience across AWS, Azure, or GCP, and exposure to container and Kubernetes security assessments.
  • Knowledge of secure coding practices and basic code review to support application security engagements; familiarity with PCI DSS, DORA, and ISO 27001.
  • Certifications such as OSCP, CEH, GPEN, GWAPT; a degree in a relevant field; and participation in bug bounty programs or CTFs.

You may be a good fit if

  • You bring hands-on AI red-teaming experience focusing on prompt injection, jailbreaking, tool abuse, insecure outputs, and data exfiltration; familiarity with LLMs' OWASP Top 10 and MITRE ATLAS is expected.
  • You have practical pentesting across networks, endpoints, web apps, and AI systems, with strong knowledge of core networking fundamentals.
  • You possess robust scripting skills (Python, Bash, or PowerShell) and can develop custom tooling and adapt PoCs; experience with Metasploit, Burp Suite, Nmap, Nessus/OpenVAS, and related suites.
  • You have used AI tooling for reconnaissance and exploit development in penetration testing contexts.
  • You can deliver concise, well-structured reports that translate technical findings into actionable remediation guidance for diverse audiences.

Why choose Fitch

  • Hybrid Work Environment: 2 to 3 days a week in office based on business needs and location.

Similar Jobs