Security engineer
- Format
- Remote
- Employment
- Project work
- Salary range
- to be agreed
Project-based load: audits come in waves, and between them there is research and adding to the internal catalogue of attacks on LLMs. The rate is agreed individually and depends on how many projects you are ready to take on.
Tasks
- Manual penetration testing of web applications, APIs and Telegram bots
- AI red teaming: injections, leaks, abuse of tools
- Write reports that both a developer and a chief executive can follow
- Add to the internal catalogue of attacks and the set of regression tests
- Write findings up on the blog with no link to specific clients
Requirements
- Hands-on web penetration testing; certificates on their own do not count
- OWASP Top-10 at the level of finding logic flaws
- The ability to write a report someone can reproduce a finding from
- Firm ethics: the boundaries are agreed in writing and we stay inside them
Nice to have
- Experience attacking LLM systems
- Knowledge of MITRE ATLAS and the OWASP LLM Top-10
- Publications or talks
Conditions
- Project-based load, rate to be agreed
- Tools and lab environments paid for
- Freedom to publish research under your own name
- Access to the internal test rig for experiments
ApplicationTell us about yourself