04 ago
|
Sabio Group
|
Madrid
04 ago
Sabio Group
Madrid
ph3Red Team Security Engineer /h3 pbDepartment: /bIT /p pbEmployment Type: /bFull Time /p pbLocation: /bMadrid /p pbReporting To: /bStephen Smith /p h3Description /h3 pAt Sabio Group, we build and operate AI-powered customer experience platforms for some of the world's most demanding enterprise brands. As we push deeper into agentic AI, multi-cloud architectures and high-volume conversational systems, the attack surface evolves with us - and we need people who can think like adversaries to keep our customers, our data and our reputation safe. /p pWe're hiring a bRed Team Security Engineer /b to join our Information Security Cyber Security team in South Africa. You'll be the offensive counterpart to our defensive function: stress-testing the solutions we design, build and operate - from cloud-native services to LLM-powered agents - by attacking them the way a real adversary would, and partnering with engineering teams to fix what you find. /p pThis is a hands-on role for someone who is genuinely curious about how systems break, comfortable writing code as well as reading it, and excited about the new class of vulnerabilities emerging in AI and agentic systems. /p h3Key Responsibilities /h3 h3Offensive Security Red Teaming /h3 ul liPlan and execute red team engagements, penetration tests and adversary simulations against our platforms, products and corporate environment. /li liIdentify, exploit and document vulnerabilities across web applications, APIs, cloud infrastructure, identity systems and AI/LLM-based services. /li liDevelop realistic attack scenarios - initial access, privilege escalation, lateral movement, data exfiltration - mapped to frameworks such as MITRE ATTCK. /li liBuild and maintain custom tooling, exploits and automation where off-the-shelf tools fall short. /li liLeverage AI pen testing tooling and frameworks as a force amplifier within your role. /li /ul h3AI Powered Security Tooling Frameworks /h3 ul liActive, hands-on use of bAI-powered offensive security tooling /b as a core part of your workflow - leveraging LLMs and agentic assistants to accelerate reconnaissance, exploit development, code review, payload generation and report writing. /li liFamiliarity with emerging bAI red-team frameworks and platforms /b - e.g. PyRIT, Garak, Promptfoo, NVIDIA Aegis, Microsoft Counterfit, HackerOne / Bugcrowd AI testing toolkits, or equivalent - and a practical sense of when to use which. /li liExperience building or extending bautomated AI red-team harnesses /b: prompt-injection test suites, jailbreak corpora, tool-abuse scenarios, multi-turn attack agents, and regression eval sets for LLM and agentic systems. /li liPragmatic judgement on the blimits and risks of AI-assisted offensive work /b - hallucinated findings, false confidence, data leakage into third-party models - and the discipline to validate AI output before acting on it. /li liCuriosity to keep pace with a fast-moving space: new models, new attack techniques, new defensive controls - and a willingness to bring those learnings back into the team. /li /ul h3AI Agentic System Security /h3 ul liProbe LLM-powered and agentic systems for prompt injection, jailbreaks, tool/function-call abuse, context leakage, insecure output handling and supply-chain risks. /li liTest RAG pipelines,
knowledge bases and integrations for data exfiltration, poisoning and unauthorized access paths. /li liContribute to internal threat models for agentic architectures and help shape secure-by-default patterns for multi-agent and tool-using systems. /li liStay close to evolving standards and guidance - e.g. OWASP Top 10 for LLMs, NIST AI RMF, emerging agent interoperability protocols. /li /ul h3Cloud Application Security Testing /h3 ul liPerform deep-dive security testing of cloud workloads across AWS, Azure and/or GCP - IAM, network, container, serverless and data-layer concerns. /li liReview CI/CD pipelines, IaC (Terraform, CloudFormation, Bicep) and Kubernetes deployments for misconfigurations and exploitable weaknesses. /li liConduct source-assisted ("grey-box") testing - reading code to find logic flaws, authZ gaps and unsafe integrations. /li /ul h3Vulnerability Management Remediation Partnership /h3 ul liTriage findings, assign realistic severity, and write clear, reproducible reports with concrete remediation guidance. /li liPartner with engineering teams to validate fixes, advise on secure design and pair on hardening work - not just throw findings over the wall. /li liDrive continuous improvement of detection coverage by working with the blue team / SOC on purple-team exercises. /li /ul h3Tooling, Automation Continuous Testing /h3 ul liBuild automation that turns one-off tests into repeatable, scheduled checks - exposure scanning, attack-path analysis, agent red-teaming harnesses. /li liIntegrate offensive testing into the SDLC: SAST/DAST/IAST, dependency scanning, secrets detection, container and IaC scanning. /li liTreat evaluation and regression of security controls as a first-class deliverable - measured, not assumed. /li /ul h3Collaboration Responsible Disclosure /h3 ul liWork alongside the Head of Information Security, AI Ethics leads, platform engineering and product teams to embed security early. /li liProduce clear design reviews, threat models, runbooks and post-engagement reports for both technical and executive audiences. /li liOperate within strict rules of engagement, with care for production stability, customer data and legal/regulatory obligations. /li /ul h3Skills Knowledge and Expertise /h3 h3Required /h3 ul liDemonstrable hands-on experience in boffensive security /b - penetration testing, red teaming, or adversary simulation - against modern web, API and cloud-based systems. /li liStrong understanding of common vulnerability classes (OWASP Top 10, authZ flaws, SSRF, deserialisation, injection, cryptographic misuse) and how to chain them into real impact. /li liSolid grasp of bcloud security /b in at least one major provider (AWS, Azure or GCP): IAM, networking, key management, container and serverless services, common misconfigurations and attack paths. /li liPractical understanding of bAI/LLM systems /b - how they work, where they fail,
and the new risks they introduce (prompt injection, jailbreaks, insecure tool use, training/RAG data exposure). /li libCoding capability /b in at least one of Python, Go, JavaScript/TypeScript or similar - comfortable writing exploits, tooling and automation, not just running other people's tools. /li liConfidence with offensive tooling - Burp Suite, nmap, Nuclei, BloodHound, Metasploit, custom scripts - and the judgement to know when to build vs. buy. /li liFamiliarity with bCI/CD, containers and IaC /b (Docker, Kubernetes, Terraform or equivalent) and how to attack and defend them. /li liAn bevaluation mindset /b: you measure security posture with reproducible tests, metrics and evidence - not gut feel. /li liComfort with bagentic development workflows /b - using AI coding assistants and AI co-work / pair-development models (Claude Code, Copilot, Cursor or equivalent) as part of your day-to-day delivery. /li liClear written and verbal communication in English: able to brief engineers, executives and (where relevant) customers on findings and risk. /li liA strong ethical compass and discipline around scope, rules of engagement, evidence handling and responsible disclosure. /li /ul h3Desirable /h3 ul liIndustry certifications such as OSCP, OSEP, OSWE, CRTO, CRTP, GPEN, GXPN, GCPN, AWS/Azure/GCP security specialties or equivalent. /li liExperience red-teaming or evaluating bagentic AI / LLM systems /b in production - prompt injection campaigns, tool-abuse testing, multi-agent attack scenarios, AI red-team frameworks. /li liExposure to bpurple teaming /b and detection engineering: working with SOC/SIEM (e.g. Sentinel, Splunk, Defender XDR) to improve detections from offensive findings. /li liExperience with bidentity attacks /b across Entra ID / Azure AD, Active Directory, OAuth/OIDC and federated environments. /li liSource-code review skills and threat modelling experience (STRIDE, attack trees, MITRE ATLAS for AI). /li liFamiliarity with regulatory and standards contexts relevant to enterprise customers - ISO 27001, SOC 2, PCI DSS, GDPR, POPIA. /li liExperience contributing to or running bug bounty programmes, CTFs, or open-source security tooling. /li liAwareness of emerging agent interoperability and security standards (e.g. MCP, A2A) and their attack surfaces. /li /ul h3Nice to Have /h3 ul liPrior experience in a SaaS, cloud platform or AI/ML company where production systems were the target of testing - useful context, but not required. /li liPublic research, conference talks, CVEs, or community contributions in offensive security or AI security. /li /ul h3Benefits /h3 pThis is your chance to join and friendly and passionate team that will motivate you to learn and develop your career in the company. /p h3Benefits may include: /h3 ul liPension Scheme /li liRemote/Versátil work /li liLife insurance /li liPrivate health /li /ul h3The Small Print /h3 pStrictly No Agencies; any submission of resumes without prior request from Sabio Group will not be deemed as an introduction and therefore will not warrant an introduction fee. All applicants must have the right to work in the territory to which the role relates (UK EU). Sabio Group are unable to offer sponsorship on any roles advertised. /p /p #J-18808-Ljbffr
📌 Red Team Security Engineer (Madrid)
🏢 Sabio Group
📍 Madrid