Live opening · Posted 11 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Contract Scope & Responsibilities ? Core Penetration Testing: Conduct detailed penetration testing of web applications, mobile applications, thick clients, cloud-native applications, APIs, and network environments using both automated tools and manual testing techniques. ? AI/LLM Security Testing: Assess AI chatbots, AI agents, and Model Context Protocol (MCP)-based applications, including risks introduced by AI systems and how those risks can be tested, governed, and reduced. ? Execute hands-on AI security test scenarios covering prompt injection, jailbreaks, harmful outputs, sensitive data leakage, tool misuse, hallucination, grounding failures, and policy bypass. ? Design and run adversarial prompts to test model and guardrail robustness. ? Reporting & Remediation: Identify, classify, and prioritize vulnerabilities based on risk and business impact, and prepare clear reports with findings, evidence, and proof-of-concept details where applicable. ? Collaboration & Delivery Support: Work with internal security, development, and project teams to understand application functionality, validate risks, communicate findings, and support remediation discussions within the agreed engagement scope. ? Stay current with emerging security threats, vulnerabilities, technologies, and testing methodologies. ? Contribute to agreed security testing templates, reporting formats, methodologies, and process documentation where required for the engagement. Required Contractor Profile ? Bachelor?s degree in computer science, information security, or a related discipline. ? 4+ years of hands-on experience delivering vulnerability assessment and penetration testing engagements. ? Strong understanding of OWASP Top 10 around Web, API, LLM, Agentic Apps & MCP, SANS Top 25, OSSTMM, PTES, and NIST standards. ? 2+ years of strong understanding and hands-on of common GenAI risks, including prompt injection, sensitive data leakage, insecure output handling, excessive agency, hallucination, and model misuse. ? Ability to write and execute structured AI security test cases. ? Hands-on experience with leading application security testing tools such as HCL AppScan and Burp Suite. ? Good conceptual understanding and practical hands-on experience with SAST, DAST, and other security testing approaches relevant to software development. ? Strong foundation in application architecture, development practices, and the software development lifecycle. ? Strong knowledge of secure software development principles, including cryptography, authentication mechanisms, and security protocols. ? Relevant certifications such as OSCP, OSWE, or CEH are a plus. ? Strong English communication skills, both written and verbal. Engagement Expectations ? Strong communication and presentation skills, with the confidence to engage effectively with stakeholders. ? Ability to work collaboratively and effectively with cross-functional and geographically dispersed teams. ? Availability to support agreed engagement timelines and occasional coordination across global time zones, as required. ? Self-driven working style with the ability to deliver quality outputs independently and within agreed timelines. ? Ability to clearly document testing scope, assumptions, limitations, evidence, and recommendations for internal review.
Penetration Testing
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.