Live opening · Posted 5 days ago

[EJV] Penetration Tester — AI Safety & Security (with Joining Bonus)

ETAS · Ho Chi Minh, , Vietnam
Smartrecruiters No Full-time
You are 5 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 5 days ago
CompanyETAS
LocationHo Chi Minh, , Vietnam
Job typeFull-time
Work modeNo
SourceSmartrecruiters
Listed5 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
12 min from Smartrecruiters publishing this role to us finding it
10 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,374 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

🎁Q4 JOINING BONUS
Join BGSV by 31 December 2026 and receive a Joining Bonus equivalent to 1 month gross salary, subject to program eligibility and terms & conditions.
About the Role
We are looking for a Penetration Tester to join our AI Safety & Security team, working hands-on across Bosch's growing portfolio of AI-enabled products and internal tooling — LLM deployments, agentic AI systems, and Model Context Protocol – style tool-calling integrations. Under the direction of the team's Lead AI Safety & Security Engineer, you will execute structured test plans against real systems, covering both whether an AI system behaves safely (does it refuse harmful requests, stay within its intended scope) and whether it is secure (can it be manipulated via prompt injection or tricked into misusing its tools). This is an individual-contributor role on a newly forming team — you'll be running real engagements from day one, not just shadowing them.
Key Responsibilities
Execute penetration tests and safety evaluations against LLM-based features and AI agents, following test plans and specifications defined by the team lead.
Run red-teaming and jailbreak testing to surface harmful, biased, or unsafe model outputs, and document reproducible findings.
Test for prompt injection (direct and indirect), excessive agency, and tool/plugin abuse in agentic and MCP-style tool-calling systems.
Verify human-in-the-loop and guardrail controls hold up under adversarial conditions, not just in normal use.
Write clear, reproducible findings reports — evidence, severity, and a specific recommended fix — that both engineers and governance stakeholders can act on.
Help build and maintain test tooling: adversarial-prompt scripts, jailbreak test cases, and MCP/tool-schema fuzzing scripts.
Track published AI security research (OWASP LLM and Agentic Top 10s, MITRE ATLAS) and bring new attack techniques into the team's test suite.
Work directly with AI/ML engineering teams to reproduce, triage, and confirm fixes for reported findings.
Support the team lead in scoping and coordinating external red-teaming/pentest vendor engagements when work is outsourced.
Required Qualifications
Bachelor's degree in Computer Science, Machine Learning, or a related field.
2–5 years in penetration testing, security testing, or applied AI/ML security work.
Hands-on experience testing LLM or agentic AI systems — prompt injection, jailbreaks, or tool/plugin abuse; coursework, CTFs, or independent projects count given how new this field is.
Working familiarity with the OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Agentic Applications.
Comfortable scripting in Python and/or JavaScript/Node to automate test cases.
Clear, precise technical writing for findings reports.
Preferred Qualifications
Exposure to the Model Context Protocol (MCP) or comparable agent tool-calling frameworks.
Traditional penetration testing experience across web, API, or network targets.
Familiarity with AI governance concepts (NIST AI RMF, ISO/IEC 42001, EU AI Act).
Open-source security tooling contributions, CTF results, or a public research/write-up portfolio.
Relevant Certifications (any of the following a plus)
Offensive security / penetration testing — OSCP, GPEN, GWAPT, or CEH.
AI-specific security — ISC2 AI Security Certificate or Certified AI Security Professional (CAISP).

Employment type
Full-time

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App