AI Security Lead – Offensive

🔥 4 minutes ago

🇪🇸 Spain – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 11%

infoinfo

🗣️🇪🇸 Spanish Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Plain Concepts

Plain Concepts

201 - 500 employees

Founded 2006

💼 Consulting

📣 Marketing

📦 Logistics

Consulting • Marketing • Logistics

Plain Concepts is an innovative technology company committed to delivering customized solutions across a wide array of digital needs. With a focus on cutting-edge areas like Artificial Intelligence, cybersecurity, cloud computing, and Internet of Things (IoT), Plain Concepts is a partner for companies looking to enhance operations and secure their digital landscapes. As a recognized Microsoft AI Partner, Plain Concepts aims to transform data into insightful information and improve business applications through bespoke IoT developments. Additionally, the company fosters revolutionary advancements in augmented and virtual reality, while driving digital transformation initiatives with Microsoft 365 and a strong focus on sustainability and social commitment.

📋 Description

• Lead AI-powered penetration testing initiatives, combining traditional offensive security techniques with AI-assisted capabilities • Design and evolve offensive security services, methodologies, assessment frameworks, and delivery models • Assess web applications, APIs, cloud environments, and AI-enabled systems to identify vulnerabilities and security risks • Evaluate the security of LLM-based applications and AI agents, including prompt injection, data leakage, excessive permissions, and insecure tool execution • Help organizations transform their pentesting programs by increasing assessment capacity and reducing delivery times without compromising quality • Drive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD pipelines • Build automation, tooling, and prototypes that improve efficiency and can be reused across multiple engagements • Act as a trusted advisor for CISOs, architects, engineering teams, and security leaders • Mentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists

🎯 Requirements

• 7+ years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing • Experience leading technical teams or complex security engagements • Strong hands-on experience with web application and API security assessments • Solid understanding of authentication, authorization, business logic vulnerabilities, and exploit validation • Experience implementing or improving Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows • Hands-on experience using LLMs, AI agents, or AI-powered security tools to enhance testing and automation activities • Experience integrating security into CI/CD pipelines and modern cloud environments • Knowledge of application security tooling, including SAST, DAST, Software Composition Analysis, and Secrets Scanning • Strong programming or scripting skills, preferably with Python or PowerShell • Experience with offensive security tools such as Burp Suite, Nmap, or similar technologies • Understanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution • Excellent communication skills, with the ability to explain technical findings to both technical and non-technical audiences • Fluent Spanish and English • OSCP, OSWE, CRTO, or GIAC certifications are nice to have • Experience building security methodologies, frameworks, or internal security services is nice to have • Background in consulting or client-facing security engagements is nice to have • Experience leading security transformation initiatives is nice to have • Knowledge of Azure and GitHub security ecosystems is nice to have

🏖️ Benefits

• Flexible schedule 35 Hours / Week • Fully remote work (optional) • Flexible compensation (restaurant, transport, and childcare) • Fully free health insurance, with a co-payment for dental services • Individual budget for training or equipment and free Microsoft certifications • English lessons • Birthday day off • Monthly bonus for electricity and Internet expenses at home • Discount on gym plan and sports activities • Plain Camp (annual team-building event) • Extra perks: events attendance and speakers, welcome pack, baby basket, Christmas basket, discount portal for employees • Selection process: phone screen and 2 interviews with the team

Apply Now

Similar Jobs

🕒 4 days ago

Jones Lang LaSalle Americas, Inc.

10,000+ employees

🏠 Real Estate

🤝 B2B

💼 Consulting

Senior Identity Security Architect defining zero trust, IAM, CIAM, and PAM architecture. Securing JLL’s global real estate technology ecosystem at enterprise scale.

AWS

Azure

Cloud

Cyber Security

🕒 September 21

CONVOTIS

501 - 1000

🤝 B2B

☁️ SaaS

Project Manager de ciberseguridad gestionando proyectos estratégicos de seguridad de la información para CONVOTIS Iberia. Coordinando equipos, riesgos, cumplimiento, proveedores, presupuesto y entregables.

🗣️🇪🇸 Spanish Required

AWS

Azure

Google Cloud Platform

PMP

🕒 September 16

Logicalis Spain

1001 - 5000

💼 Consulting

Técnico/a PAM CyberArk administrando cuentas privilegiadas, credenciales y Safes. Soporte de servicios gestionados de ciberseguridad para un cliente financiero de Logicalis Spain.

🗣️🇪🇸 Spanish Required

Linux

Vault

🕒 September 16

pasiona

51 - 200

💼 Consulting

📦 Logistics

🏭 Manufacturing

Technical Project Consultant implementing MTSB cybersecurity dashboards in Qualys for Pasiona Consulting clients. Coordinating requirements, providers, testing, validation, and acceptance.

🗣️🇪🇸 Spanish Required

Cyber Security

🕒 August 28

Jones Lang LaSalle Americas, Inc.

10,000+ employees

🏠 Real Estate

🤝 B2B

💼 Consulting

Application Security Architect securing JLL’s real estate technology platforms. Leading DevSecOps, threat modeling, and enterprise application security architecture.

AWS

Azure

Cloud

Google Cloud Platform

Microservices