# Lead Security Engineer - Penetration Testing & AI Security

**Company:** [GoHighLevel](https://hotfix.jobs/companies/gohighlevel)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** Application Security, Penetration Testing, Threat Modeling, Ai Security, Llm Security, RAG, Python, Go, JavaScript, Kubernetes, Docker, DevSecOps, SAST, DAST, Owasp
**Posted:** 2026-09-09

> Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.

## Job Description

## Responsibilities
- Lead application security initiatives across web, mobile, API, microservices, and cloud-native products.
- Conduct architecture reviews, threat modeling, secure design and code reviews, penetration tests, and hands-on security assessments.
- Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.
- Define security standards, requirements, guardrails, and reusable secure engineering patterns.
- Improve CI/CD security testing with SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
- Drive risk-based vulnerability triage and remediation with engineering teams.
- Develop security automation and promote secure coding through guidance, documentation, and training.
- Lead security reviews and adversarial testing of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
- Assess model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent toolchains.
- Test for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, model abuse, data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.
- Evaluate guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
- Develop AI security testing methodologies, playbooks, automation, and test cases using Garak, PyRIT, or similar frameworks.
- Assess security and supply-chain risks involving third-party models, AI platforms, and AI-enabled SaaS products.
- Produce security reports with evidence, risk ratings, business impact, and remediation guidance.
- Communicate risks to developers, architects, product leaders, and executive stakeholders.
- Mentor engineers and help establish a security-conscious engineering culture.

## Requirements
- 8+ years of cybersecurity experience with hands-on expertise in application security, product security, penetration testing, or security engineering.
- 1–3 years of AI security experience, including AI/ML security, adversarial testing of AI systems, or security-focused applied AI research.
- Experience with threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
- Strong knowledge of web, mobile, API, and cloud-native security, OWASP guidance, and business-logic risks.
- Understanding of OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
- DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
- Knowledge of Docker, Kubernetes, microservices, and cloud security.
- Experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
- Understanding of prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
- Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
- Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
- Strong written and verbal communication skills.

## Nice to Have
- Experience building or scaling application security practices in a SaaS or product-led technology organization.
- Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.
- Experience developing security automation, internal testing tools, or reusable security guardrails.
- Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.
- Certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI security credential.

## Similar jobs

- [Senior Security Engineer](https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206) - Greenlight - Bengaluru, India
- [Senior Security Engineer - DART](https://hotfix.jobs/jobs/8f733ffe-5874-43b6-9dcb-4a76ac35e099) - Rippling - Bengaluru, India
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Detection and Response Engineer](https://hotfix.jobs/jobs/ebb8ac3d-4282-4505-bdb8-4699d594df80) - Anyscale - $200k – $240k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99) - Anyscale - $180k – $210k/yr

**Apply:** https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb
**Canonical:** https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb