Work Type
Remote
Location
Nigeria
Compensation
Not specified
About this opportunity
Role Overview
Attack and stress-test generative AI systems, LLM applications, and agentic workflows to identify security vulnerabilities. You will document actionable findings, prove real impact, and map vulnerabilities to standard security frameworks.
Key Responsibilities
- Probe LLM applications and agentic systems for exploitable behaviors, including direct/indirect prompt injection, guardrail and policy bypass, system prompt extraction, tool/function-call abuse, data exfiltration via RAG pipelines, and privilege escalation.
- Prove real impact beyond simple output jailbreaks.
- Write detailed reports with steps to reproduce, root cause analysis in agent/tool design, severity ratings, and OWASP Top 10 for LLM Applications mapping.
- Work strictly within defined scoping boundaries.
Qualifications & Requirements
- Exposure to generative AI security (professional or self-directed research).
- Verifiable evidence of security work (CVE credit, public bug bounty profile, vendor acknowledgment, published write-up/advisory, conference talk, or certification verification link).
- Fluent written English for technical reporting.
- Willingness to complete an identity check and sign an NDA prior to system access.
Nice to Have
- ~5 years of hands-on web penetration testing experience (or shorter if backed by published AI security work).
- Offensive security certifications (OSCP, OSWE, OSCE3, or GIAC families).
- Python or NodeJS proficiency to build testing harnesses.
- Active Hack The Box, TryHackMe, or CTFtime profile.
- Degree in Computer Science or Information Security.