Work Type
Remote
Location
Kenya
Compensation
Not specified
About this opportunity
Role Overview
Attack and stress-test generative AI systems, LLM applications, and agentic workflows to identify security vulnerabilities. You will document actionable findings, prove real impact beyond simple jailbreaks, and map vulnerabilities to standard security frameworks.
Key Responsibilities
- Probe LLM applications and agentic systems for exploitable behaviors, including direct/indirect prompt injection, guardrail/policy bypass, system prompt extraction, tool/function-call abuse, data exfiltration via RAG pipelines, and privilege escalation.
- Demonstrate real-world impact rather than trivial output jailbreaks.
- Write actionable reports detailing reproduction steps, root cause in agent/tool design, severity ratings, and OWASP Top 10 for LLM Applications mapping.
- Work strictly within designated scoping boundaries.
Qualifications & Requirements
- Around 5 years of hands-on web penetration testing experience (shorter records accepted if backed by published AI security work).
- Real exposure to generative AI security (professional or self-directed).
- Fluent written English for technical deliverable reporting.
- Verifiable evidence of security work (CVE credit, public bug bounty profile, vendor acknowledgment, published write-up/advisory, conference talk, or certification verification link).
- Willingness to undergo an identity check and sign an NDA prior to system access.
Nice to Have
- Offensive security certifications (OSCP, OSWE, OSCE3, or GIAC families).
- Python or NodeJS proficiency to build testing harnesses.
- Active Hack The Box, TryHackMe, or CTFtime profile.
- Degree in Computer Science or Information Security.