Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior AI Security Red Team Lead & Offensive Testing Expert

Evolvesec

The Senior Application Security Tester & AI Red Team Subject Matter Expert is a senior-level offensive security role for a tester who has mastered modern web and API security and is now defining how Evolve Security tests AI-enabled applications, large language models, and agentic systems. This role wears two hats: hands-on senior application penetration tester for our most complex client engagements, and the firm-wide subject matter expert who builds, scales, and represents Evolve Security’s AI red team practice. The senior tester executes assessments with full autonomy, owns the technical relationship with client security and engineering leadership, mentors mid-level engineers and OSOC analysts, and is the recognized internal authority on offensive AI/ML testing methodology, tooling, and threat modeling. Typical Experience: 5–8+ years of offensive security experience with a deep concentration in web application and API penetration testing, plus demonstrable hands-on work testing AI/ML systems — LLM-backed applications, RAG pipelines, fine-tuned models, multi-agent systems, or production ML inference. A track record of dozens of completed assessments, published research, conference talks, CVEs, or open-source contributions is expected. Domain Expertise: Mastery of web application and API security beyond the OWASP Top 10 — business logic abuse, complex authentication and authorization flows (OAuth 2.0 / OIDC, SAML, JWT, mTLS), SSRF chains, deserialization, request smuggling, prototype pollution, and modern SPA / GraphQL attack surface. Equally fluent in the OWASP Top 10 for LLM Applications and OWASP ML Top 10 — prompt injection (direct, indirect, multi-modal), jailbreaks and safety bypasses, insecure output handling, training data poisoning and extraction, model denial of service, supply chain vulnerabilities in model and plugin ecosystems, excessive agency in agentic systems, sensitive data leakage from system prompts and embeddings, and vector store / RAG poisoning. Technical Skills: Expert with the modern offensive toolchain — Burp Suite Pro (including custom extensions), OWASP ZAP, Nuclei, Postman, Nmap, Metasploit, BloodHound — and able to build bespoke tooling when the off-the-shelf option falls short. Comfortable with AI red-teaming tooling such as Garak, PyRIT, Promptfoo, Giskard, and adversarial ML libraries, and confident designing custom evaluation harnesses against client-specific LLM and agent stacks. Strong scripting and small-tool development in Python, with working knowledge of JavaScript / TypeScript, Bash, and PowerShell. Familiar with the components of modern AI applications: vector databases (Pinecone, Weaviate, pgvector), embedding models, retrieval pipelines, agent frameworks (LangChain, LlamaIndex, CrewAI), and tool-use protocols including MCP. Soft Skills: Excellent written and verbal communication — produces publication-quality reports with no editorial rework, leads CISO and engineering-leader briefings, and de-escalates contested findings with technical rigor. Mentors mid-level engineers and OSOC analysts through code review, paired testing, and methodology coaching. Comfortable representing Evolve Security externally — webinars, podcasts, conference CFPs, and client thought-leadership content. Certifications (Preferred, not required): OSWE, OSCP, OSEP, GWAPT, GXPN, Burp Suite Certified Practitioner; AI/ML-adjacent credentials and contributions such as AI Red Team certifications, published prompt injection research, MITRE ATLAS contributions, or SANS SEC545/SEC595. Expertise that aligns to our approach Lead end-to-end web application and API penetration tests as the senior technical owner, scoping the engagement, executing the assessment, and presenting findings to client security and engineering leadership. Apply structured testing techniques aligned to OWASP WSTG and OWASP API Security Top 10 to assess authentication, session management, access control (vertical and horizontal privilege escalation), input validation, error handling, and business logic flaws. Design and execute AI red team engagements against LLM-backed applications, RAG systems, and agentic workflows — covering prompt injection (direct, indirect, multi-modal), jailbreak resilience, system prompt and tool-use exfiltration, training data and embedding leakage, insecure output handling, and excessive agency in tool-using agents. Map AI findings to the OWASP Top 10 for LLM Applications, OWASP ML Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework so client stakeholders can defend severity and remediation calls internally. Test the full AI application surface: model endpoints, prompt and response pipelines, retrieval augmentation, vector stores, fine-tuning pipelines, plugin / tool integrations (including MCP servers), guardrail and safety layers, and supporting cloud infrastructure. Demonstrate proficiency in manual exploit development for both classical web vulnerabilities (XSS, SQLi, SSRF, IDOR, CSRF, deserialization) and LLM-specific attacks (jailbreak chains, indirect prompt injection via RAG content, agent hijacking via crafted tool outputs). Validate authentication mechanisms — OAuth, OIDC, SAML, MFA implementations, and JWT — and how they extend into AI-specific surfaces such as agent identity, per-user tool scoping, and prompt-level authorization. Assess session management, secrets handling, and data-flow controls in AI applications, including how user data ends up in prompts, logs, vector stores, and model fine-tunes. Execute client-side testing using browser dev tools and proxy-based inspection, evaluating DOM-based vulnerabilities, insecure local storage, and AI-driven client behaviors (e.g., embedded copilots and in-page agents). Test REST and GraphQL APIs using a combination of dynamic, manual, and automated methods; extend the same rigor to model and agent APIs. Perform code-assisted (grey-box) and full source review when available, identifying logic flaws, insecure configurations, and dangerous patterns specific to AI integrations (untrusted-content-into-prompt, unbounded tool use, missing output sanitization). Build, maintain, and contribute to Evolve Security’s AI red team methodology, payload libraries, evaluation harnesses, and reporting templates — and serve as the firm-wide reviewer for AI-related findings. Mentor mid-level penetration testing engineers and OSOC analysts through paired testing, technical review, knowledge-sharing sessions, and contributions to internal training and the academy. Represent Evolve Security externally through conference talks, blog posts, webinars, and client thought-leadership content on application security and AI red teaming. Communicate findings clearly, with strong emphasis on business impact, reproducibility, and strategic remediation guidance that engineering teams can actually ship. Success in the first 6 months looks like: Published, version-controlled AI red team methodology covering LLM applications, RAG systems, and agentic workflows, adopted across Evolve Security engagements. A reusable AI red team toolkit (custom Garak/PyRIT probes, payload libraries, evaluation harnesses) ready for any tester to use on a client engagement. Senior technical ownership of at least one strategic, AI-focused client account. Mentorship cadence in place with mid-level engineers and OSOC analysts; demonstrable uplift in their AI-related findings and reporting quality. At least one piece of public thought leadership (talk, blog, or research) attributed to Evolve Security. Who is Evolve Security? Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions. In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”,currentlyrankedthe #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practicalskills,needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies. We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent. Benefits Include Healthcare Benefits 401(k) Match Parental Leave Flexible Paid Time Off Annual vacation reimbursement #J-18808-Ljbffr Evolvesec

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior AI Security Red Team Lead & Offensive Testing Expert in Chicago, IL vacancy
  • Evolve Security is looking for a Senior Application Security Tester & AI Red Team Subject Matter Expert in Chicago, IL. In this senior-level role, you will lead application penetration tests and be a key authority in AI-enabled...  ...have 5-8+ years of offensive security experience... 
    Senior
    Flexible hours

    Evolve Security

    Chicago, IL
    2 days ago
  • $80.5k - $159.3k

     ...Crowe is seeking an Offensive Security Senior Consultant to navigate complex cybersecurity...  .... This role involves leading Offensive Security engagements including penetration testing and providing assessment...  ...collaborate with technical teams across various industries to... 
    Senior

    Crowe

    Chicago, IL
    3 days ago
  • $132k - $165k

    Early Warning is seeking a Senior Red Team Engineer in Chicago, Illinois. This role involves executing...  ...collaborating with internal teams on security assessments. Candidates should have at...  ...security experience, with 2 years in offensive security. Strong scripting skills in... 
    Senior

    Early Warning

    Chicago, IL
    3 days ago
  • Cedar Cares, Inc is looking for a Senior Red Team Specialist to execute advanced offensive security operations and engage in hands-on security engagements. Applicants should have over 5 years of experience in red teaming and strong communication skills. This role follows... 
    Senior

    Cedar Cares, Inc

    Chicago, IL
    2 days ago
  • $86.5k - $166k

     ...(IT) Management Level Senior Associate Job Description...  ...Summary At PwC, our people in Offensive Security focus on improving the...  ...against dedicated adversaries by testing key elements of the security...  ...threats. Those in the Red Team at PwC will focus on simulating... 
    Senior
    H1b
    Visa sponsorship
    Work visa
    Flexible hours

    PwC IT Services Co.

    Chicago, IL
    2 days ago
  • $138.21k - $172.76k

    A leading global restaurant brand is seeking a Senior Analyst, Cyber Defense - Penetration Testing, to identify vulnerabilities through offensive security testing. This role requires collaboration with stakeholders to ensure informed, risk-based decisions. Candidates should... 
    Senior

    McDonald's

    Chicago, IL
    5 days ago
  • $150k - $225k

     ...will be on the bleeding edge of AI, helping transform...  ...for our product and technology teams as you discover repeatable solutions...  ...discovery and scoping to POC, testing, and handover. ~ Code and...  ...instrument logging/metrics, add tests, security controls, and deployment... 
    Senior

    CADDi

    Chicago, IL
    4 days ago
  • $175k - $195k

     ...change they need to own their future. We are seeking a senior-level AI Security Architect to help clients design, secure, and scale...  ...modeling, architecture risk assessments, and AI security testing (including red teaming) for AI systems. Assess AI supply chain risk,... 
    Senior

    Huron Consulting Group Inc.

    Chicago, IL
    4 days ago
  • TransUnion LLC is seeking a skilled Red Teamer for their Cybersecurity team in Chicago. This role involves conducting in-depth threat emulation exercises, including Red Team and Purple Team operations to uncover vulnerabilities in our systems. The ideal candidate will have... 
    Senior
    Work at office

    TransUnion LLC

    Chicago, IL
    2 days ago
  • $167.37k - $209.21k

     ...business as the leading global omni-...  ...a time.?Using AI, robotics and...  ...and talented teams come in. They'...  ...Overview As Senior Manager, Offensive Security , you will lead...  ...penetration testers and red team operators...  ..., concurrent testing engagements...  ...regions ~ Expert-level... 
    Senior
    Local area
    Shift work

    McDonald's Corporation

    Chicago, IL
    2 days ago
  • $107k - $214.5k

     ...We are the leading provider of professional services...  ...looking for team members to join our Security, Privacy, and Risk Consulting...  ..., penetration testing, and secure architecture...  ...verbal) findings to senior management and...  ...Penetration Tester (GPEN); Offensive Security Certified... 
    Work experience placement
    Local area

    RSM US LLP

    Chicago, IL
    1 day ago
  •  ...personalized, and secure, PayPal empowers...  ...as one global team with our customers...  ..., Inc. seeks Senior Data Scientist in...  ...Job Duties: Lead the development...  ...machine learning and AI into fraud detection...  ...6. Developing, testing, and operating...  ...request is a red flag and likely... 
    Senior
    Work at office
    Local area
    Immediate start
    Remote work
    Flexible hours

    PayPal

    Chicago, IL
    1 day ago
  •  ...Senior Application Security Engineer AgileEngine is an Inc. 5000 company...  ...development and AI/ML, and our people-first...  ...Python engineering teams, and leverage LLMs...  ...application security testing tools, including SAST...  ...500 enterprises and leading product brands. Work... 
    Senior
    Flexible hours

    AgileEngine

    Chicago, IL
    18 hours ago
  • $103.2k - $154.8k

    A leading insurance provider is seeking a Senior Analyst SDET to lead the Quality Engineering efforts in their transformation. The role...  ...on establishing frameworks for automated testing and driving quality practices across teams. Key qualifications include 5+ years of experience... 
    Senior

    The Hartford

    Chicago, IL
    5 days ago
  •  ...Title: Senior Security Architect - SaaS / Cloud Platforms...  ...Architecture Role Overview of Team & Need The client...  ...based in Chicago and leads a team within Security...  ...response plan, pen testing Very good understanding...  ...Knowledge related to AI, specifically Microsoft... 
    Senior
    Work experience placement
    Work at office

    Spectraforce Technologies

    Chicago, IL
    1 day ago
  • $145k - $192.5k

    Cyber Threat Defense AI Security Senior Engineer Bank of...  ...Security (GIS) team. Location Denver,...  ...Act as a technical expert on AI‑driven cybersecurity...  ...Collaborate with offensive security teams to...  ...AI‑enhanced red teaming and adversarial...  .... Experience leading large‑scale technical... 
    Senior

    Bank of America

    Chicago, IL
    2 days ago
  • $130k - $180k

     ...finally made it possible for AI to impact clinical care in...  ..., at the right time. Senior Application Security Engineer Tempus is seeking...  ...expertise in penetration testing to join our Application Security team. In this role, you will lead efforts to identify and remediate... 
    Senior

    Tempus

    Chicago, IL
    3 days ago
  • $77k - $202k

     ...Management Level Senior Associate Job...  ...Dynamics team will provide the opportunity...  ...of success with leading efforts to...  ...and Subject Matter Experts for signoff; Developing...  ...solution testing, building test cases...  ...thoughtfully to establish a secure and trusted... 
    Senior
    Work experience placement
    H1b

    PricewaterhouseCoopers

    Chicago, IL
    12 days ago
  •  ...ll work with leading companies across...  ...cloud and AI journeys. With...  ..., and Red Hat, you’ll have...  ...technologies to uncover security...  ...in joining a team of like-minded passionate experts, many of whom...  ...X-Force Red Offensive Security team...  ...penetration tests against clients... 
    Senior
    Worldwide

    IBM

    Chicago, IL
    7 days ago
  • McDonald's Corporation is seeking a Senior Manager, Offensive Security to lead a global team of penetration testers based in Chicago. You will oversee offensive security operations, ensuring the identification and mitigation of security risks across the enterprise. The... 

    McDonald's Corporation

    Chicago, IL
    4 days ago
  • $171.7k - $300.5k

     ...sophisticated clients using leading technology and exceptional service...  .... • Approves Information Security, (IS), architecture/designs,...  ...audits, the evaluation and testing of hardware, firmware and software...  ...• Negotiates with senior leaders across the business... 
    Senior
    Work experience placement
    H1b
    Flexible hours

    Northern Trust

    Chicago, IL
    4 days ago
  • $131k - $169k

     ...Senior Security Engineer Seeking a development & cloud focused Senior...  ...join our expanding security team. The ideal candidate will have...  ...passion for AppSec, Cloud and AI. They will be a skilled communicator...  ...teams to remedy items and testing fixes ~ Working with... 
    Senior
    Work at office
    Work from home
    Flexible hours
    Day shift

    Karbon

    Chicago, IL
    5 days ago
  • $125k - $140k

     ...Senior Business Systems Analyst This...  ...strength is a talented team who flourish in...  ...financial security while delivering...  ...artificial intelligence (AI) and automation...  ...subject matter experts, technical...  ...and tools. Leads and performs requirements...  ...to creation of test plans/matrices/... 
    Senior
    Temporary work
    Work experience placement
    Work at office
    Local area
    Flexible hours

    Ascot Group

    Chicago, IL
    10 days ago
  • $160.58k - $231.95k

    Senior Discovery IT System Administrator Employment Type: Full-Time...  ...systems, ensuring availability, security, and integration with cloud...  ...installation, configuration, testing, and maintenance of operating...  ...[email protected] We may use AI tools to support the hiring process... 
    Senior
    Full time
    Flexible hours

    CGS Federal (Contact Government Services)

    Chicago, IL
    1 day ago
  • Senior / Lead Conversational AI & Digital Payments Solutions Engineer 02/04/2026 Contract...  ...will design scalable, secure, and high-performing solutions...  ...needed. Partner with cloud teams (AWS, Azure, GCP) to ensure...  ...design, data preparation, testing, and feedback loops. Understanding... 
    Senior
    Contract work

    Compunnel, Inc.

    Chicago, IL
    2 days ago
  •  ...Business Intelligence team is building AI-enabled analytics...  ...We're seeking a Senior Software...  ...build, establish secure development workflows...  ...implement automated testing, security...  ...BigQuery, Redshift) Expert-level SQL, query...  ...Collaboration Leads by example through... 
    Senior
    Contract work
    Remote work
    Relocation package

    GE Aerospace

    Chicago, IL
    18 hours ago
  • $52 - $74 per hour

     ...Services client is seeking a Lead Security Architect to join their enterprise security team! This position is based...  ..., and penetration testing Collaborate with...  ...security subject matter expert within the enterprise security...  ...Exposure to AI security concepts and Microsoft... 
    Work at office
    Local area
    3 days per week

    KellyMitchell Group

    Chicago, IL
    5 days ago
  • $128.1k - $239.6k

     ...powerhouse of diverse teams and take your...  ...is seeking a Cloud Security consultant with expertise...  ...consultant will lead the enablement of CNAPP...  ...automated security testing and compliance,...  ...SME (subject matter expert) to mature/advance...  .... Enabled by data, AI and advanced technology... 
    Senior
    Summer holiday
    Local area
    Flexible hours
    Shift work

    Ernst & Young Oman

    Chicago, IL
    2 days ago
  •  ...You’ll work with leading companies across...  ...cloud and AI journeys. With support...  ...technology, and Red Hat, you’ll have...  .... This is a senior individual contributor...  ..., and business teams to ensure...  ...enterprise standards for security, scalability,...  ..., monitoring, testing, evaluation pipelines... 
    Senior
    Worldwide

    IBM

    Chicago, IL
    1 day ago
  • $66 - $95 per hour

     ...: Our client is seeking a Lead Security Architect to join their team! This position is located...  ...Information Security Architect, Senior Security Consultant, and...  ...Texas.Duties:Develop unit tests during the development...  ...remote.Duties:Analysis of the AI-powered featuresIdentify... 
    Local area
    Remote work

    KellyMitchell Group

    Chicago, IL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior AI Security Red Team Lead & Offensive Testing Expert. Be the first to apply!