Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Tester & AI Red Team Subject Matter Expert

Evolve Security

The Senior Application Security Tester & AI Red Team Subject Matter Expert is a senior-level offensive security role for a tester who has mastered modern web and API security and is now defining how Evolve Security tests AI-enabled applications, large language models, and agentic systems. This role wears two hats: hands-on senior application penetration tester for our most complex client engagements, and the firm-wide subject matter expert who builds, scales, and represents Evolve Security's AI red team practice. The senior tester executes assessments with full autonomy, owns the technical relationship with client security and engineering leadership, mentors mid-level engineers and OSOC analysts, and is the recognized internal authority on offensive AI/ML testing methodology, tooling, and threat modeling.

Requirements

Typical Experience: 5-8+ years of offensive security experience with a deep concentration in web application and API penetration testing, plus demonstrable hands-on work testing AI/ML systems - LLM-backed applications, RAG pipelines, fine-tuned models, multi-agent systems, or production ML inference. A track record of dozens of completed assessments, published research, conference talks, CVEs, or open-source contributions is expected.

Domain Expertise: Mastery of web application and API security beyond the OWASP Top 10 - business logic abuse, complex authentication and authorization flows (OAuth 2.0 / OIDC, SAML, JWT, mTLS), SSRF chains, deserialization, request smuggling, prototype pollution, and modern SPA / GraphQL attack surface. Equally fluent in the OWASP Top 10 for LLM Applications and OWASP ML Top 10 - prompt injection (direct, indirect, multi-modal), jailbreaks and safety bypasses, insecure output handling, training data poisoning and extraction, model denial of service, supply chain vulnerabilities in model and plugin ecosystems, excessive agency in agentic systems, sensitive data leakage from system prompts and embeddings, and vector store / RAG poisoning.

Technical Skills: Expert with the modern offensive toolchain - Burp Suite Pro (including custom extensions), OWASP ZAP, Nuclei, Postman, Nmap, Metasploit, BloodHound - and able to build bespoke tooling when the off-the-shelf option falls short. Comfortable with AI red-teaming tooling such as Garak, PyRIT, Promptfoo, Giskard, and adversarial ML libraries, and confident designing custom evaluation harnesses against client-specific LLM and agent stacks. Strong scripting and small-tool development in Python, with working knowledge of JavaScript / TypeScript, Bash, and PowerShell. Familiar with the components of modern AI applications: vector databases (Pinecone, Weaviate, pgvector), embedding models, retrieval pipelines, agent frameworks (LangChain, LlamaIndex, CrewAI), and tool-use protocols including MCP.

Soft Skills: Excellent written and verbal communication - produces publication-quality reports with no editorial rework, leads CISO and engineering-leader briefings, and de-escalates contested findings with technical rigor. Mentors mid-level engineers and OSOC analysts through code review, paired testing, and methodology coaching. Comfortable representing Evolve Security externally - webinars, podcasts, conference CFPs, and client thought-leadership content.

Certifications (Preferred, not required): OSWE, OSCP, OSEP, GWAPT, GXPN, Burp Suite Certified Practitioner; AI/ML-adjacent credentials and contributions such as AI Red Team certifications, published prompt injection research, MITRE ATLAS contributions, or SANS SEC545/SEC595.
Expertise that aligns to our approach
  • Lead end-to-end web application and API penetration tests as the senior technical owner, scoping the engagement, executing the assessment, and presenting findings to client security and engineering leadership.
  • Apply structured testing techniques aligned to OWASP WSTG and OWASP API Security Top 10 to assess authentication, session management, access control (vertical and horizontal privilege escalation), input validation, error handling, and business logic flaws.
  • Design and execute AI red team engagements against LLM-backed applications, RAG systems, and agentic workflows - covering prompt injection (direct, indirect, multi-modal), jailbreak resilience, system prompt and tool-use exfiltration, training data and embedding leakage, insecure output handling, and excessive agency in tool-using agents.
  • Map AI findings to the OWASP Top 10 for LLM Applications, OWASP ML Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework so client stakeholders can defend severity and remediation calls internally.
  • Test the full AI application surface: model endpoints, prompt and response pipelines, retrieval augmentation, vector stores, fine-tuning pipelines, plugin / tool integrations (including MCP servers), guardrail and safety layers, and supporting cloud infrastructure.
  • Demonstrate proficiency in manual exploit development for both classical web vulnerabilities (XSS, SQLi, SSRF, IDOR, CSRF, deserialization) and LLM-specific attacks (jailbreak chains, indirect prompt injection via RAG content, agent hijacking via crafted tool outputs).
  • Validate authentication mechanisms - OAuth, OIDC, SAML, MFA implementations, and JWT - and how they extend into AI-specific surfaces such as agent identity, per-user tool scoping, and prompt-level authorization.
  • Assess session management, secrets handling, and data-flow controls in AI applications, including how user data ends up in prompts, logs, vector stores, and model fine-tunes.
  • Execute client-side testing using browser dev tools and proxy-based inspection, evaluating DOM-based vulnerabilities, insecure local storage, and AI-driven client behaviors (e.g., embedded copilots and in-page agents).
  • Test REST and GraphQL APIs using a combination of dynamic, manual, and automated methods; extend the same rigor to model and agent APIs.
  • Perform code-assisted (grey-box) and full source review when available, identifying logic flaws, insecure configurations, and dangerous patterns specific to AI integrations (untrusted-content-into-prompt, unbounded tool use, missing output sanitization).
  • Build, maintain, and contribute to Evolve Security's AI red team methodology, payload libraries, evaluation harnesses, and reporting templates - and serve as the firm-wide reviewer for AI-related findings.
  • Mentor mid-level penetration testing engineers and OSOC analysts through paired testing, technical review, knowledge-sharing sessions, and contributions to internal training and the academy.
  • Represent Evolve Security externally through conference talks, blog posts, webinars, and client thought-leadership content on application security and AI red teaming.
  • Communicate findings clearly, with strong emphasis on business impact, reproducibility, and strategic remediation guidance that engineering teams can actually ship.
Success in the first 6 months looks like:
  • Published, version-controlled AI red team methodology covering LLM applications, RAG systems, and agentic workflows, adopted across Evolve Security engagements.
  • A reusable AI red team toolkit (custom Garak/PyRIT probes, payload libraries, evaluation harnesses) ready for any tester to use on a client engagement.
  • Senior technical ownership of at least one strategic, AI-focused client account.
  • Mentorship cadence in place with mid-level engineers and OSOC analysts; demonstrable uplift in their AI-related findings and reporting quality.
  • At least one piece of public thought leadership (talk, blog, or research) attributed to Evolve Security.
Benefits

Who is Evolve Security?


Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client's security posture by providing continuous penetration testing, training services, and talent solutions.


In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, "Evolve Academy", currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.


We are passionate about directly improving our customers' security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.


Benefits Include
  • Healthcare Benefits
  • 401(k) Match
  • Parental Leave
  • Flexible Paid Time Off
  • Annual vacation reimbursement
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior Application Security Tester & AI Red Team Subject Matter Expert in United States vacancy
  •  ...Artificial Intelligence Subject Matter Expert (SME) Job Title...  ...Secret SUMMARY: The AI SME serves as the...  ...within the Security Operations Center (SOC...  ...assessing a range of AI applications. Conduct operational...  ...adversarial AI testing and red-teaming WORKING CONDITIONS... 
    Suggested

    Agile Defense

    Reston, VA
    1 day ago
  • $180k - $225k

     ...Senior Program Protection & Technology Security Foreign Disclosure Subject Matter Expert This is a unique opportunity to support a high-priority...  ...(P2/TSFD SMEd) to join our team to help contribute to our...  ...requires high level application and practitioner level understanding... 
    Senior
    Contract work
    Work at office

    Technology Security Associates

    Arlington, VA
    2 days ago
  • $149.6k - $254.32k

     ...experienced Radar Systems Subject Matter Expert (SME) to serve as a...  ...decisions, advising senior leadership and...  ...across multidisciplinary teams and customer organizations...  ...critical national security missions....  ...processing and mission applications. ~ Ability to influence... 
    Senior
    Full time
    Temporary work
    Work at office
    Local area
    Remote work

    BAE Systems USA

    Westminster, CO
    2 days ago
  •  ...Title: Senior Subject Matter Expert *Local to DMV area Description: • Design...  ...multi-factor authentication for secure remote access to internal systems and applications. • Implement secure access...  ...transfer materials to internal IT teams and business stakeholders.... 
    Senior
    Work experience placement
    Work at office
    Local area
    Remote work

    3B Staffing LLC

    Laurel, MD
    19 hours ago
  •  ...Intelligence Ethics Subject Matter Expert Analytica is...  ...skilled and security-cleared Artificial...  ...artificial intelligence (AI) platforms across...  ...and advise senior leadership on their...  ...technology, applications, or policy. Minimum...  ...to assist our team. All hiring decisions... 
    Suggested
    For contractors
    Local area

    Analytica

    Washington DC
    1 day ago
  •  ...Seeking a full-time Senior Application Security Tester who will serve as both a hands-on penetration tester for complex client engagements and a subject matter expert in AI red teaming, working remotely to define testing methodologies for AI-enabled applications and mentor... 
    Senior
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 hours ago
  •  ...AI/ML Subject Matter Expert (SME) / Analytics Team Lead Nationwide IT Services, NIS, is seeking an AI/ML Subject Matter Expert (SME) / Analytics Team...  ...staff to integrate AI/ML capabilities into enterprise applications and data environments. Support data exploration,... 
    For contractors
    Work at office

    Nationwide IT Services, Inc.

    Arlington, VA
    2 days ago
  •  ...a world-class team of professionals...  ...intelligence (AI), machine learning...  ...US's dedicated experts in defense, aerospace, security, and related...  ...Strategic Engagement Subject Matter Expert to lead...  ...advising senior leadership on stakeholder...  ...All Qualified Applicants will receive... 
    Work at office

    Avantus

    Arlington, VA
    15 hours ago
  •  ...Senior Subject Matter Expert Until Filled (EST) DHS Arlington, VA, USA Full Time Location: Arlington...  ...ensure alignment with mission and security priorities. Responsibilities:...  ...facilitating knowledge transfer across teams. Ensure solutions align with DHS enterprise... 
    Senior
    Full time
    Contract work

    Silo Smashers

    Arlington, VA
    2 days ago
  • $109 - $112 per hour

     ...Senior Ping Identity Subject Matter Expert Genesis10 is currently seeking a Senior Ping Identity Subject Matter Expert for a remote position...  ...expertise across the Ping Identity ecosystem Advise teams on application onboarding, authentication flows, federation, and... 
    Senior
    Hourly pay
    Contract work
    Remote work

    Genesis10

    United States
    2 days ago
  •  ...candidate to join our talented Team. Job Title: Senior Subject Matter Expert Location(s): Washington, DC...  ...Software Development Methodologies, Security Engineering, Communications and...  ...required. All qualified applicants will receive consideration for employment... 
    Senior

    Ampcus

    Washington DC
    1 day ago
  • $105k

     ...knowledge with a multifaceted team of world-class engineers...  ...Sector (SES) is seeking an EDL Subject Matter Expert (SME) to help the Dragonfly...  ...obtain a Top Secret level security clearance. If selected, you...  ...at  .   All qualified applicants will receive consideration... 
    Temporary work
    For contractors
    Work experience placement
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Laboratory (APL)

    Laurel, MD
    19 hours ago
  •  ...Senior Maritime Data And Infrastructure Subject Matter Expert (Dot) Bowhead seeks a Senior Maritime Data & Infrastructure SME to join our team in Washington, DC. This position reports directly to the...  ...Salary Range: 75,000-95,000 SECURITY CLEARANCE REQUIRED: Must be... 
    Senior
    Work at office
    Remote work

    Bowhead

    Washington DC
    19 hours ago
  •  ...customers. We are hiring a Senior ATO/A&A Subject Matter Expert to support an enterprise-...  ...identify and prioritize application-level vulnerabilities and drives remediation of Security Technical Information Guide...  ...with the technical team. Creates, documents, and manages... 
    Senior
    For contractors
    Work at office
    Local area
    Immediate start
    Remote work

    ESM

    Washington DC
    2 days ago
  •  ...Technologies is seeking a Senior ATO Subject Matter Expert to support federal cybersecurity...  ...this role, you will lead Security Assessment & Authorization...  ...with cybersecurity teams, engineers, system owners,...  ...Employer and all qualified applicants will receive consideration... 
    Senior
    Local area

    GAMA-1 Technologies

    Washington DC
    1 day ago
  •  ...Integrated Maintenance Data System (IMDS) Senior Subject Matter Expert (SME) Consulting Solutions -...  ...our Field Assistance Services (FAS) team. The Field Assistance...  ..., desktop, and system components, as applicable). ~ Strong analytical and problem... 
    Senior
    Worldwide
    Monday to Friday
    Shift work
    Weekend work
    Day shift

    Zigabyte Corporation

    Montgomery, AL
    4 days ago
  • $150k

     ...Senior Subject Matter Expert — Federal Contracting & Compliance Employment Type Full-Time, Exempt |...  ...permanent W-2 position anchoring PSCG's core team. The role is not tied to any specific...  ...client counterparts on FAR and DFARS application as a billable consultant. • Support... 
    Senior
    Permanent employment
    Full time
    For contractors
    For subcontractor

    Essential HealthCare Solutions, LLC

    Dallas, TX
    19 hours ago
  •  ...Senior Subject Matter Expert In Card Payments Join Enfuce at a pivotal moment as we build and scale our next-generation card processing platform...  ...), acting as the primary SME authority across internal teams and scheme counterparts, deeply analysing and resolving issues... 
    Senior
    Remote work
    Work visa
    Flexible hours

    Enfuce

    United States
    5 days ago
  • $178.4k - $226.7k

     ...Amazon is seeking a Senior Security Engineer for our AI Red Team within Threat Operations. This experienced engineer will conduct Red Team operations...  ...offensive security and a strong understanding of cloud and application security principles. The compensation package... 
    Senior

    Amazon

    New York, NY
    1 day ago
  •  ...Senior Infrastructure Subject Matter Expert (SME) BeVera Solutions, LLC is a rapidly growing public health and...  ...to federal and state agencies. Our team supports mission-critical programs...  ...prohibit discrimination against any applicant or employee based on race, color, religion... 
    Senior
    Contract work
    Work at office
    Local area
    3 days per week

    BeVera Corps

    Atlanta, GA
    19 hours ago
  • $150k - $200k

     ...quality in every aspect. As experts in healthcare IT, Apex is...  ...seeking highly experienced Senior Domain Subject Matter Experts to provide deep mission...  ...for an assigned embedded team, offering specialized...  ...requirements (e.g., HIPAA), and security policies. Qualifications... 
    Senior
    Contract work
    Remote work

    Goldbelt

    Falls Church, VA
    7 days ago
  •  ...where innovation meets passion. Every team member is a vital piece of our...  ...today! Responsibilities: The Subject Matter Expert (Senior) defines requirements, performs analyses...  ...Affirmative Action employer. All qualified applicants will receive consideration for... 
    Senior
    Full time
    Temporary work
    Flexible hours

    Interclypse

    Annapolis, MD
    2 days ago
  •  ...Senior Hcm Subject Matter Expert Spatial Front, Inc. (SFI), a two-time USA Today...  ...Expert to join our growing team. The ideal candidate will...  ...possess an active Secret security clearance or be able to obtain...  ...Employer — all qualified applicants will receive consideration... 
    Senior
    Full time
    Contract work

    Spatial Front

    Arlington, VA
    19 hours ago
  •  ...where innovation meets passion. Every team member is a vital piece of our...  ...applying today! Responsibilities The Subject Matter Expert (Senior) defines requirements, performs analyses...  ...Action employer. All qualified applicants will receive consideration for employment... 
    Senior
    Temporary work
    Flexible hours

    Interclypse

    Annapolis Junction, MD
    19 hours ago
  •  ...Senior Medical Coding Subject Matter Expert Federal Health Contract Support, Defense Health Agency (DHA) Position contingent on contract award (target...  ...and steering committees on behalf of the contractor team. Brief MCPB leadership and the DHA Contracting Officer... 
    Senior
    Full time
    Contract work
    For contractors
    Local area
    Remote work
    Worldwide
    Monday to Friday

    ASRT Inc.

    Falls Church, VA
    25 minutes ago
  • $100k - $140k

     ...The Team The Global Delivery division is responsible for onboarding all new clients...  ...verticals - Software Implementation, Subject Matter Expertise, and Managed Services - and...  ...time of this posting. Consistent with applicable law, compensation will be determined based... 
    Senior
    Work at office

    Clearwater Analytics

    Chicago, IL
    3 days ago
  •  ...experienced Anti-Tamper (AT) Subject Matter Experts to support the Anti...  ...directly supporting senior Department of the Air...  ...Sky, you'll join a team of mission-driven...  ...critical national security challenges . We empower...  .... All qualified applicants will receive consideration... 
    Senior

    Blue Sky Innovators Inc

    Washington DC
    2 hours ago
  •  ...Transportation Subject Matter Expert, Senior Manager Industry Applications-PRD professionals design, implement and deploy packaged software solutions that have...  ...outside area of responsibility. Manages large teams and/or work efforts (if in an individual contributor... 
    Senior

    ClifyX

    Hartford, CT
    2 hours ago
  • $161k - $188k

     ...and Canada. Their cross-disciplinary team collaborates closely with clients to...  ...Future Of Mobility.” Job Summary: The Senior Subject Matter Expert - Railway Vehicles (Implementation...  ...acquisition for projects, such as grant applications to state and federal agencies.... 
    Senior
    Full time
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area
    Remote work
    Work from home
    Home office
    Flexible hours
    Night shift

    DB E.C.O. North America

    United States
    3 days ago
  •  ...are a world-class team of professionals...  ...artificial intelligence (AI), machine...  ...QinetiQ US's dedicated experts in defense, aerospace, security, and related...  ...Analyst Subject Matter Expert to provide senior-level expertise on...  ...advisory support on the application of defense acquisition... 
    Work at office

    QinetiQ US

    Arlington, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Tester & AI Red Team Subject Matter Expert. Be the first to apply!