> Markdown version of [/jobs/ext/1334552-senior-ai-llm-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1334552-senior-ai-llm-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior AI/LLM Penetration Tester - **Company:** Bishop Fox - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Microsoft Azure, Cloud Computing, Cloud Engineering, Code Review, Cyber Security, Computer Programming, Information Leak Prevention, Python (Programming Language), Machine Learning, Open Source Technology, Open Web Application Security, Process Driven Development, Systems Development Life Cycle, Red Team (Cyber Security), Web Application Security, Software Engineering, Scripting, Large Language Models, Software Security, GWAPT, AI Platforms, Information Technology, Virtual Agents - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3dbaf1fc3c3dd9d5 ## About the Role * 5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments * Experience assessing AI/LLM-powered applications for vulnerabilities such as: + Prompt injection + Jailbreak techniques + Indirect prompt injection + Data leakage and sensitive information disclosure + Insecure tool/function calling + Agentic AI abuse + Model misuse and unsafe output generation + Understanding of modern AI architectures, including: * Experience performing manual application security testing beyond automated scanning * Strong understanding of web application security fundamentals, including the OWASP Top 10 Web, Agentic, and LLM Applications. * Experience reviewing AI application architectures and identifying security weaknesses across APIs, cloud infrastructure, and application logic * Experience performing source code review and dynamic testing * Familiarity with cloud platforms (AWS, Azure, or GCP) and securing AI workloads * Scripting or programming experience in Python, JavaScript Go, Java, or similar languages * Familiarity with LLM application and agent-orchestration frameworks, inference provider APIs, external capability integration for models, and open source tooling across commercial and self-hosted ecosystems. * Knowledge of authentication, authorization, networking, APIs, and secure software development practices * Excellent written and verbal communication skills, including presenting findings to technical and executive audiences * Ability to mentor teammates and contribute to internal research, tooling, and methodology development * OSCP, OSEP, GWAPT, GPEN, GXPN, or other relevant certifications are helpful but not required * Bachelor's degree in Computer Science, Cybersecurity, or a related technical field is a plus What Sets You Apart * Experience conducting AI red team exercises against production or pre-production AI systems * Research into emerging AI attack techniques or contributions to the offensive security community * Experience building or securing AI agents and autonomous workflows * Knowledge of adversarial machine learning concepts and model security * Experience with cloud-native AI platforms such as Azure OpenAI, Amazon Bedrock, or Google Vertex AI * Familiarity with AI software development lifecycle (AI SDLC) and AI governance frameworks ## Related Videos - [Prompt Injection, Poisoning & More: The Dark Side of LLMs](https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools](https://www.wearedevelopers.com/videos/1217-can-machines-dream-of-secure-code-emerging-ai-security-risks-in-llm-driven-developer-tools) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path)