> Markdown version of [/jobs/ext/1416352-pentester-offensive-forward-deployment-engineer](https://www.wearedevelopers.com/jobs/ext/1416352-pentester-offensive-forward-deployment-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Pentester, Offensive Forward Deployment Engineer - **Company:** Mistral AI - **Location:** Paris, France - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Code Review, Continuous Integration, Open Source Technology, Software Security, Machine Learning Operations, Programming Languages - **Published:** July 24, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=ef180f40d662912b ## About the Role * Current P0 specialty: web / AppSec + source-code review; also high-value: internal / Active Directory, cloud (AWS/GCP/Azure), CI/CD & supply chain * Senior enough to run an engagement solo from scoping to delivery * Uses AI in your workflow with a nuanced view of its capabilities and limitations * Comfortable being client-facing, mobile, and switching between different engagements * Proven track record of delivering high-quality penetration testing results * Strong problem-solving abilities and attention to detail in vulnerability identification It would be ideal if you also have: * Build your own offensive tooling (builder mindset that scales your impact) * Published CVEs / GHSAs or a strong bug-bounty track record * Conference talks, CTF achievements, or other public recognition in the security community * Strong code review skills for multiple programming languages * Experience with AI/ML systems and their unique security challenges * Contributions to open-source security tools or research ## Description * Run our offensive security solution on real client engagements: scoping, executing tooling, and delivering results * Triaging output and killing false positives to ensure high-quality, actionable findings for clients * Advise clients through deployment and remediation, acting as a trusted security partner * Travel to client premises and switch between engagements in a classic pentest consulting cadence Internal Dogfooding * Pentest Mistral's own systems, finding vulnerabilities before our offensive solution matures * Hunt for vulnerabilities internally and on open-source/in-the-wild targets between client engagements * Transfer knowledge and findings to the forming internal security team * Act as Mistral's own first customer for our cyber harnesses Guiding the Harness * Use real offensive expertise to steer the cyber harness: identify vulnerabilities it should catch * Validate and triage the harness's output, ensuring it meets the high standards of human pentesters * Benchmark human vs. agent performance, helping to close the gap between automated and manual testing * Contribute to the development of AI-powered offensive security capabilities ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)