> Markdown version of [/jobs/ext/2477350-ai-enhanced-penetration-tester](https://www.wearedevelopers.com/jobs/ext/2477350-ai-enhanced-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI-Enhanced Penetration Tester - **Company:** AXA - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Data Analysis, Apple Mac Systems, Application Integration Architecture, Software System Penetration Testing, Microsoft Azure, Big Data, Burp Suite, Cloud Computing Security, Static Program Analysis, Computer Programming, Computer Networks, Linux, Python (Programming Language), Network Security, Machine Learning, Natural Language Processing, Network Architecture, Network Protocols, Nmap, Open Source Intelligence, Open Web Application Security, Tensorflow, Systems Architecture, TCP/IP, Web Applications, Scripting, Google Cloud, Cloud Platform System, Pytorch, Large Language Models, Prompt Engineering, Deep Learning, Scikit Learn, Metasploit, Data Analytics, Nessus, Machine Learning Operations, Unsupervised Learning, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 11, 2026 - **Apply:** https://es.indeed.com/viewjob?jk=5da0c35dc8d20c2e ## About the Role + 3+ years of hands-on experience in penetration testing, ethical hacking, or offensive security roles. + Proven experience or strong demonstrable interest in applying AI/ML concepts and tools to cybersecurity challenges. * Preferred: * + Experience with specific AI-powered security tools for vulnerability scanning, threat intelligence, attack surface management, or code analysis. + Experience in developing or customizing AI/ML models for offensive security tasks (e.g., natural language processing for social engineering, anomaly detection for network traffic, predictive modeling for vulnerabilities). + Active participation in the security community (e.g., CTFs, conferences, open-source contributions related to AI in security). Technical skills * Deep Penetration Testing Expertise: Strong understanding of traditional penetration testing methodologies, tools (e.g., Burp Suite, Nmap, Metasploit, Nessus), and common vulnerabilities (e.g., OWASP Top 10, CWE). * Programming Proficiency: Expert-level proficiency in Python is essential, with experience in developing scripts, automation, and integrating APIs. * AI/ML Fundamentals: Solid understanding of core AI/ML concepts, algorithms, and data science principles (e.g., supervised/unsupervised learning, deep learning, NLP). * Cloud Security: Experience with security assessments in cloud environments (AWS, Azure, GCP). * Operating Systems: Proficient with Linux, Windows, and macOS environments. * Networking: Strong understanding of TCP/IP, network protocols, and common network security controls. * Preferred Technical Knowledge: * + Familiarity with common ML frameworks (e.g., TensorFlow, PyTorch, Scikit-learn) for understanding how to integrate or leverage them. + Experience with large language models (LLMs) and their potential applications in offensive security (e.g., prompt engineering for attack generation, code analysis). * Certifications (Preferred): Relevant security certifications such as OSCP, OSWE, OSCE, GXPN, GPEN, CEH. Soft skills / transversal skills * Analytical Skills: Exceptional problem-solving abilities, with a creative and innovative mindset to identify and exploit complex vulnerabilities, and to analyze large datasets for security insights. * Communication: Excellent written and verbal communication skills, with the ability to clearly articulate technical findings, risks, and recommendations to diverse technical and non-technical audiences. * Collaboration & Knowledge Sharing: Ability to work closely with other security engineers, developers, and infrastructure teams to communicate findings, foster a culture of secure development, and mentor junior team members on AI-enhanced techniques. * Continuous Learning: A strong drive for continuous learning and development in the rapidly evolving fields of AI and cybersecurity. ## Description Join us as an AI-Enhanced Penetration Tester to revolutionize cybersecurity with cutting-edge AI/ML techniques. Conduct advanced assessments, automate vulnerabilities, and proactively defend against complex threats. Innovate, analyze, and strengthen digital defenses in a dynamic, forward-thinking environment!, We are seeking a highly skilled and forward-thinking individual to elevate our cybersecurity posture by applying Artificial Intelligence and Machine Learning techniques to traditional penetration testing, attack surface monitoring, and vulnerability assurance. The primary purpose of this role is to enhance the efficiency, depth, and proactive capabilities of our offensive security operations. You will be instrumental in identifying complex vulnerabilities, simulating advanced cyberattacks, and providing data-driven insights that directly contribute to AXA's robust security and digital posture, ensuring effective controls are in place and aligned with our Group Security Corporate function's mandate for advanced assurance and monitoring. Main missions As our AI-Enhanced Penetration Tester, your key missions will include: * Conduct Advanced Penetration Tests: Perform detailed security assessments and penetration tests across a wide range of traditional systems, including web applications, APIs, network infrastructure, cloud environments (AWS, Azure, GCP), and internal systems. * Integrate AI into Pentesting Workflows: Research, evaluate, and implement AI/ML tools and techniques to augment and automate various stages of the penetration testing lifecycle, such as: + Intelligent Reconnaissance for advanced OSINT, asset discovery, and mapping complex attack surfaces. + Automated Vulnerability Discovery using AI/ML for smarter fuzzing, code analysis (SAST/DAST), and identifying logical flaws. + Exploit Generation Assistance leveraging AI to assist in developing sophisticated exploits and bypasses. + Threat Modeling & Attack Path Analysis utilizing AI to analyze system architecture and predict likely attack vectors. + Payload Generation & Obfuscation employing AI to create highly effective and evasive payloads. + Behavioral Anomaly Detection to identify suspicious activities during tests. * Continuous Attack Surface Monitoring (ASM): Utilize AI-driven tools and techniques to continuously monitor and map the organization's dynamic attack surface, identifying new assets, services, and potential entry points. Proactively detect changes that could introduce new risks or expand the attack surface. * Vulnerability Landscape Assurance: Leverage AI and data analytics to perform assurance activities on the overall vulnerability landscape. This includes: + Validating the effectiveness of vulnerability scanning tools. + Analyzing vulnerability data to identify trends, prioritize remediation efforts, and assess the true risk posture. + Performing re-verification of remediated vulnerabilities using AI-assisted methods to ensure closure and prevent recurrence. + Providing data-driven insights into the efficacy of security controls. * Tool Development & Customization: Develop custom scripts, tools, and integrate AI/ML models to enhance existing penetration testing platforms and create novel offensive security capabilities. * Reporting & Remediation: Document detailed findings, including proof-of-concept exploits, risk assessments, and clear, actionable recommendations for remediation to development and operations teams. * Research & Innovation: Stay at the forefront of AI advancements in cybersecurity, actively research new attack techniques, and explore emerging AI/ML applications for offensive security. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) - [Spot, Squash, Secure: Fighting Security Bugs with GitHub Copilot](https://www.wearedevelopers.com/videos/100052-spot-squash-secure-fighting-security-bugs-with-github-copilot) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)