> Markdown version of [/jobs/ext/424151-pentester-offensive-forward-deployment-engineer](https://www.wearedevelopers.com/jobs/ext/424151-pentester-offensive-forward-deployment-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Pentester, Offensive Forward Deployment Engineer - **Company:** Mistral AI - **Location:** Paris, France (Remote available) - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Code Review, Continuous Integration, Open Source Technology, Software Security, Machine Learning Operations, Programming Languages - **Published:** June 12, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=486aeb28de654e6a ## About the Role * Current P0 specialty: web / AppSec + source-code review; also high-value: internal / Active Directory, cloud (AWS/GCP/Azure), CI/CD & supply chain * Senior enough to run an engagement solo from scoping to delivery * Uses AI in your workflow with a nuanced view of its capabilities and limitations * Comfortable being client-facing, mobile, and switching between different engagements * Proven track record of delivering high-quality penetration testing results * Strong problem-solving abilities and attention to detail in vulnerability identification It would be ideal if you also have: * Build your own offensive tooling (builder mindset that scales your impact) * Published CVEs / GHSAs or a strong bug-bounty track record * Conference talks, CTF achievements, or other public recognition in the security community * Strong code review skills for multiple programming languages * Experience with AI/ML systems and their unique security challenges * Contributions to open-source security tools or research Location & Remote This role is open to remote in Europe. Ideally you would be based in one of our European offices (Paris, France and London, UK). We strongly believe in the value of in-person collaboration and we encourage going to the office as much as we can (at least 3 days per months) to create bonds and smooth communication. Our remote policy aims to provide flexibility, improve work-life balance and increase productivity. ## Description * Run our offensive security solution on real client engagements: scoping, executing tooling, and delivering results * Triaging output and killing false positives to ensure high-quality, actionable findings for clients * Advise clients through deployment and remediation, acting as a trusted security partner * Travel to client premises and switch between engagements in a classic pentest consulting cadence Internal Dogfooding * Pentest Mistral's own systems, finding vulnerabilities before our offensive solution matures * Hunt for vulnerabilities internally and on open-source/in-the-wild targets between client engagements * Transfer knowledge and findings to the forming internal security team * Act as Mistral's own first customer for our cyber harnesses Guiding the Harness * Use real offensive expertise to steer the cyber harness: identify vulnerabilities it should catch * Validate and triage the harness's output, ensuring it meets the high standards of human pentesters * Benchmark human vs. agent performance, helping to close the gap between automated and manual testing * Contribute to the development of AI-powered offensive security capabilities ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)