EU remote
AI Red Team Specialist – Lead Researcher in Agentic Security
About this role
We’re looking for an experienced red teamer with proven credentials in agentic red teaming to join our advanced product and research team. What you’ll do You’ll join the team dedicated to building and developing a tool that dynamically tests and evaluates large language models (LLMs) and their native application context for vulnerabilities. You’ll be working with seasoned reverse engineers, application pentesters, red teamers, and data scientists, bridging multiple digital disciplines by creating a unique suite that gives our clients the capability to test, remediate, and harden their agentic workloads.
What you’ll bring Most of all, we value ingenuity, curiosity, and drive. You may be a great fit for this role if you have experience with: Building or contributing to tools used for dynamic application testing Working extensively with open source or proprietary tools used for web and application pentesting Actively adopting LLMs and Model Context Protocol (MCP) in automating and enhancing your penetration tests Spending time researching agentic vulnerabilities and attending relevant trainings or conferences To fit right in here at The Tech Collective: You should be genuinely curious about new developments within the red teaming domain You possess the willingness to tackle new and technical challenges as they arise You know how to break down and structure complex assignments and enjoy sharing your knowledge and insights with your team members You possess a startup mentality to help drive the innovation and ingenuity of our red team products You can cooperate seamlessly with different profiles in a highly diverse team of researchers, developers, consultants, and red teamers We don’t expect you to know everything – after all, agentic security is a rapidly evolving field! In this role, we’re looking for someone who wants to own, develop, and innovate the product modules related to testing the application context (e.g., API security, cryptographic implementation, broken authentication, RBAC) and supporting infrastructure (e.g., misconfigurations, server-side vulnerabilities) for the agents that we test.
To succeed in this role, your experience and competencies should include: Professional experience A minimum of five years’ progressive experience in enterprise red teaming or offensive research A proven track record of web application pentesting with an emphasis on remediation and hardening Experience defining and driving product roadmaps for red team tools (not required, but highly valued) Demonstrated ability to evaluate complex technology stacks, including common cloud platforms (M365/Azure, Google, or AWS), CI/CD pipelines, and AI-powered platforms and systems Experience communicating technical findings to non-technical stakeholders and the ability to bring technical assessments to life Technical competencies Familiarity with both Mitre and OWASP frameworks, and experience applying them in client reporting Relevant security certifications (e.g., OSCP, OSCE, OSEP, GIAC GPEN/GXPN, etc.) are a plus, indicating solid foundational knowledge and commitment to the offensive security field.