AI-Enhanced Penetration Tester - madrid
hace 6 días
Madrid
Overview In this role you apply AI/ML to offensive security, elevating pen-testing, attack-surface monitoring, and vulnerability assurance. You’ll drive data-driven insights to strengthen AXA’s security posture across cloud, web, and infrastructure. The role sits in Group Security, collaborating with cross-functional teams to embed advanced assurance and proactive defenses. You will innovate with AI tools, simulate complex attacks, and help shape secure development and operations at scale. This is a chance to lead cutting-edge security improvements in a global, tech-led insurer. Compensaciones / Beneficios • equal opportunities and diversity, • international, global team, • focus on technology and innovation, • career development in a tech-led insurer, • collaborative security culture Responsabilidades, • Perform advanced penetration tests across web apps, APIs, networks, cloud (AWS, Azure, GCP) and internal systems, • Integrate AI/ML into pentesting workflows and tooling for reconnaissance, vulnerability discovery, exploit generation, threat modeling, and payload generation, • Conduct continuous attack surface monitoring with AI to identify new assets, services, and entry points, • Lead AI-driven vulnerability landscape assurance, validating scanners and prioritizing remediation with data analytics, • Develop and customize scripts/tools to augment penetration testing platforms and create offensive security capabilities, • Document findings with PoC exploits, risk assessments, and remediation recommendations for Dev/Sec teams, • Stay at the forefront of AI advancements in cybersecurity and explore new AI/ML applications for offensive security, • Mentor juniors and collaborate with security, development, and infrastructure teams Requisitos principales, • 3+ years in penetration testing, ethical hacking or offensive security, • Demonstrated interest or experience applying AI/ML to cybersecurity, • Experience with AI-powered security tools for vulnerability scanning, threat intelligence, ASM, or code analysis, • Programming proficiency in Python; automation and API integration, • Knowledge of AI/ML fundamentals, NLP, anomaly detection, and data science concepts, • Cloud security experience (AWS, Azure, GCP), • Proficiency with Linux, Windows, macOS; strong networking understanding, • Familiarity with ML frameworks (TensorFlow, PyTorch, Scikit-learn) and LLMs for offensive security, • Security certifications such as OSCP, OSWE, OSCE, GXPN, GPEN, CEH are a plus, • Analytical and problem-solving mindset, • Clear written and verbal communication, • Collaborative and cross-functional teamwork, • Burp Suite, • Nmap, • Metasploit