jobs in Gravitas Recruitment Group (Global) Ltd

Full Time AI Security Penetration Tester Jobs, in Gravitas Recruitment Group (Global) Ltd - Maukerja

AI Security Penetration Tester

Gravitas Recruitment Group (Global) Ltd

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

AI Security Penetration Tester / AI Red Team Engineer

The Opportunity

We are looking for a hands-on Penetration Tester to join a specialist cybersecurity team working across traditional offensive security and the rapidly developing area of AI security.

This is not purely a conventional VAPT position.

You will conduct penetration testing across applications, infrastructure and enterprise environments while also helping develop the organisation's capability to test AI systems and use AI within offensive security engagements.

A key part of the role will involve assessing LLMs, Agentic AI, RAG systems and AI-enabled applications, as well as exploring how autonomous and semi-autonomous AI agents can be programmed and safely used to enhance penetration-testing workflows.

What You Will Do

  • Conduct hands-on penetration testing and vulnerability assessments across web applications, APIs, infrastructure, networks and cloud environments.
  • Perform security testing and red-team exercises against LLMs, GenAI applications and Agentic AI systems.
  • Assess AI attack surfaces including prompts, RAG pipelines, memory, tools, APIs, MCP integrations and agent orchestration layers.
  • Test for vulnerabilities such as prompt injection, jailbreaks, sensitive-data leakage, insecure tool use, excessive agency, poisoned inputs/context and AI-driven business-logic abuse.
  • Design controlled adversarial scenarios to determine how AI agents can be manipulated into performing unintended actions.
  • Develop and use AI-enabled penetration-testing techniques and tooling to improve reconnaissance, vulnerability discovery, attack simulation, analysis and testing efficiency.
  • Use scripting and AI/LLM technologies to automate repeatable offensive-security workflows and security evaluations.
  • Explore the controlled use of agentic AI for autonomous or semi-autonomous security testing, with appropriate human oversight and authorisation.
  • Build reusable attack scenarios, testing methodologies and evaluation approaches for emerging AI technologies.
  • Validate findings manually and produce clear, reproducible evidence, risk assessments and remediation recommendations.
  • Work closely with security, engineering and technology teams to strengthen AI security controls and secure development practices.
  • Contribute to AI-security testing standards, methodologies and internal technical capability.

What We Are Looking For

Non-Negotiable

  • Strong hands-on experience in penetration testing, VAPT, offensive security or red teaming.
  • An active CREST practitioner certification, such as CRT/CCT or another relevant CREST-recognised penetration-testing qualification.
  • Eligible for / currently holding the required Singapore CAT 1 security clearance for the engagements supported by this position.
  • Practical exposure to AI/ML or AI Security, beyond simply using consumer GenAI tools.
  • Understanding of security risks associated with LLMs and Agentic AI systems.
  • Ability to script and automate security-testing activities, preferably using Python.
  • Demonstrable ability to responsibly use AI within penetration-testing or offensive-security workflows.
  • Understanding of AI governance, risk management, responsible AI use and human oversight within security testing.

AI Security Capability

Candidates should ideally have practical knowledge across several of the following:

  • LLM and GenAI security testing
  • Agentic AI / autonomous agents
  • Prompt injection and jailbreak testing
  • RAG security
  • MCP and tool/API security
  • Agent memory and context manipulation
  • Tool misuse and excessive agency
  • Data leakage and model-output security
  • Adversarial AI/ML techniques
  • AI red teaming
  • AI-assisted vulnerability discovery
  • Automated attack/evaluation frameworks
  • OWASP guidance for LLM/GenAI applications
  • MITRE ATLAS or equivalent AI threat frameworks

Experience building or programming AI agents for authorised security testing and attack simulation would be particularly valuable.

Qualifications & Assurance

Candidates should be able to demonstrate a combination of:

  • Active professional penetration-testing certification.
  • Degree or recognised qualification in Cybersecurity, Computer Science, Artificial Intelligence, Machine Learning or a related discipline.
  • Relevant AI/ML certifications, formal courses or technical training.
  • Training records or practical evidence demonstrating experience with AI-enabled penetration-testing or AI-security tools.
  • Knowledge of AI governance, risk, accountability and responsible-use requirements.
  • Willingness to operate under formal ethical, confidentiality and responsible-use requirements, including signing applicable responsibility and acceptable-use statements.

Advantageous Experience

  • CREST-aligned AI-enabled penetration-testing environments.
  • Security testing of production LLM, RAG or Agentic AI applications.
  • Development of AI/LLM security-testing tools or frameworks.
  • Python-based offensive tooling.
  • Burp Suite and established web/API penetration-testing tooling.
  • LangChain, LangGraph, LlamaIndex or similar agent frameworks.
  • MCP servers, tool/function calling or agent integration architectures.
  • Cloud security across AWS, Azure or GCP.
  • Red-team or adversary-simulation experience.
  • Government, defence, financial-services or other high-assurance environments.

What Makes This Role Different

This position sits at the intersection of traditional penetration testing, AI security and Agentic AI.

You will not only test conventional technology environments — you will help define how emerging AI systems are attacked, assessed and secured, while developing responsible ways to use AI itself to make penetration testing more scalable, intelligent and effective.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More