Senior Security Engineer – Red Team

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Red Team Engineer securing Coupa’s AI-powered spend management platform. Testing web, mobile, API, and AI/LLM systems while developing autonomous security-testing agents.

Responsibilities:

  • Execute sophisticated penetration tests and red team exercises
  • Develop new attack techniques and testing methodologies
  • Conduct penetration testing on web applications, mobile apps, AI/LLM systems, and APIs
  • Assess Coupa's AI and LLM integrations for prompt injection, jailbreaking, data poisoning, and model evasion
  • Develop, deploy, and manage AI agents for continuous autonomous security testing and vulnerability discovery
  • Identify network and system vulnerabilities and recommend countermeasures or mitigating controls
  • Perform penetration and remediation testing, reporting, and advanced penetration techniques
  • Guide development teams on secure coding best practices, including AI/ML model security
  • Serve as an escalation point during critical security incidents and lead root-cause analysis and threat hunting
  • Maintain, support, and extend application security tooling, standards, and processes including SAST, DAST, WAF, and AI-based security analysis platforms

Requirements:

  • 3–8 years of experience in an equivalent security-related role, including hands-on AI-driven security testing
  • Bachelor's or Master's degree in Computer Science (or equivalent), or equivalent experience
  • Hands-on experience developing or utilizing autonomous, agentic systems for security penetration testing
  • Experience building and maintaining cross-functional relationships
  • Strong experience in web/API security, including attacks against AI/ML systems
  • Familiarity with AWS, Azure, or GCP cloud environments
  • Hands-on experience handling and managing bug bounty programs
  • Proficiency in one or more scripting languages, with a strong preference for Python for AI/ML development
  • Knowledge of OWASP Top 10, SANS Top 25, and OWASP Top 10 for Large Language Models
  • Familiarity with PTES, OSSTMM, NIST, OSINT, and OWASP frameworks
  • Ability to translate technical security findings into actionable business risks for non-technical stakeholders and executives
  • Ability to work in a team environment
  • Relevant security certifications such as CEH, OSCP, GPEN, LPT, or EWPTX are a plus, but not required

Benefits:

  • Two company-wide paid wellness days off each year
  • Paid day off on your birthday or another day within your birthday month
  • 40 hours of paid volunteer time off annually
  • Free, confidential, 24/7/365 Employee Assistance Program counseling and resources
  • Business travel medical, safety, pre-trip planning, and emergency support through Zurich Travel Assist
  • Monetary referral bonuses for successful referrals
  • Location-specific benefits packages including medical/dental insurance, retirement/pension plans, and life or accident protection