Senior Security Engineer – Red Team
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Red Team Engineer securing Coupa’s AI-powered spend management platform. Testing web, mobile, API, and AI/LLM systems while developing autonomous security-testing agents.
Responsibilities:
- Execute sophisticated penetration tests and red team exercises
- Develop new attack techniques and testing methodologies
- Conduct penetration testing on web applications, mobile apps, AI/LLM systems, and APIs
- Assess Coupa's AI and LLM integrations for prompt injection, jailbreaking, data poisoning, and model evasion
- Develop, deploy, and manage AI agents for continuous autonomous security testing and vulnerability discovery
- Identify network and system vulnerabilities and recommend countermeasures or mitigating controls
- Perform penetration and remediation testing, reporting, and advanced penetration techniques
- Guide development teams on secure coding best practices, including AI/ML model security
- Serve as an escalation point during critical security incidents and lead root-cause analysis and threat hunting
- Maintain, support, and extend application security tooling, standards, and processes including SAST, DAST, WAF, and AI-based security analysis platforms
Requirements:
- 3–8 years of experience in an equivalent security-related role, including hands-on AI-driven security testing
- Bachelor's or Master's degree in Computer Science (or equivalent), or equivalent experience
- Hands-on experience developing or utilizing autonomous, agentic systems for security penetration testing
- Experience building and maintaining cross-functional relationships
- Strong experience in web/API security, including attacks against AI/ML systems
- Familiarity with AWS, Azure, or GCP cloud environments
- Hands-on experience handling and managing bug bounty programs
- Proficiency in one or more scripting languages, with a strong preference for Python for AI/ML development
- Knowledge of OWASP Top 10, SANS Top 25, and OWASP Top 10 for Large Language Models
- Familiarity with PTES, OSSTMM, NIST, OSINT, and OWASP frameworks
- Ability to translate technical security findings into actionable business risks for non-technical stakeholders and executives
- Ability to work in a team environment
- Relevant security certifications such as CEH, OSCP, GPEN, LPT, or EWPTX are a plus, but not required
Benefits:
- Two company-wide paid wellness days off each year
- Paid day off on your birthday or another day within your birthday month
- 40 hours of paid volunteer time off annually
- Free, confidential, 24/7/365 Employee Assistance Program counseling and resources
- Business travel medical, safety, pre-trip planning, and emergency support through Zurich Travel Assist
- Monetary referral bonuses for successful referrals
- Location-specific benefits packages including medical/dental insurance, retirement/pension plans, and life or accident protection

















