PitchMeAI
Alignerr

AI Security Penetration Tester

Alignerr · United States

  • Hybrid
  • Contract
  • $60,000 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Test AI systems for security vulnerabilities.
  • Exploit weaknesses in AI/ML pipelines.
  • Conduct web, network, and API assessments.
  • Document findings in actionable reports.
  • Work remotely on flexible contract basis.

About the role

About The Role

What if your hacking skills could directly shape how safe and secure AI systems are for millions of users worldwide? We're looking for AI Security Penetration Testers to probe, attack, and stress-test AI-powered applications and infrastructure — identifying vulnerabilities before bad actors do.

This is a fully remote, flexible contract role where your offensive security expertise meets the cutting edge of artificial intelligence. You'll work on high-impact projects that directly improve the security posture of AI systems used at scale.

Organization: Alignerr
Type: Hourly Contract
Location: Remote
Commitment: 10–40 hours/week

What You'll Do

  • Conduct penetration tests against AI-powered applications, APIs, and infrastructure to uncover security vulnerabilities
  • Identify and exploit weaknesses in AI/ML pipelines, including prompt injection, model manipulation, data poisoning vectors, and authentication flaws
  • Perform web application, network, and API security assessments using industry-standard tools and methodologies
  • Simulate real-world attack scenarios — from reconnaissance through exploitation and post-exploitation
  • Document findings in clear, structured reports with severity ratings, evidence, and actionable remediation guidance
  • Evaluate AI-specific attack surfaces including adversarial inputs, jailbreaks, and data exfiltration risks
  • Stay current with emerging AI security threats and contribute insights to improve testing methodologies
  • Work independently on task-based engagements on your own schedule

Who You Are

  • Experienced penetration tester with a strong understanding of offensive security principles and methodologies (OWASP, PTES, MITRE ATT&CK)
  • Proficient with industry-standard tools such as Burp Suite, Metasploit, Nmap, Kali Linux, or equivalent
  • Solid understanding of web application security, network security, and API security testing
  • Able to think like an attacker — creative, persistent, and methodical in finding what others miss
  • Strong written communication skills — you can translate complex technical findings into clear, actionable reports
  • Self-motivated and reliable when working independently without direct supervision
  • Comfortable working across diverse technology stacks and environments

Nice to Have

  • Relevant certifications such as OSCP, OSCE, CEH, GPEN, GXPN, or eWPT
  • Experience with AI/ML security testing — adversarial machine learning, prompt injection, LLM red-teaming
  • Background in red teaming, bug bounty programs, or CTF competitions
  • Familiarity with cloud security (AWS, GCP, Azure) and container security
  • Programming or scripting skills in Python, Bash, PowerShell, or similar
  • Knowledge of secure development practices and DevSecOps workflows
  • Experience conducting security assessments in compliance-driven environments (SOC 2, ISO 27001, etc.)

Why Join Us

  • Work on cutting-edge AI security projects alongside leading research labs
  • Fully remote and flexible — work when and where it suits you
  • Freelance autonomy with access to high-impact, intellectually challenging engagements
  • Be at the forefront of AI security — a rapidly growing field with massive demand
  • Sharpen your skills against novel AI-specific attack surfaces that few security professionals have encountered
  • Contribute directly to making AI systems safer and more trustworthy for users worldwide
  • Potential for ongoing work and contract extension as new projects launch

Key skills/competency

  • AI Security Penetration Tester
  • Penetration Testing
  • AI Security
  • Vulnerability Assessment
  • Web Application Security
  • API Security
  • Offensive Security
  • Prompt Injection
  • Adversarial Machine Learning
  • LLM Red-Teaming

Skills & topics

  • AI Security Penetration Tester
  • Penetration Testing
  • AI Security
  • Vulnerability Assessment
  • Web Application Security
  • API Security
  • Offensive Security
  • Prompt Injection
  • Adversarial Machine Learning
  • LLM Red-Teaming
  • Cybersecurity
  • Remote Work
  • Contract Role
  • Hourly
  • Ethical Hacking

How to get hired

  • Tailor your resume: Highlight AI security, penetration testing, and relevant certifications like OSCP or CEH. Quantify achievements using data from bug bounty programs or CTFs.
  • Showcase offensive security skills: Detail experience with tools like Burp Suite, Metasploit, Nmap, and Kali Linux. Mention specific AI attack vectors you've tested (e.g., prompt injection, data poisoning).
  • Emphasize communication: Demonstrate ability to write clear, actionable reports detailing vulnerabilities and remediation steps for AI systems.
  • Highlight remote work capability: Showcase self-motivation, reliability, and independent work ethic for task-based engagements.
  • Prepare for technical interviews: Be ready to discuss AI-specific attack surfaces, adversarial ML concepts, and common web/API vulnerabilities.

Technical preparation

Master OWASP, PTES, and MITRE ATT&CK frameworks.,Practice with Burp Suite, Metasploit, Nmap.,Study AI attack vectors: prompt injection, poisoning.,Develop scripting in Python, Bash, or PowerShell.

Behavioral questions

Describe a complex vulnerability you discovered.,How do you approach independent, task-based work?,Explain a technical finding to a non-technical person.,How do you stay updated on AI security threats?

Frequently asked questions

What specific AI security vulnerabilities will I be testing for as an AI Security Penetration Tester at Alignerr?
As an AI Security Penetration Tester at Alignerr, you will focus on identifying and exploiting AI-specific vulnerabilities such as prompt injection, model manipulation, data poisoning, adversarial inputs, and jailbreaks. You'll also conduct traditional web application, network, and API security assessments related to AI systems.
Is the AI Security Penetration Tester role at Alignerr remote, and what are the expected working hours?
Yes, the AI Security Penetration Tester role at Alignerr is fully remote. The commitment is flexible, ranging from 10 to 40 hours per week, allowing you to work on task-based engagements on your own schedule.
What tools and methodologies are essential for an AI Security Penetration Tester applying to Alignerr?
Proficiency with industry-standard penetration testing tools such as Burp Suite, Metasploit, Nmap, and Kali Linux is essential. Familiarity with offensive security methodologies like OWASP, PTES, and MITRE ATT&CK is also crucial, alongside an understanding of AI/ML security testing techniques.
Does Alignerr require specific certifications for the AI Security Penetration Tester position?
While not strictly required, Alignerr values relevant certifications such as OSCP, OSCE, CEH, GPEN, GXPN, or eWPT. Experience with AI/ML security testing, red teaming, or bug bounty programs is also highly beneficial.
How does Alignerr ensure AI systems are secure for millions of users through this role?
Alignerr utilizes AI Security Penetration Testers to proactively identify and exploit vulnerabilities in AI-powered applications and infrastructure. By uncovering weaknesses before malicious actors can, your work directly improves the security posture and trustworthiness of AI systems used at scale.
What programming or scripting skills are beneficial for an AI Security Penetration Tester at Alignerr?
Programming or scripting skills in languages like Python, Bash, or PowerShell are considered a plus for an AI Security Penetration Tester at Alignerr. These skills can be valuable for automating tasks, developing custom tools, and analyzing security data.