ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Lead Security Engineer - Penetration Testing & AI Security
HighLevel

Lead Security Engineer - Penetration Testing & AI Security

Remote (India) · Staff/Principal · Remote

Expect moderate competitionVerified listingPosted 26d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

HIGH

HighLevel is actively reviewing profiles and moving candidates through the pipeline right now.

Apply window

First 72 hours

Window passed - posted 26d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

20 listed
CI/CDInput/OutputPenetration TestingYouTube ChannelsAgentic AISecurity TestingMachine LearningAccess Controls+12 more
CI/CDInput/OutputPenetration TestingYouTube ChannelsAgentic AI

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

About us
HighLevel is an AI-powered business operating system that gives agencies, entrepreneurs and SMBs the infrastructure to build, automate and scale. Today, HighLevel supports SMBs across 150+ countries, fueling community-driven growth rooted in real customer outcomes.
To date, businesses operating on HighLevel have generated over $7 billion in ecosystem value, demonstrating the impact of shared infrastructure at scale. By centralizing conversations, automation and intelligence into one system, we help businesses move faster, reduce complexity and execute efficiently.
Behind the platform, HighLevel powers more than 4 billion API hits and 2.5 billion message events daily. With 250 terabytes of distributed data, 250+ microservices and over 1 million domain names supported, our architecture is built for performance, resilience and long-term scalability.

Our people
With over 2,000 team members across 10+ countries, HighLevel operates as a global, remote-first organization built for speed and ownership. We value initiative, clarity and execution, creating space for ambitious people to build systems that support millions of businesses worldwide. Here, innovation thrives, ideas are celebrated and people come first, no matter where they call home.

Our impact
Every month, HighLevel enables more than 1.5 billion messages, 200 million leads and 20 million conversations for the more than 1 million businesses we support. Behind those numbers are real people building independence, expanding opportunity and creating measurable impact. We’re proud to be a part of that.
Learn more about us on our YouTube Channel or Blog Posts



What You’ll Be Doing

Application Security, Secure SDLC & DevSecOps

  • Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products.

  • Conduct architecture reviews, threat modeling, secure design and code reviews, and hands-on security assessments.

  • Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.

  • Define practical security standards, requirements, guardrails, and reusable secure engineering patterns.

  • Improve security testing across CI/CD pipelines using SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.

  • Drive risk-based vulnerability triage and remediation in partnership with engineering teams.

  • Develop security automation and promote secure coding through developer guidance, documentation, and training.

  • AI Security Assessment & Adversarial Testing

    • Lead security reviews of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.

    • Assess AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.

    • Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse.

    • Evaluate applicable risks involving data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.

    • Test security controls such as guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.

    • Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks.

    • Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products.

    • Reporting, Collaboration & Leadership

      • Produce clear security reports containing evidence, risk ratings, business impact, and actionable remediation guidance.

      • Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders.

      • Partner with external consultants, researchers, and bug bounty programs for specialized assessments where required.

      • Mentor engineers and help establish a security-conscious engineering culture.

      • Stay current with developments in Application Security, AI Security, and adversarial testing.



What You’ll Bring
  • 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.

  • Experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.

  • 1-3 years of AI Security experience, with AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.

  • Strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.

  • Strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.

  • Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.

  • Practical knowledge of Docker, Kubernetes, microservices, and cloud security.

  • Demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.

  • Understanding of AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.

  • Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.

  • Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.

  • Strong written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.



Preferred Qualifications
  • Experience building or scaling Application Security practices within a SaaS or product-led technology organization.

  • Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.

  • Experience developing security automation, internal testing tools, or reusable security guardrails.

  • Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.

  • Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.



Equal Employment Opportunity Information
The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government record keeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.
#LI-Remote #LI-SS1

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

Keep browsing

All open roles at HighLevel

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.