Freelance- AI/ML Security Specialist
Summary
Lead adversarial security testing for AI/ML systems, including LLMs and generative AI, identifying vulnerabilities like prompt injection and data leakage, and delivering remediation guidance.
Department: Offensive Security / VAPT
Reports to: Head of Penetration Testing
Role Summary
We're looking for an AI/ML Security Specialist to lead adversarial security testing of AI and machine-learning systems—from LLM applications and generative AI products to traditional ML pipelines. You'll identify how AI systems can be manipulated, leaked, or compromised, and deliver evidence-based findings with practical remediation guidance.
- Conduct AI red-teaming engagements for LLMs, generative AI, and ML-driven systems.
- Test against the OWASP Top 10 for LLM Applications, including prompt injection, data leakage, insecure output handling, excessive agency, and model DoS.
- Assess jailbreaks, guardrail bypasses, safety-filter evasion, and hallucinations.
- Evaluate AI attack surfaces including APIs, RAG, embeddings, data ingestion, model integrations, and cloud hosting.
- Assess privacy risks involving prompts, logs, caches, embeddings, and third-party services.
- Evaluate ML pipeline security, including data poisoning, model theft, adversarial inputs, and supply-chain risks.
- Produce technical reports with PoCs, business impact, severity ratings, and remediation guidance.
- Collaborate with web, API, network, and cloud security teams.
- Continuously improve AI security methodologies and tooling.
Required Qualifications
- Hands-on experience testing or red-teaming LLM and generative AI systems.
- Strong knowledge of the OWASP LLM Top 10 and prompt injection techniques.
- Understanding of ML pipelines, inference, embeddings, fine-tuning, and RAG.
- Strong application & API security fundamentals.
- Excellent technical reporting and communication skills.
- Mandatory certification: OSCP, OSWE, CREST (CRT/CCT), GWAPT, GPEN, or eWPTX.
Highly Desirable
- CRTP, OSTP, OSWE, AWS Security, or Azure Security certifications.
- Experience with Secure SDLC, DevSecOps, cloud-native security, AI red-teaming tools (Garak, PyRIT), NIST AI RMF, ISO/IEC 42001, AWS/Azure/GCP, container security, multimodal AI, and regulated industries.