
Lead Offensive AI Security
Plain Concepts • Spain
No Relocation
Posted: September 28, 2026
Job Description
At Plain Security Studios, we're redefining how organizations combine Offensive Security, AI, and DevSecOps to build more secure applications.
We're looking for a Lead Offensive AI Security to help shape the future of AIpowered penetration testing, application security, and secure software development.
This is a unique opportunity to combine technical leadership, hands-on security expertise, and innovation, while leading a growing team of specialists and working with clients on cutting-edge security challenges.
Key Responsibilities
- Lead AI-powered penetration testing initiatives, combining traditional offensive security techniques with AI-assisted capabilities.
- Design and evolve offensive security services, methodologies, assessment frameworks, and delivery models.
- Assess web applications, APIs, cloud environments, and AI enabled systems to identify vulnerabilities and security risks.
- Evaluate the security of LLM-based applications and AI agents, including prompt injection, data leakage, excessive permissions, and insecure tool execution.
- Help organizations transform their pentesting programs, increasing assessment capacity and reducing delivery times without compromising quality.
- Drive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD pipelines.
- Build automation, tooling, and prototypes that improve efficiency and can be reused across multiple engagements.
- Act as a trusted advisor for CISOs, architects, engineering teams, and security leaders.
- Mentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists.
- 7+ years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing.
- Experience leading technical teams or complex security engagements.
- Strong hands-on experience with web application and API security assessments.
- Solid understanding of authentication, authorization, business logic vulnerabilities, and exploit validation.
- Experience implementing or improving Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows.
- Hands-on experience using LLMs, AI agents, or AI-powered security tools to enhance testing and automation activities.
- Experience integrating security into CI/CD pipelines and modern cloud environments.
- Knowledge of application security tooling, including SAST, DAST, Software Composition Analysis, and Secrets Scanning.
- Strong programming or scripting skills, preferably with Python or PowerShell.
- Experience with offensive security tools such as Burp Suite, Nmap, or similar technologies.
- Understanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution.
- Excellent communication skills, with the ability to explain technical findings to both technical and non-technical audiences.
- Fluent Spanish and English.
Nice to Have:
- OSCP, OSWE, CRTO, or GIAC certifications.
- Experience building security methodologies, frameworks, or internal security services.
- Background in consulting or client-facing security engagements.
- Experience leading security transformation initiatives.
- Knowledge of Azure and GitHub security ecosystems.