Plain Concepts logo

Lead Offensive AI Security

Plain Concepts • Spain


No Relocation

Posted: September 28, 2026

Job Description

At Plain Security Studios, we're redefining how organizations combine Offensive Security, AI, and DevSecOps to build more secure applications.

We're looking for a Lead Offensive AI Security to help shape the future of AIpowered penetration testing, application security, and secure software development.

This is a unique opportunity to combine technical leadership, hands-on security expertise, and innovation, while leading a growing team of specialists and working with clients on cutting-edge security challenges.

Key Responsibilities

  • Lead AI-powered penetration testing initiatives, combining traditional offensive security techniques with AI-assisted capabilities.
  • Design and evolve offensive security services, methodologies, assessment frameworks, and delivery models.
  • Assess web applications, APIs, cloud environments, and AI enabled systems to identify vulnerabilities and security risks.
  • Evaluate the security of LLM-based applications and AI agents, including prompt injection, data leakage, excessive permissions, and insecure tool execution.
  • Help organizations transform their pentesting programs, increasing assessment capacity and reducing delivery times without compromising quality.
  • Drive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD pipelines.
  • Build automation, tooling, and prototypes that improve efficiency and can be reused across multiple engagements.
  • Act as a trusted advisor for CISOs, architects, engineering teams, and security leaders.
  • Mentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists.
At Plain Security Studios, we're redefining how organizations combine Offensive Security, AI, and DevSecOps to bu...

  • 7+ years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing.
  • Experience leading technical teams or complex security engagements.
  • Strong hands-on experience with web application and API security assessments.
  • Solid understanding of authentication, authorization, business logic vulnerabilities, and exploit validation.
  • Experience implementing or improving Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows.
  • Hands-on experience using LLMs, AI agents, or AI-powered security tools to enhance testing and automation activities.
  • Experience integrating security into CI/CD pipelines and modern cloud environments.
  • Knowledge of application security tooling, including SAST, DAST, Software Composition Analysis, and Secrets Scanning.
  • Strong programming or scripting skills, preferably with Python or PowerShell.
  • Experience with offensive security tools such as Burp Suite, Nmap, or similar technologies.
  • Understanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution.
  • Excellent communication skills, with the ability to explain technical findings to both technical and non-technical audiences.
  • Fluent Spanish and English.

Nice to Have:

  • OSCP, OSWE, CRTO, or GIAC certifications.
  • Experience building security methodologies, frameworks, or internal security services.
  • Background in consulting or client-facing security engagements.
  • Experience leading security transformation initiatives.
  • Knowledge of Azure and GitHub security ecosystems.