● Hands-on experience with OWASP Web and Mobile Top 10 standards,NIST CSF, NIST SP 800,PCI
DSS including mitigation of common threats.
● Strong understanding of the OWASP Top 10 for LLM Applications and OWASP Top 10 for
Generative AI, with hands-on experience identifying and validating AI/LLM-specific security risks.
● Strong knowledge of OWASP Top 10 web and the ability to effectively communicate
methodologies and techniques with development teams
● Execute penetration testing projects using the established methodology, tools and rules of
● Solid understanding of application security topics such as authentication, authorization,
encryption, session management, federation, API security, etc.
● Extensive experience with web and mobile application security tools like code scanners
(Checkmarx, Fortify, Ghidra, Hopper, MobSF) and dynamic analysis tools (Burp Suite, ZAP, etc.).
● Experienced in performing security assessments of AI models, LLM-powered applications,
chatbots, AI agents, and AI-integrated APIs, covering both traditional and AI-specific attack
● Hands-on experience with AI security testing tools, prompt engineering, adversarial testing
techniques, and integrating Model Context Protocol (MCP) servers with security tools to
automate and enhance AI security assessments.
● Skilled in evaluating AI systems for vulnerabilities such as prompt injection, indirect prompt
injection, sensitive information disclosure, insecure tool usage, excessive agency, model
manipulation, and unsafe output handling.
● Proficient in designing and executing end-to-end AI penetration testing methodologies,
leveraging automation and custom tooling to improve assessment efficiency and coverage.
● Write reports including recommendations, root cause analysis, security summary analysis, and
● Review application code for security vulnerabilities and practices dangerous to security and
● Convey complex technical security concepts to technical and non-technical audiences including
● Mentor junior members of the team and act as a subject matter expert for application security
● Manage integration with manual and automated tools for static and dynamic testing.
● Conduct threat modeling and risk analysis to identify exposure and develop mitigation plans.
● Build security into infrastructure and architecture designs and guide the implementation with
● Experience with cloud security, particularly for AWS and/or Azure Experience with integrating
security into a DevOps culture.