{"id":1401376,"url":"https://alion.io/job/plain-concepts-ai-security-lead-offensive","title":"Lead Offensive AI Security","company":{"id":2318,"name":"Plain Concepts","domain":"plainconcepts.com","url":"https://alion.io/company/plain-concepts","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workable","truth_index":{"grade":"A","score":95,"open_postings":10,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":90,"computed_at":"2026-09-30T05:45:00Z"}},"role":"AI/ML","role_family":"AI/ML","seniority":"lead","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["ES"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":72000,"max_usd":172000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":773},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Burp Suite","optional":false},{"name":"CI/CD","optional":false},{"name":"LLM","optional":false},{"name":"Nmap","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Agile","optional":true},{"name":"Azure","optional":true},{"name":"GitHub","optional":true}],"status":"live","first_seen_at":"2026-09-28T15:46:37Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-29T21:07:54Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"At Plain Security Studios, we're redefining how organizations combine Offensive Security, AI, and DevSecOps to build more secure applications.\nWe're looking for a Lead Offensive AI Security to help shape the future of AIpowered penetration testing, application security, and secure software development.\nThis is a unique opportunity to combine technical leadership, hands-on security expertise, and innovation, while leading a growing team of specialists and working with clients on cutting-edge security challenges.\nKey Responsibilities\nLead AI-powered penetration testing initiatives, combining traditional offensive security techniques with AI-assisted capabilities.\nDesign and evolve offensive security services, methodologies, assessment frameworks, and delivery models.\nAssess web applications, APIs, cloud environments, and AI enabled systems to identify vulnerabilities and security risks.\nEvaluate the security of LLM-based applications and AI agents, including prompt injection, data leakage, excessive permissions, and insecure tool execution.\nHelp organizations transform their pentesting programs, increasing assessment capacity and reducing delivery times without compromising quality.\nDrive Secure SDLC and DevSecOps initiatives, integrating security controls into engineering workflows and CI/CD pipelines.\nBuild automation, tooling, and prototypes that improve efficiency and can be reused across multiple engagements.\nAct as a trusted advisor for CISOs, architects, engineering teams, and security leaders.\nMentor and develop a multidisciplinary team of offensive security, application security, and DevSecOps specialists.\nRequirements\n7+ years of experience in Offensive Security, Application Security, Adversarial Testing, or Penetration Testing.\nExperience leading technical teams or complex security engagements.\nStrong hands-on experience with web application and API security assessments.\nSolid understanding of authentication, authorization, business logic vulnerabilities, and exploit validation.\nExperience implementing or improving Secure SDLC practices, including threat modeling, secure code reviews, vulnerability management, and remediation workflows.\nHands-on experience using LLMs, AI agents, or AI-powered security tools to enhance testing and automation activities.\nExperience integrating security into CI/CD pipelines and modern cloud environments.\nKnowledge of application security tooling, including SAST, DAST, Software Composition Analysis, and Secrets Scanning.\nStrong programming or scripting skills, preferably with Python or PowerShell.\nExperience with offensive security tools such as Burp Suite, Nmap, or similar technologies.\nUnderstanding of AI application security risks, including prompt injection, data leakage, retrieval access controls, and unsafe tool execution.\nExcellent communication skills, with the ability to explain technical findings to both technical and non-technical audiences.\nFluent Spanish and English.\nNice to Have:\nOSCP, OSWE, CRTO, or GIAC certifications.\nExperience building security methodologies, frameworks, or internal security services.\nBackground in consulting or client-facing security engagements.\nExperience leading security transformation initiatives.\nKnowledge of Azure and GitHub security ecosystems.\nBenefits\nSalary determined by the market and your experience \n Flexible schedule 35 Hours / Week \n Fully remote work (optional) \n Flexible compensation (restaurant, transport, and childcare) \n Fully free health insurance, with a co-payment for dental services \n Individual budget for training or equipment and free Microsoft certifications \n English lessons \n Birthday day off \n Monthly bonus for electricity and Internet expenses at home \n Discount on gym plan and sports activities \n Plain Camp (annual team-building event) \n Extra perks: events attendance and speakers, welcome pack, baby basket, Christmas basket, discount portal for employees The pleasure of always working with the latest technological tools!\n Will you let us know you better?\nThe selection process: Simple, just 3 steps.\n Phone screen\n 2 interviews with the team \n What is Plain Concepts?\nPlain Concepts is a global company of over 500 people passionate about technology and innovation. Since our founding, we have grown through technical proficiency and confidence in ideas that others might consider risky, creating custom solutions for our clients. With offices in more than 6 countries, our mission is to continue to drive cuttingedge projects around the world.\nWe are highly committed to technical excellence. We are known for developing highly customized projects, offering specialized technical consultancy and training.\nThanks to the great work of our technicians, we have been recognized for our ability to lead innovative projects that generate value, from artificial intelligence to blockchain, driving solutions that help companies optimize their performance.\nWhat we do at Plain Concepts?\nWe pride ourselves on being a 100% technical team, dedicated to crafting custom projects from scratch, offering expert technical consultancy, and providing top-tier training.\n Our approach goes beyond traditional outsourcing; we focus on creating value together with our clients.\n Our teams are diverse and multidisciplinary, operating in a flat, collaborative structure.\n We live and breathe AGILE principles, ensuring flexibility and efficiency in everything we do.\n Knowledge-sharing is at our core: from supporting each other internally to contributing to the broader tech community through conferences, events, and talks.\n Innovation drives us - even the boldest ideas are welcome here.\n Transparency underpins all our relationships, fostering trust and long-term partnerships.\n Want to learn more?\nCheck out our website! https://www.plainconcepts.com/\nAt Plain Concepts, we certainly seek to provide equal opportunities. We want diverse applicants regardless of race, colour, gender, religion, national origin, citizenship, disability, age, sexual orientation, or any other characteristic protected by law.","description_format":"text","description_chars":6074,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"Spanish","level":"Advanced (C1)","optional":false},{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Flexible schedule","Health insurance","Sports activities"],"hiring_locations":[{"name":"Spain","iso":"ES","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Corporate Training","IT Consulting & Digital Transformation","Custom Software Development"],"lifecycle":[{"event":"open","at":"2026-09-28T15:46:37Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":90,"reasons":["conf:8","velocity","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/plain-concepts-ai-security-lead-offensive","json_url":"https://alion.io/job/plain-concepts-ai-security-lead-offensive.json","meta":{"generated_at":"2026-09-30T06:04:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4210,"day_limit":5000,"remaining_today":790,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}