- Expérience
- N'importe lequel
- Salaire
- USD 60 – USD 100 / hour
- Ouvertures
- 1
- Publié
- il y a 1 heure
- Mode de travail
- Travaillez à domicile
- CV
- Candidature requise
Description de l'emploi
Position Overview
This contract role focuses on information security within SaaS and cloud-based ecosystems, offering remote work with a flexible commitment of 10 to 40 hours per week. Compensation ranges from $60 to $100 per hour.
Key Responsibilities
- Develop and establish detailed red-teaming workflows and adversarial scenarios specific to SaaS and cloud infrastructures.
- Perform hands-on penetration tests and adversarial threat modeling on platforms including Microsoft 365, Google Workspace, Slack, GitHub, and Snowflake.
- Provide senior-level review of red-teaming activities, ensuring the thoroughness and quality of assessments.
- Identify and document possible exploitation methods of AI agents, such as prompt injection, privilege escalation, data theft, and destructive interventions.
- Offer actionable guidance for the creation and assessment of security controls, policies, and detection mechanisms relevant to live SaaS settings.
- Collaborate alongside cybersecurity peers to deliver comprehensive written and verbal feedback regarding findings and enhancement strategies.
- Contribute to benchmarking efforts by designing adversarial use cases reflecting current threat landscapes and methodologies.
Qualifications and Experience
- Substantial practical experience in areas like red teaming, penetration testing, cloud and application security, or security engineering.
- In-depth knowledge of enterprise SaaS security fundamentals, focusing on identity management, role-based access control, permissions, and data governance.
- Hands-on exposure to Microsoft 365, Google Workspace, Slack, GitHub, and Snowflake, particularly from a security assessment perspective.
- Proven ability to analyze how AI and SaaS platforms might be potentially compromised by adversaries.
- Strong communication skills, both verbal and written, capable of clearly explaining intricate security challenges and providing remediation advice.
- A record demonstrating impactful security initiatives rather than just surface-level experience.
Additional Information
- Application process includes submission of resume, evaluation, and an interview stage.