We are building a unified, scalable AI security testing and benchmarking platform integrated within the Hyperspace ecosystem. This initiative unifies diverse security services behind a single, intelligent agent that automatically routes requests to the appropriate capability, simplifying workflows for developers and AppSec teams. The project also involves evaluating cost-effective open-weight LLMs, benchmarking various AI security tools, and seamlessly connecting capabilities across the software development lifecycle (SDLC) using the Model Context Protocol (MCP) and agentic approaches.
Responsibilities
- Design and implement a unified AI security testing and benchmarking platform within the Hyperspace ecosystem
- Build an intelligent agent capable of automatically routing requests to the appropriate security service
- Evaluate cost-effective open-weight LLMs for security use cases
- Benchmark various AI security tools to assess performance and effectiveness
- Connect security capabilities across the software development lifecycle using MCP and agentic approaches
- Collaborate with developers and AppSec teams to simplify security workflows
- Conduct dynamic and static testing to identify vulnerabilities
- Apply application security fundamentals to detect and address OWASP Top 10 vulnerabilities across Web Application, MCP, and LLM contexts
Requirements
- 5+ years of experience in security engineering and development
- Understanding of AI security concepts, including MCP, LLM, and RAG
- Knowledge of dynamic and static testing methodologies
- Background in application security fundamentals, including OWASP Top 10 vulnerabilities across Web Application, MCP, and LLM domains
- English proficiency at B2 level or higher
Nice to have
- Familiarity with cross-language code, with the capability to read, understand, and make small patches when needed
- Interest in AI for security and security for AI topics, along with skills in clear technical writing and reporting
- Capability to communicate effectively across engineering, security, and stakeholder teams