Company Description: ZySec AI builds the Sovereign Intelligence Stack—end-to-end AI infrastructure that organizations fully own and control. The company focuses on enabling mission-critical organizations to deploy AI strategically while preserving data ownership, regulatory compliance, and robust security.
Its flagship platform, CyberPod, is an autonomous data intelligence solution built on RAG and agentic AI workflows, turning fragmented data into trusted, real-time insights with zero data exposure. Deployed in high-stakes environments, ZySec AI delivers private-by-design, resilient systems that unlock maximum value from existing data assets with minimal setup. The team is driven by the vision of a world where sovereign intelligence is trusted by design and retained within the organizations that create it.
Key Responsibilities
· This is a full-time, in office AI & Application Security Engineer role based in Hyderabad.
· Conduct penetration tests across web applications, APIs, internal/external infrastructure, and cloud and on-premise deployments
· Perform security assessments of AI systems - prompt injection (direct and indirect), jailbreak and guardrail bypass, system prompt extraction, RAG and knowledge-base poisoning, tool/agent abuse, insecure output handling, and sensitive data exposure
· Test the infrastructure underneath AI workloads: inference endpoints, vector databases, model registries, embedding pipelines, containers, and MLOps environments
· Review the AI supply chain - model provenance, third-party weights, dependencies, and deployment artefacts
· Perform secure code review and threat modelling for platform features prior to release
· Build automation and internal tooling to make testing repeatable - custom payload sets, CI-integrated security checks, and harnesses built on frameworks such as Garak, PyRIT, or Promptfoo
· Document findings with working proof-of-concepts, drive remediation with engineering, and validate fixes
· Map findings to OWASP Top 10,
OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF, and support customer-facing security and compliance requirements
Qualifications
· 2-4 years of hands-on experience in penetration testing, application security, or offensive security
· Degree in Computer Science, Engineering, or a related field, or equivalent practical experience
· Demonstrated depth in web application and API security testing, plus working capability in network or cloud infrastructure testing
· Solid grounding in OWASP Top 10, OWASP API Security Top 10, and authentication, authorization, and session management flaws
· Practical exposure to AI/LLM security - prompt injection, jailbreaks, or LLM application testing - through work, research, labs, or CTFs
· Working understanding of LLM application architecture: system prompts, embeddings and vector stores, RAG retrieval, function/tool calling, and agent loops
· Python scripting for automation and tooling; comfortable in Linux and terminal-driven environments
· Practical command of Burp Suite, Nmap, Nuclei, and similar tooling, with the judgement to validate and chain findings manually
· Clear technical writing and the ability to explain risk to engineers and to non-technical stakeholders
Preferred Qualifications
· Certifications such as OSCP, HTB COAE, OSAI, OSWE, CRTP, eWPTX, GWAPT
· Hands-on experience with AI red teaming frameworks (Garak, PyRIT, Promptfoo, Giskard, ART) or adversarial ML concepts
· Docker and Kubernetes security, CI/CD pipeline security
· Cloud security experience across AWS, Azure, or GCP
· Familiarity with MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, or India's DPDP Act and CERT-In directions
· Security research output - CVEs, bug bounty track record, open-source tooling, or conference talks (OWASP, BSides, Nullcon)
Interested in this opportunity?
Please send your updated resume to
[email protected] along with a brief two-line introduction about yourself explaining why you're a great fit for this role.
We look forward to reviewing your application!
📌 AI & Application Security Engineer (Hyderabad)
🏢 ZySec AI
📍 Hyderabad