Lovable29.05.2026

Penetration Tester

Зарплата не указана
Полная занятостьОфис

Обязанности

  • 01Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines
  • 02Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products
  • 03Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable
  • 04Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution
  • 05Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture
  • 06Help make Lovable the most secure AI product in the market

Требования

  • 0112+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure
  • 02A track record the field knows about: CVEs to your name, hall-of-fame credits in major bug bounty programs, or a reputation that precedes you
  • 03Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement
  • 04Hands-on experience using AI as part of your hacking workflow — not just testing AI systems, but actively leveraging it as an offensive tool
  • 05Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors
  • 06Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce
  • 07Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately
  • 08Low ego, high output. You collaborate as naturally as you compete against systems
  • 09Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling
Penetration Tester · Rekru