Sobre esta vaga de Senior Information Security Specialist (Red Team & SaaS Security) na Gramian Consulting Group
About Us
Gramian Consultancy is a boutique consultancy specializing in IT professional services and engineering talent solutions. With a strong background in software engineering and leadership, we help companies build high-performing teams by matching them with professionals who truly fit their needs.
Role Overview
Our client operates in the enterprise software space, supporting organisations that rely on cloud-based collaboration, productivity, development, and data platforms.
We are looking for a Senior Information Security Specialist to design and evaluate adversarial security scenarios for modern SaaS and cloud environments. The role combines red teaming, penetration testing, threat modelling, and security review, with a particular focus on how AI-enabled systems could be manipulated through identity abuse, prompt injection, data exfiltration, privilege escalation, or destructive actions. Previous experience in AI security is helpful but not required.
CONTRACT: Freelance contractor, paid per completed task
COMMITMENT: Flexible, based on available tasks and project demand
LOCATIONS: Fully remote - GLOBAL
PROCESS: Application review, gaming setup check, practical assessment, and onboarding
HOURLY RATE: $60 - $100/h
Responsibilities
- Design realistic red-team scenarios for enterprise SaaS and cloud platforms.
- Conduct security assessments across collaboration, identity, source-control, and data platforms.
- Develop adversarial workflows involving access abuse, data leakage, and privilege escalation.
- Evaluate risks related to AI agents, prompt injection, and unauthorised system actions.
- Review red-team exercises and assess their technical depth and realism.
- Recommend security controls, monitoring approaches, and detection strategies.
- Create benchmark scenarios based on current attack methods.
- Document findings, attack paths, risks, and remediation recommendations.
- Review the work of other security contributors and provide technical feedback.
Requirements
- Strong hands-on experience in red teaming, penetration testing, cloud security, application security, or security engineering.
- Deep knowledge of identity, RBAC, permissions, and data governance in SaaS environments.
- Practical security experience with platforms such as Microsoft 365, Google Workspace, Slack, GitHub, or Snowflake.
- Experience designing threat models and adversarial attack scenarios.
- Knowledge of privilege escalation, data exfiltration, access abuse, and destructive-action risks.
- Experience documenting security findings and remediation guidance.
- Proven delivery of practical security assessments or offensive security projects.