Cyber Security Engineer (Offensive Security)
Sabio · Métropole du Cap
Job description
About the role
Sabio Group is looking for a Cyber Security Engineer specialized in offensive security to join its Information Security & Cyber Security team in South Africa. The role focuses on red‑team activities, testing the company’s AI‑powered platforms, cloud services and other solutions by thinking like an adversary. You will work hands‑on to uncover vulnerabilities and collaborate with engineering teams to remediate them.
Key responsibilities
- Plan and execute red team engagements, penetration tests and adversary simulations against platforms, products and the corporate environment.
- Identify, exploit and document vulnerabilities across web applications, APIs, cloud infrastructure, identity systems and AI/LLM‑based services.
- Develop realistic attack scenarios – initial access, privilege escalation, lateral movement, data exfiltration – mapped to frameworks such as MITRE ATT&CK.
- Build and maintain custom tooling, exploits and automation where off‑the‑shelf tools fall short.
- Leverage AI‑powered offensive security tooling, including LLMs and agentic assistants, for reconnaissance, exploit development, code review, payload generation and report writing.
- Work with emerging AI red‑team frameworks and platforms such as PyRIT, Garak, Promptfoo, NVIDIA Aegis, Microsoft Counterfit, and AI testing toolkits from HackerOne or Bugcrowd.
- Create and extend automated AI red‑team harnesses (prompt‑injection suites, jailbreak corpora, tool‑abuse scenarios, multi‑turn attack agents).
- Assess the limits and risks of AI‑assisted offensive work, validate findings, and ensure data confidentiality.
Required profile
- Hands‑on curiosity about how systems break and a passion for exploring emerging AI and agentic vulnerabilities.
- Comfortable writing and reading code to develop and adapt exploits.
- Ability to work independently while partnering closely with engineering teams to remediate issues.
- Pragmatic judgement on the use of AI‑assisted tools, recognizing hallucinations, false confidence, and data‑leakage risks.
- Continuous learning mindset to stay ahead of new models, attack techniques, and defensive controls.
Required skills
- Red teaming and penetration testing
- MITRE ATT&CK framework
- Web application and API security
- Cloud infrastructure and identity system security
- AI/LLM security testing and prompt‑injection mitigation
- AI‑powered offensive tooling (LLMs, agentic assistants)
- Experience with PyRIT, Garak, Promptfoo, NVIDIA Aegis, Microsoft Counterfit
- Familiarity with HackerOne/Bugcrowd AI testing toolkits
- Custom exploit development and automation scripting
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in South Africa.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 3 weeks from now
18 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Sabio
Métropole du Cap
Related job offers
-
Full Stack Engineer (Internal Tools & Payments)
Zepz Métropole du Cap -
Software Engineer
OfferZen Métropole du Cap -
Software Engineer – Java Backend (FinTech)
Acuity Consultants Métropole du Cap -
Senior Manager, Digital Service Coordination and Pilot Partnerships
c40 Belgium, South Africa, United Kingdom -
IT Lead – BOOST Programme
Samaha Consulting Johannesburg