Mid-level offensive security engineer running client pentests and refining AI-driven security tools at Mistral AI.
Mid-level pentesters who can independently scope and deliver full client engagements. Candidates need strong web or AppSec experience plus source-code review skills and comfort using AI daily. They must be client-facing and ready to switch between external tests and internal vulnerability hunting.
As published by Mistral AI on their official careers page.
We are seeking hands-on Pentesters to join our Offensive Security team. You will be running our maturing offensive solution on real clients engagements while also hunting for vulnerabilities in Mistral's own systems and in the wild. This is a unique opportunity to break real client systems, discover 0-days for fun, and help build the AI that automates offensive security at scale.
Your work will directly impact both our clients' security posture and Mistral's own defensive capabilities. You'll be at the forefront of our offensive security practice, with the chance to shape how AI transforms penetration testing. We welcome offensive security experts at all levels who are passionate about breaking systems and building the tools that make security testing more effective.
Client Engagements
• Run our offensive security solution on real client engagements: scoping, executing tooling, and delivering results
• Triaging output and killing false positives to ensure high-quality, actionable findings for clients
• Advise clients through deployment and remediation, acting as a trusted security partner
• Travel to client premises and switch between engagements in a classic pentest consulting cadence
Internal Dogfooding
• Pentest Mistral's own systems, finding vulnerabilities before our offensive solution matures
• Hunt for vulnerabilities internally and on open-source/in-the-wild targets between client engagements
• Transfer knowledge and findings to the forming internal security team
• Act as Mistral's own first customer for our cyber harnesses
Guiding the Harness
• Use real offensive expertise to steer the cyber harness: identify vulnerabilities it should catch
• Validate and triage the harness's output, ensuring it meets the high standards of human pentesters
• Benchmark human vs. agent performance, helping to close the gap between automated and manual testing
• Contribute to the development of AI-powered offensive security capabilities
• Current P0 specialty: web / AppSec + source-code review; also high-value: internal / Active Directory, cloud (AWS/GCP/Azure), CI/CD & supply chain
• Senior enough to run an engagement solo from scoping to delivery
• Uses AI in your workflow with a nuanced view of its capabilities and limitations
• Comfortable being client-facing, mobile, and switching between different engagements
• Proven track record of delivering high-quality penetration testing results
• Strong problem-solving abilities and attention to detail in vulnerability identification
It would be ideal if you also have:
• Build your own offensive tooling (builder mindset that scales your impact)
• Published CVEs / GHSAs or a strong bug-bounty track record
• Conference talks, CTF achievements, or other public recognition in the security community
• Strong code review skills for multiple programming languages
• Experience with AI/ML systems and their unique security challenges
• Contributions to open-source security tools or research
Location & Remote
This role is open to remote in Europe. Ideally you would be based in one of our European offices (Paris, France and London, UK). We strongly believe in the value of in-person collaboration and we encourage going to the office as much as we can (at least 3 days per months) to create bonds and smooth communication. Our remote policy aims to provide flexibility, improve work-life balance and increase productivity.
What we offer
💰 Competitive salary and equity (stock-options)
🧑⚕️ Health insurance
🚴 Transportation allowance
🥎 Sport allowance
🥕 Meal vouchers
💰 Private pension plan
🍼 Generous parental leave policy
🌎 Visa sponsorship
By applying, you agree to our Applicant Privacy Policy.
OpenAI
Software Engineer, Infrastructure Reliability at OpenAI — London, UK. Mid-level engineering role on the Applied AI Infrastructure team.
OpenAI
Solutions Engineering, Ads Solutions at OpenAI — San Francisco. Mid-level engineering role on the Go To Market team.
OpenAI
Software Engineer, Internal Applications - Enterprise at OpenAI — Remote · San Francisco. Intern-level engineering role on the Security team.
OpenAI
AI Deployment Engineer, Startups at OpenAI — San Francisco. Mid-level engineering role on the Technical Success team.
OpenAI
Value Engineer, AI Success - San Francisco at OpenAI — San Francisco. Mid-level engineering role on the AI Success team.
OpenAI
Engineering Manager, Premium at OpenAI — San Francisco. Lead-level engineering role on the Applied AI Engineering team.