SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Coupa Software is seeking a Security Engineer to join its Red Team, responsible for challenging and improving the company's security posture through simulated real-world attacks. This is a hands-on role focused on protecting Coupa Cloud for a growing customer base.
Key Responsibilities:
- Conduct penetration testing on internally and externally hosted applications including web apps, mobile apps, AI/LLM systems, and APIs using both traditional and AI-powered tools
- Perform specialized security assessments on Coupa's AI and LLM integrations, targeting prompt injection, jailbreaking, data poisoning, and model evasion
- Develop, deploy, and manage AI agents for continuous and autonomous security testing and vulnerability discovery
- Identify network and system vulnerabilities and recommend countermeasures or mitigating controls
- Execute penetration and remediation testing with advanced techniques in a fast-paced environment
- Maintain, support, and extend application security tooling, standards, and processes including SAST, DAST, WAF, and emerging AI-based security analysis platforms
- Translate complex technical security findings into actionable business risks for non-technical stakeholders and executive leadership
About Coupa:
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform. The company leverages trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers to help businesses predict, prescribe, and automate smarter, more profitable business decisions.
Requirements:
- 2+ years of experience in an equivalent security-related role with hands-on experience in AI-driven security testing
- Strong experience in web/API security with focus on testing and defending against attacks on AI/ML systems
- Hands-on experience handling and managing bug bounty programs
- Proficiency in one or more scripting languages, with strong preference for Python for AI/ML development
- Knowledge of common application security issues (OWASP Top 10, SANS Top 25) and OWASP Top 10 for Large Language Models
- Well-versed with pentest standards/frameworks such as PTES, OSSTMM, NIST, OSINT, and OWASP
- Hands-on experience developing or utilizing autonomous, agentic systems for security penetration testing
- Familiarity with cloud environments such as AWS, Azure, GCP
- Bachelor's or Master's degree in Computer Science or equivalent experience
- Proven track record of building and maintaining cross-functional relationships
- Ability to work in a team environment
- Relevant security certifications a plus but not required (CEH, OSCP, GPEN, LPT, eJPT)