Senior AI Penetration Tester (Chicago)
Fitch GroupAbout the role
As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insights, robust data, and dynamic tools to champion more efficient, transparent financial markets. With over 100 years of experience and colleagues in over 30 countries, Fitch Group’s culture of credibility, independence, and transparency is embedded throughout its structure, which includes Fitch Ratings, one of the world’s top three credit ratings agencies, and Fitch Solutions, a leading provider of insights, data and analytics. With dual headquarters in London and New York, Fitch Group is owned by Hearst.
Fitch's Technology & Data Team is a dynamic department where innovation meets impact. Our team includes the Chief Data Office, Chief Software Office, Chief Technology Office, Emerging Technology, Shared Technology Services, Technology, Risk and the Executive Program Management Office (EPMO). Driven by our investment in cutting-edge technologies like AI and cloud solutions, we’re home to a diverse range of roles and backgrounds united by a shared passion for leveraging modern technology to drive projects that matter to our organization and clients. We are also proud to be recognized by Built In as a Best Place to Work in Technology 3 years in a row. Whether you're an experienced professional or just starting your career, we offer an exciting and supportive environment where you can grow, innovate, and make a difference.
Want to learn more about a career in technology and data at Fitch? Visit:
https://careers.fitch.group/content/Technology-and-Data/?locale=en_US
Fitch Group is currently seeking a Senior AI Penetration Tester based out of our Chicago office.
How You’ll Make an Impact:
We are seeking a Senior AI Penetration Tester to join our Information Security department. The ideal candidate will bring 2–4 years of hands-on penetration testing experience, deep technical expertise, a proactive approach to identifying security gaps, and the ability to leverage AI agents and automation to continuously improve testing capabilities.
- Conduct security assessments of AI systems and implementations — including AI chatbots, MCP (Model Context Protocol) servers, and enterprise deployments of Claude, ChatGPT, and Azure OpenAI Studio — identifying risks such as prompt injection, model abuse, data exfiltration etc. Execute continuous adversarial testing of AI platforms and guardrails to validate controls keep pace with evolving vendor capabilities.
- Plan, scope, and execute penetration testing engagements across network infrastructure (servers, firewalls, endpoints, Active Directory) and perform comprehensive web application security assessments covering OWASP Top 10 vulnerabilities, business logic flaws, authentication weaknesses, and API security issues — following OWASP, and MITRE ATT&CK and other methodologies.
- Leverage AI agents and AI-assisted tooling (such as Claude and ChatGPT) to augment testing workflows and automate reconnaissance, while developing and maintaining custom scripts and exploit code for attack chain automation, payload generation, and post-exploitation tasks.
- Document and communicate assessment outcomes — including findings, risk context, and remediation guidance — clearly for both technical teams and senior stakeholders; collaborate with Vulnerability Management, Application, and Infrastructure teams to ensure findings are handed off with clear remediation ownership.
- Stay current with the latest offensive security research, CVEs, exploitation techniques, and AI security threats; support red team exercises and threat simulation activities; and maintain detailed records of testing activities, methodologies, and evidence per internal documentation standards.
You May be a Good Fit if:
The ideal candidate will have 2–4 years of hands-on penetration testing experience, with demonstrated expertise across emerging AI security, network, and application domains. They should possess strong scripting and exploit development skills, comfort working with AI-powered tools, and the ability to communicate complex technical findings clearly and effectively.
- Hands-on AI red-teaming experience covering prompt injection (direct and indirect), jailbreaking, tool-use abuse, insecure output handling, training/context data exfiltration, and model DoS; familiarity with OWASP Top 10 for LLMs and MITRE ATLAS expected.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s