You will create small, runnable agent and retrieval-augmented generation (RAG) codebases with realistic security weaknesses. You will test static analysis tools and document how well they detect vulnerabilities in tool calling, memory, and Model Context Protocol (MCP) systems.
- Build agent and RAG repositories with code-reachable Sensitive Information Disclosure and Excessive Agency vulnerabilities.
- Create vulnerable, fixed, and hard-negative versions with only small security-relevant differences.
- Trace and annotate assets, data and action paths, controls, root causes, severity, and remaining risk.
- Define authorization contexts and write deterministic tests for vulnerable, fixed, and negative behavior.
- Recommend security controls and take part in calibration and peer review.
What it pays and takes
This is contract, part-time work for someone with deep experience in application security and LLM agent frameworks. The project requires at least 20 hours per week and professional fluency in English.
- Pay: $150 per hour.
- Time: 20+ hours per week.
- Location: Open worldwide.
- Work type: Contractor and part time.
- Experience: 5+ years in application or product security, or security-focused software engineering, including secure code review.
- Security analysis: Experience with source-to-sink analysis, taint analysis, SAST, CodeQL, or Semgrep.
- GenAI systems: Hands-on experience building LLM agents or RAG systems with tools such as LangChain, LlamaIndex, OpenAI or Anthropic SDKs, or MCP.
- Authorization: Strong knowledge of actors, trust boundaries, tenants, OAuth, IAM, identity, permitted data and actions, purposes, recipients, and document-level access control.
- Programming: Production experience with Python and/or TypeScript.
- Helpful background: OWASP LLM security risks, MCP, threat modeling, or security evaluation.
How it works
Apply on OpenTrain with your resume, then complete the application on the hiring site.
About AI training work
AI training work is the human work behind modern artificial intelligence, including testing systems, reviewing model behavior, and preparing examples that help software improve. Experienced engineers are needed for specialized projects such as security evaluation because they can identify realistic risks and judge whether safeguards work.