Pentester, Offensive Forward Deployment Engineer
Apply at source. Mistral AI handles the application directly; Houtini doesn't take a fee from candidates or companies. We curate which companies appear; the listings come from yubhub.
What the team is looking for.
About Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed to meet enterprise needs, whether on-premises or in cloud environments. Our offerings include le Chat, the AI assistant for life and work. We are a team passionate about AI and its potential to transform society. Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between France, USA, UK, Germany and Singapore. We are creative, low-ego and team-spirited. Join us to be part of a pioneering company shaping the future of AI. Together, we can make a meaningful impact.
Role summary We are seeking hands-on Pentesters to join our Offensive Security team. You will be running our maturing offensive solution on real clients engagements while also hunting for vulnerabilities in Mistral's own systems and in the wild. This is a unique opportunity to break real client systems, discover 0-days for fun, and help build the AI that automates offensive security at scale. Your work will directly impact both our clients' security posture and Mistral's own defensive capabilities. You'll be at the forefront of our offensive security practice, with the chance to shape how AI transforms penetration testing. We welcome offensive security experts at all levels who are passionate about breaking systems and building the tools that make security testing more effective.
What you will do Client Engagements • Run our offensive security solution on real client engagements: scoping, executing tooling, and delivering results • Triaging output and killing false positives to ensure high-quality, actionable findings for clients • Advise clients through deployment and remediation, acting as a trusted security partner • Travel to client premises and switch between engagements in a classic pentest consulting cadence Internal Dogfooding • Pentest Mistral's own systems, finding vulnerabilities before our offensive solution matures • Hunt for vulnerabilities internally and on open-source/in-the-wild targets between client engagements • Transfer knowledge and findings to the forming internal security team • Act as Mistral's own first customer for our cyber harnesses Guiding the Harness • Use real offensive expertise to steer the cyber harness: identify vulnerabilities it should catch • Validate and triage the harness's output, ensuring it meets the high standards of human pentesters • Benchmark human vs. agent performance, helping to close the gap between automated and manual testing • Contribute to the development of AI-powered offensive security capabilities About you • Current P0 specialty: web / AppSec + source-code review; also high-value: internal / Active Directory, cloud (AWS/GCP/Azure), CI/CD & supply chain • Senior enough to run an engagement solo from scoping to delivery • Uses AI in your workflow with a nuanced view of its capabilities and limitations • Comfortable being client-facing, mobile, and switching between different engagements • Proven track record of delivering high-quality penetration testing results • Strong problem-solving abilities and attention to detail in vulnerability identification It would be ideal if you also have: • Build your own offensive tooling (builder mindset that scales your impact) • Published CVEs / GHSAs or a strong bug-bounty track record • Conference talks, CTF achievements, or other public recognition in the security community • Strong code review skills for multiple programming languages • Experience with AI/ML systems and their unique security challenges • Contributions to open-source security tools or research
- web
- AppSec
- source-code review
- internal
- Active Directory
- cloud
- AWS
- GCP
- Azure
- CI/CD
- supply chain
Other roles you might consider.
Filtered through the same AI-companies allowlist.
Regional Vice President (RVP) of Solution Architecture
Cursor
Regional Director, Forward Deployed Engineering
Cursor
Regional Director, Forward Deployed Engineering
Cursor
Engineering Manager, Identity & Access Platform
OpenAI
Technical Deployment Lead - UAE
OpenAI
Software Engineer - Networking Software and Services
xAI
New to AI work? Start with these.
Six pieces of orientation. Most AI-company job specs assume you've done this kind of hands-on work already. If you haven't, an afternoon with one of these is the cheapest way to close the gap.
Claude Desktop, from zero.
The agentic-AI assistant most of the people you'd be working alongside use every day. Install, configure, first useful prompts.
What MCPs areThe best MCPs for Claude Desktop.
MCP servers extend an AI assistant with tools and data. The catalogue most teams use. Useful technical context for any AI-engineering role.
Code with AIClaude Code, the complete beginners' guide.
The CLI for AI-paired development. Required reading if you're applying for any engineering role that mentions agents, or any role full stop.
Run a local modelHow to set up LM Studio.
Running a model on your own machine teaches you more about how AI products work in three hours than a year of using ChatGPT will.
The hardware realityBeginner's guide to AI hardware.
What the infrastructure under the model actually looks like. Useful context for infrastructure, applied-AI and hardware roles.
Browse the stackMCP catalogue.
Eleven MCP servers Houtini maintains or recommends. Each detail page describes a real piece of working AI infrastructure.