Skip to content

Open nowPosted 49 days ago

Penetration Tester / ML Data Collection

autoroboto-llc4 open roles

Where
United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPenetration Tester / ML Data Collectionautoroboto-llc · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on autoroboto-llc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 49 days ago

The posting

Penetration Tester / ML Data Collection

Location: Mountain View, CA

About AutoRoboto

AutoRoboto is an engineering and management consulting firm that has delivered projects for some of the largest technology companies in the San Francisco Bay Area. Our work spans mechanical, electrical, and software design; data collection and quality assurance; and validation testing for new hardware and software.

We're deliberately small. That means our engineers work directly with client teams, see their work reach production quickly, and move between problem domains as our customers' priorities shift. If you want a narrow lane and a long approval chain, this isn't the place. If you want range and ownership, read on.

The Role

This is a hybrid position that sits at the intersection of offensive security and machine learning data work — two areas where our clients increasingly need the same person in the room.

On the security side, you'll take a proactive, offensive role: performing authorized penetration tests against client systems, using a range of tools and techniques to find the gaps an attacker would exploit. You'll document every action in detail and produce clear reports covering what you attempted, what succeeded, what it means for the client's risk posture, and how to fix it.

On the ML side, you'll help design and run the data collection efforts that support our clients' model development and evaluation — including adversarial and edge-case data, where your security instincts are a direct advantage. You'll also apply the same rigor to data quality that you apply to security findings: reproducible process, documented methodology, defensible results.

You'll typically be embedded with one or two client teams at a time, with engagements that shift as their roadmaps do.

What You'll Do

Offensive security

  • Plan and execute authorized penetration tests across web applications, APIs, internal networks, and hardware-adjacent systems, working within clearly defined scope and rules of engagement
  • Identify, validate, and prioritize vulnerabilities by real-world exploitability and business impact, not just scanner severity
  • Write detailed technical findings and remediation guidance, and present results to both engineering teams and non-technical stakeholders
  • Retest remediated findings and confirm fixes hold
  • Contribute to our internal testing methodology, checklists, and tooling so engagements get faster and more consistent over time

ML data collection and quality assurance

  • Design and run data collection efforts against client specifications, including adversarial, edge-case, and failure-mode data
  • Build and maintain QA processes that catch labeling errors, coverage gaps, and dataset drift before they reach a training run
  • Write and maintain scripts and tooling to automate collection, validation, and reporting
  • Document collection methodology and dataset provenance to a standard that holds up under client audit
  • Partner with client ML teams to translate model evaluation needs into concrete collection plans

Across both

  • Keep meticulous records — in this role, the report is the deliverable
  • Operate strictly within authorized scope and client agreements, and escalate immediately when a finding falls outside it
  • Adapt as client priorities change, which they will

What We're Looking For

  • 3+ years in penetration testing, offensive security, red teaming, or security assessment work
  • Hands-on command of the standard offensive toolkit and, more importantly, the judgment to know which tool the situation actually calls for
  • Working knowledge of common vulnerability classes and how they show up in real systems (web, API, network, authentication and authorization flows)
  • Scripting proficiency in Python or a comparable language, sufficient to automate your own workflow
  • Exceptional written communication — you can turn a messy engagement into a report a client executive will read and act on
  • Familiarity with ML/AI workflows and what makes a dataset good or useless
  • Comfort with ambiguity and client-facing work; you'll be representing AutoRoboto directly
  • Authorization to work in the United States and ability to work on-site or hybrid in Mountain View, CA

Nice to Have

  • Relevant certifications (OSCP, GPEN, CEH, or similar)
  • Experience with adversarial ML, model red-teaming, or AI safety evaluation work
  • Background in hardware or embedded security
  • Prior consulting or agency experience

Why AutoRoboto

  • Direct client exposure and real ownership from day one
  • Variety — our engagements change, and so does the work
  • A small team where your process improvements actually become the process
  • Full-time role with benefits
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against autoroboto-llc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on autoroboto-llc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    autoroboto-llc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.