Any
Up to PHP 30,000/month
40
Sep 25, 2026
Find the holes in our systems before anyone else does, and use AI to do it faster and at scale.
ABOUT US
We are a content creation and online coaching business running a lot of automation, AI agents, APIs, websites and cloud servers. We need a security expert who can test and harden all of it, and who knows how to leverage AI (LLMs, agents, automation) to make security work faster.
We are hiring for multiple positions. Full-time and part-time both welcome.
WHAT YOU'LL DO
- Run authorized penetration tests on our own web apps, APIs, servers and cloud setup
- Find, document and help fix vulnerabilities (OWASP Top 10, auth, misconfigurations, exposed secrets)
- Harden our Linux servers, VPS / cloud accounts, and access controls
- Review the security of our AI agents and automations: prompt injection, tool misuse, data leakage, API key handling
- Use AI and scripting to automate recon, scanning, log review and reporting
- Set up monitoring and alerting so we know when something is wrong
- Write clear reports with priorities and fixes the team can act on
MUST HAVE
- Hands-on pentesting experience (web / API / network)
- Comfortable with tools like Burp Suite, Nmap, Metasploit, OWASP ZAP or similar
- Strong Linux and networking fundamentals
- Python or Bash scripting
- Practical experience using AI / LLMs in your security workflow
- Ethical, discreet and trustworthy; you only test what you are authorized to test
NICE TO HAVE
- Certifications such as OSCP, PNPT, eJPT, CEH, Security+ or similar
- Bug bounty track record (HackerOne, Bugcrowd, etc.)
- Cloud security (AWS / GCP), secrets management
- Knowledge of LLM / AI security (prompt injection, OWASP Top 10 for LLM apps)
PAY: Up to PHP 30,000/month (full-time), based on skill and certifications. Part-time pro-rated.
HOW WE HIRE
Screen on the "To apply" ask below, then a call, then a short PAID scoped test, then a small contract, then ongoing.
TO APPLY
1. Describe one real vulnerability you found (anonymized is fine): how you found it, impact, and how it was fixed.
2. Tell us how you use AI in your security work.
3. List your certifications or bug bounty profile, if any.
Applications with only a CV are skipped.