# Senior Information Security Specialist (Red Team & SaaS Security)

**Company:** [Gramian Consulting Group](http://jobs.workable.com/companies/kANY7hHLXDH7fUqyifRLmf.md)
**Location:** Remote
**Workplace:** remote
**Employment type:** Contract
**Department:** Talent Solutions

[Apply for this job](http://jobs.workable.com/view/af95acb0-70ba-4da3-aa94-54ce370ce533)

## Description

**About Us**

Gramian Consultancy is a boutique consultancy specializing in IT professional services and engineering talent solutions. With a strong background in software engineering and leadership, we help companies build high-performing teams by matching them with professionals who truly fit their needs.

**Role Overview**

Our client operates in the enterprise software space, supporting organisations that rely on cloud-based collaboration, productivity, development, and data platforms.

We are looking for a **Senior Information Security Specialist** to design and evaluate adversarial security scenarios for modern SaaS and cloud environments. The role combines **red teaming, penetration testing, threat modelling, and security review**, with a particular focus on how AI-enabled systems could be manipulated through identity abuse, prompt injection, data exfiltration, privilege escalation, or destructive actions. Previous experience in AI security is helpful but not required.

**CONTRACT: Freelance contractor, paid per completed task**

**COMMITMENT: Flexible, based on available tasks and project demand**

**LOCATIONS: Fully remote - GLOBAL**

**PROCESS: Application review, gaming setup check, practical assessment, and onboarding**

**HOURLY RATE:** $60 - $100/h

**Responsibilities**

-   Design realistic **red-team scenarios** for enterprise SaaS and cloud platforms.
-   Conduct security assessments across collaboration, identity, source-control, and data platforms.
-   Develop adversarial workflows involving access abuse, data leakage, and privilege escalation.
-   Evaluate risks related to AI agents, prompt injection, and unauthorised system actions.
-   Review red-team exercises and assess their technical depth and realism.
-   Recommend security controls, monitoring approaches, and detection strategies.
-   Create benchmark scenarios based on current attack methods.
-   Document findings, attack paths, risks, and remediation recommendations.
-   Review the work of other security contributors and provide technical feedback.

## Requirements

-   Strong hands-on experience in **red teaming, penetration testing, cloud security, application security, or security engineering**.
-   Deep knowledge of identity, RBAC, permissions, and data governance in SaaS environments.
-   Practical security experience with platforms such as Microsoft 365, Google Workspace, Slack, GitHub, or Snowflake.
-   Experience designing threat models and adversarial attack scenarios.
-   Knowledge of privilege escalation, data exfiltration, access abuse, and destructive-action risks.
-   Experience documenting security findings and remediation guidance.
-   Proven delivery of practical security assessments or offensive security projects.
