Open role, AI & Agentic Security
Agentic Security
Specialist
Autonomy is the feature and the attack surface. Securing AI agents so they can act on their own without acting against the client.
Contained, observable, reversible
Wise Pirates seeks restless people, focused on evolving to learn, on producing meaningful impacts, and on working in a highly collaborative way, in a Digital and Tech context. We want to meet people who are digital natives and full of good energy and a good attitude.
This is not application security with a new label. An agent reads untrusted language, holds real privileges and decides its own next step, which breaks most of the assumptions the usual stack was built on. Risk concentrates when one agent can reach private data, untrusted content and a way to send data out at the same time, and a single hidden instruction on a web page turns a helpful assistant into a quiet leak.
Our rule for autonomy is that it must be contained, observable and reversible. If an agent can do damage nobody can see, stop or undo, it is not ready for production. Your job is to make that true in practice: least privilege, hard guardrails, a human on the high-stakes calls, and a kill switch that works.
This is a young discipline, and we would rather hire someone early with the right instincts than wait for a decade of experience that does not exist yet. We build agents ourselves, which is the fastest way to learn how they break. Like everyone here, you will be judged on the marginal value you add to the company and to the projects you touch.
What you will actually do
- Threat AssessmentMap how a client’s agents could fail or be turned, working from the OWASP Top 10 for Agentic Applications rather than from intuition.
- Guardrail DesignDesign the controls that keep an agent inside its remit: scoped permissions, allowed tools, output filtering, approval steps on the consequential actions.
- Identity & PrivilegeTreat every agent as a non-human identity with delegated access, and keep standing privilege as close to zero as the job allows.
- Red TeamingAttack our own and our clients’ agents on purpose: prompt injection, goal hijacking, tool misuse, memory poisoning, and whatever the current month has invented.
- Tool & MCP Supply ChainReview the tools and connectors an agent is given, because an agent is only as trustworthy as the least trustworthy thing it can call.
- MonitoringMake agent behaviour observable: logging, tracing and alerting that a human can actually read, for systems whose output is not deterministic.
- Incident ResponseContain, investigate and explain when something goes wrong, and make sure the rollback path exists before it is needed.
- GovernanceWork to the EU AI Act, DORA and sector rules where they apply, and produce the documentation an audit will ask for.
- Client AdvisoryExplain agentic risk to people who have to sign off on it, without either dismissing it or catastrophising.
Technical & platform skills
- Experience
- 1 to 3 years in security, or in engineering with a real security focus. This discipline is new enough that trajectory matters more than tenure.
- Security fundamentals
- Solid grounding in identity and access, least privilege, secrets, and how systems are actually compromised.
- AI literacy
- Literacy in Tech and AI subjects, and practical understanding of how LLMs and agents work: context, tools, memory, and why the same prompt can return different answers. Sophisticated use of AI platforms, both with efficiency and security.
- Agentic threat awareness
- Familiarity with prompt injection, tool misuse and privilege abuse as concrete attack patterns rather than as headlines.
- Scripting
- Python or similar, enough to test, automate and build a proof of concept for an attack or a control.
- Cloud
- Working knowledge of a major cloud, Google Cloud above all, and of how permissions are granted in it.
- Communication
- Ability to write a finding clearly, with the risk, the evidence and the fix, for a reader who is not in security.
- Languages
- Fluent Portuguese and solid English.
Behavioral skills
- Kindness
- At Wise Pirates we promote and admire kindness, independently of rhythm, intensity and efficiency.
- Curiosity
- You want to understand why something behaves the way it does, and you keep asking after the first answer.
- Ownership
- Accountability for what you deliver and for what you promise a client.
- Collaborative Spirit
- Proactive in working across multi-disciplinary teams, sharing knowledge rather than holding it.
- Analytical Mindset
- Capable of putting data first and obsessed with insight building, always with client satisfaction and business results in mind.
- AI Readiness
- Interest and fluency in using AI as a partner to deliver efficient value, respecting security and privacy regulations.
- Results-Oriented Zeal
- An unwavering commitment to the client’s bottom line, pushing boundaries to chase the best overall performance and business goals.
Not required. Noticed.
- Additional years of experience beyond the range above, for a broader remit and more ownership over how the discipline is run.
- Offensive security background: pentesting, red teaming, CTFs, or a bug bounty record.
- Application security or cloud security experience.
- Hands-on with the OWASP Top 10 for Agentic Applications, or with the OWASP LLM Top 10.
- Experience with MCP servers, agent frameworks or tool-calling architectures.
- Security certifications, or the equivalent shown by what you have actually broken.
- Familiarity with the EU AI Act, DORA, NIS2 or ISO 27001.
- Threat modelling practice, STRIDE or otherwise.
- Detection engineering, SIEM or observability tooling.
- Identity and access management at scale, human or non-human.
- Having built agents yourself, which teaches failure modes faster than reading about them.
- Experience in a regulated sector, or with data residency and sovereignty requirements.
A Digital, Tech and AI Business Partner
Wise Pirates is a leading Digital, Tech, and AI Business Partner, operating from Portugal. With a team of 100+ professionals, we are a Martech-independent agency at the forefront of innovation in Southern Europe. Our ambition is to lead an AI-first marketing ecosystem, blending human creativity with the power of artificial intelligence.
We are dynamic, forward-thinking, and driven by data, automation, and meaningful customer experiences. We believe that our people are our most valuable asset, and we are committed to fostering a culture where they can grow, innovate, and thrive.
Our value proposition is holistic and new generation. We combine services with proprietary products, custom data and proprietary frameworks, so the client gets one capability aimed at their business results, not a stack of separate disciplines. You get to work across all of it.
The part most
job ads skip
- A front-row seat in a growing agency placing AI at the centre of how we work and how we serve our clients, both in service and products. Senior peers in every discipline, our sharpest edge and your fastest growth.
- A culture of autonomy connected to a clear orientation towards action and performance. You own your projects end-to-end and have real space to grow. The rhythm is intense and evolution happens at a fast pace.
- Direct exposure to a wide range of use cases, industries, and clients across 80+ countries, with real impact on what gets shipped.
- Continuous learning alongside a cross-functional team of automation, data, media, and creative specialists.
Why join the navy when you can be a pirate?
Portugal, hybrid, full time. Direct client impact from day one, alongside senior peers in every discipline.
Apply for this role