Principal Security Consultant
- Moves you to
- New Zealand
- Support
- Visa sponsorship
- Posted
- Sep 29, 2026
Fenko is a New Zealand AI-native security company. We deliver penetration testing through Foxhound, our AI-enabled assessment platform, and we assess and secure the AI systems our clients are building. We also score browser and IDE extension risk through RiskyPlugins, maintain the open-source passive DNS project dnsmonster, and build AI agents for clients.
About the role
The Principal Security Researcher helps set the standard for how Fenko tests and what it reports. The role combines research and engineering with client delivery: you will research vulnerabilities and attack techniques, turn them into repeatable testing methods, and build the tooling behind our engagements, while also leading penetration tests and AI security assessments for clients from scoping through to the final report. Lessons from engagements feed back into the tooling, and the tooling is applied on the next engagement.
You will work directly with the founder and have a significant say in the company's technical direction.
Key responsibilities
- Lead penetration tests and security assessments end to end, including scoping, testing, verifying findings, rating risk and reporting
- Assess client AI systems, covering prompt injection, agent and tool permissions, MCP integrations and data exposure
- Research vulnerabilities, attack techniques and countermeasures, and turn the results into repeatable testing and detection methods
- Build and maintain the tooling and automation behind our services and products, including the controls that keep automated testing within scope
- Evaluate AI models and agentic techniques for security work, and help shape how we use them
- Contribute to our browser and IDE extension supply-chain research
- Set the testing standards and procedures that govern our assessment work
- Investigate security incidents affecting our systems or client engagements
- Advise clients on security architecture, hardening and remediation
- Contribute technical control design and evidence to our ISO 27001/42001 and SOC 2 programmes
Requirements
- A bachelor's degree or higher in computer science, information security or a related field, or at least three years' full-time experience in offensive security, vulnerability research or security engineering
- Demonstrated experience finding and verifying vulnerabilities in web applications, APIs, cloud environments or networks
- Strong programming ability in Go, Python, Rust or a similar language
- Experience building security tooling or automation
- Hands-on experience building or testing agentic AI systems
- Clear technical writing for both engineering and executive audiences
- Eligibility for client-required security vetting
Desirable
- Familiarity with agent security frameworks such as the OWASP Agentic Security Initiative, MITRE ATLAS, or the Linux Foundation's agent identity and verification work
- OSCP, OSWE, CRT or an equivalent certification
- Published research, CVEs or open-source security tooling
- Remote-first work anywhere in New Zealand. Fenko has no commercial office, and client site visits are occasional
- Flexible, async-friendly hours with few meetings
- Ten days' paid sick leave from your first day
- KiwiSaver employer contributions on top of salary
- Support for certifications such as OSCP and CRT, including study time and exam fees
- Encouragement to speak at conferences and contribute to open-source security projects
- Visa sponsorship: Fenko is an Immigration New Zealand accredited employer and can support an Accredited Employer Work Visa (AEWV) application for the successful candidate
Employment details
Permanent, full-time. Auckland-based role, working remotely within New Zealand.