Ai Security Architect For Offensive Automation
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
About The Project (description, Duration, Stage)Hands-on AI-for-Security engagement with a regulated iGaming / online-gaming group.The client’s security team is genuinely advanced: they already run an AI-driven offensive-security capability - continuous external-perimeter scanning feeding an LLM agent that plans exploitation, sources and validates exploits, and executes them in sandboxed environments - plus a runtime anomaly-detection layer watching for intrusion and privilege-escalation patterns across their products.They built this themselves and have explicitly asked us to challenge and improve it, not just rubber-stamp it.What You’ll Actually Do (example Tasks)Join joint working sessions with the client’s hands-on security engineers; challenge and harden their AI-driven offensive pipeline end-to-end (recon ? verification ? AI-planned exploitation ? sandboxed execution).Design and refine the exploitation agent: how the LLM plans attack paths, selects and validates exploits, and orchestrates parallel sandboxes safely and reproducibly.Optimise cost-per-finding of the existing exploitation pipeline: benchmark local / sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against frontier models for the recon, exploitation and analysis loops; quantify accuracy / latency / cost trade-offs and recommend hardware sizing.Shape the runtime anomaly-detection layer: define which intrusion / privilege-escalation precursor patterns are worth collecting (signal over raw-log volume), and design the missing pieces - automated response (kill a malicious process / disable an account on detection) and triage routing by criticality.Stand up a quick-win PoC to anchor the engagement - e.g. an automated dependency / PR vulnerability-scanning pass, or a head-to-head local-vs-frontier benchmark of the exploitation agent.Turn findings into a defensible technical proposal and roadmap; present methodology and trade-offs to a technical CISO / CTO audience.Keep all sensitive work build-time and in-perimeter - no pushing intellectual property, configs, or recon-enabling data to external model providers; respect regulated-gaming certification constraints (no uncertified AI in runtime-critical paths).Skills (hands-on First)Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.Writes their own code (Python + shell) and can explain methodology to non-security executives.KnowledgeModern offensive-security methodology and the current exploit / zero-day landscape.Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task).Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) - strong plus.Defensive side - SIEM, anomaly detection, incident response - plus.ExperienceKey characteristics (ideally 4/4):Hands-on offensive securityBuilt or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbotCloud hyperscaler experience (AWS preferred)Technology consulting / client-facing delivery - can lead a CISO-level technical conversationRole-specific characteristics:3+ years hands-on offensive security / vulnerability research / red-teamDemonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligenceHas wired LLMs into real security workflows (recon, exploitation, triage)Has run self-hosted / local open models in a real engagement, with a view on cost and hardwareComfortable being the sole domain expert in the room and owning the methodologyTerms & conditionsAllocation: ~**** FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement#J-***-Ljbffr
Requirements
Skills (hands-on First)Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.Writes their own code (Python + shell) and can explain methodology to non-security executives.KnowledgeModern offensive-security methodology and the current exploit / zero-day landscape.Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task). Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) - strong plus.Defensive side - SIEM, anomaly detection, incident response - plus.ExperienceKey characteristics (ideally 4/4):Hands-on offensive securityBuilt or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbotCloud hyperscaler experience (AWS preferred)Technology consulting / client-facing delivery - can lead a CISO-level technical conversationRole-specific characteristics:3+ years hands-on offensive security / vulnerability research / red-teamDemonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligenceHas wired LLMs into real security workflows (recon, exploitation, triage)Has run self-hosted / local open models in a real engagement, with a view on cost and hardwareComfortable being the sole domain expert in the room and owning the methodologyTerms & conditionsAllocation: ~**** FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 138 - Are you secure about this?
Dev Digest 137 - AI'm not sure about this
Dev Digest 120 - Apple and peers
Dev Digest 121 - AI goes offline