Ai Security Architect For Offensive Automation

Neurons Lab
Valencia, Spain
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Software System Penetration Testing Burp Suite Information Technology Consulting Python (Programming Language) Kali Linux Nmap Pattern Recognition Security Information and Event Management Large Language Models Metasploit
+2 more
GPT Vulnerability Analysis

Job description

About The Project (description, Duration, Stage)Hands-on AI-for-Security engagement with a regulated iGaming / online-gaming group.The client’s security team is genuinely advanced: they already run an AI-driven offensive-security capability - continuous external-perimeter scanning feeding an LLM agent that plans exploitation, sources and validates exploits, and executes them in sandboxed environments - plus a runtime anomaly-detection layer watching for intrusion and privilege-escalation patterns across their products.They built this themselves and have explicitly asked us to challenge and improve it, not just rubber-stamp it.What You’ll Actually Do (example Tasks)Join joint working sessions with the client’s hands-on security engineers; challenge and harden their AI-driven offensive pipeline end-to-end (recon ? verification ? AI-planned exploitation ? sandboxed execution).Design and refine the exploitation agent: how the LLM plans attack paths, selects and validates exploits, and orchestrates parallel sandboxes safely and reproducibly.Optimise cost-per-finding of the existing exploitation pipeline: benchmark local / sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against frontier models for the recon, exploitation and analysis loops; quantify accuracy / latency / cost trade-offs and recommend hardware sizing.Shape the runtime anomaly-detection layer: define which intrusion / privilege-escalation precursor patterns are worth collecting (signal over raw-log volume), and design the missing pieces - automated response (kill a malicious process / disable an account on detection) and triage routing by criticality.Stand up a quick-win PoC to anchor the engagement - e.g. an automated dependency / PR vulnerability-scanning pass, or a head-to-head local-vs-frontier benchmark of the exploitation agent.Turn findings into a defensible technical proposal and roadmap; present methodology and trade-offs to a technical CISO / CTO audience.Keep all sensitive work build-time and in-perimeter - no pushing intellectual property, configs, or recon-enabling data to external model providers; respect regulated-gaming certification constraints (no uncertified AI in runtime-critical paths).Skills (hands-on First)Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.Writes their own code (Python + shell) and can explain methodology to non-security executives.KnowledgeModern offensive-security methodology and the current exploit / zero-day landscape.Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task).Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) - strong plus.Defensive side - SIEM, anomaly detection, incident response - plus.ExperienceKey characteristics (ideally 4/4):Hands-on offensive securityBuilt or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbotCloud hyperscaler experience (AWS preferred)Technology consulting / client-facing delivery - can lead a CISO-level technical conversationRole-specific characteristics:3+ years hands-on offensive security / vulnerability research / red-teamDemonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligenceHas wired LLMs into real security workflows (recon, exploitation, triage)Has run self-hosted / local open models in a real engagement, with a view on cost and hardwareComfortable being the sole domain expert in the room and owning the methodologyTerms & conditionsAllocation: ~**** FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement#J-***-Ljbffr

Requirements

Skills (hands-on First)Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.Writes their own code (Python + shell) and can explain methodology to non-security executives.KnowledgeModern offensive-security methodology and the current exploit / zero-day landscape.Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task). Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) - strong plus.Defensive side - SIEM, anomaly detection, incident response - plus.ExperienceKey characteristics (ideally 4/4):Hands-on offensive securityBuilt or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbotCloud hyperscaler experience (AWS preferred)Technology consulting / client-facing delivery - can lead a CISO-level technical conversationRole-specific characteristics:3+ years hands-on offensive security / vulnerability research / red-teamDemonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligenceHas wired LLMs into real security workflows (recon, exploitation, triage)Has run self-hosted / local open models in a real engagement, with a view on cost and hardwareComfortable being the sole domain expert in the room and owning the methodologyTerms & conditionsAllocation: ~**** FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:09 min

Using generative AI to develop an automated security exploit

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · World Congress 2024

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

Videos

See all

Related articles

See all