Senior Offensive Security Engineer (Autonomous testing)

Quorum Cyber
Edinburgh, UK
4 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
£59,905.0
Working hours
Regular working hours
Languages
English

Tech stack

Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Business Logic Software System Penetration Testing Automation of Tests Code Review Encodings Continuous Integration Intrusion Detection and Prevention Python (Programming Language) Open Web Application Security
+11 more
PCI Data Security Standards Quorum Software Engineering TypeScript Large Language Models Containerization Infrastructure Automation Frameworks Free and Open-Source Software Virtual Agents Software Version Control Api Management

Job description

  • Delivering high-quality network, web, API, cloud and red-team engagements that provide clear, actionable outcomes for clients.
  • Building agentic systems that can safely complete defined stages of offensive testing with increasing levels of autonomy.
  • Proving that the automation works through robust evaluation, testing and measurement of accuracy, coverage, reliability, cost and time saved.
  • Convert successful automation into a repeatable, scalable, multi-tenant managed service with clear service levels and commercial value.
  • Creating a clear understanding of where automation can be trusted, where human expertise is required and where an agent should not be used.
  • Embedding appropriate safeguards, including scope validation, authorisation controls, kill switches, prohibited-action lists and complete audit trails.
  • Raising the technical quality bar across the team and sharing your expertise in both offensive security and production-grade software engineering.
  • Ultimately, you will have helped Quorum Cyber deliver continuous assurance at a scale that traditional penetration testing alone cannot achieve.

Requirements

Strength in all three areas. Depth in offensive security and demonstrable AI agent-building are both non-negotiable.

Offensive security depth

  • Around 7 years hands-on, including at least 4 delivering client-facing engagements.
  • Network testing: external and internal, Active Directory attack paths, privilege escalation, lateral movement, post-exploitation.
  • Web and API testing: the OWASP Top 10 and, more importantly, what it misses, meaning business logic flaws, authentication and session weaknesses, and multi-step chains.
  • Red teaming: objective-based operations covering initial access, command and control, EDR evasion, and purple-team work, against a client actively trying to catch you.
  • Excellent written English, with redacted reports or a willingness to sit a writing exercise. The report is the product., * You have shipped a non-trivial LLM agent: something that plans, calls real tools, handles errors, and finishes a multi-step task unsupervised. A private repository or a work project you can describe in detail counts.
  • You are fluent with tool calling, structured output, the Model Context Protocol, and at least one agent framework or SDK (LangGraph, CrewAI, the OpenAI or Claude Agent SDKs, PydanticAI, or a hand-rolled loop). We are framework-agnostic and interested in your reasoning.
  • You can describe an evaluation harness you built: the dataset, the scoring, how you caught regressions, and how you handled the fact that the same input does not give the same output twice.
  • You are honest about the limits and can say with examples which parts of a test agents do well, badly, or should not attempt at all.

Software engineering and disposition

  • Strong Python, the working language of this role. Go, Rust, or TypeScript is useful.
  • Version control, code review, tests, CI/CD, containerisation, infrastructure as code, one major cloud. This runs unattended against client estates, so build it like production software.
  • Genuine enthusiasm for automating a craft you spent years mastering, and the honesty to say when it is not good enough yet.
  • Comfortable with ambiguity and with distributed, written-first working. Much of this role is deciding what to build next., * Consultancy, MSSP, or managed service experience.
  • Exposure to commercial autonomous or continuous testing platforms (XBOW, Horizon3.ai NodeZero, Pentera) as a user, evaluator, or competitor.
  • Open-source contributions to offensive or agent tooling, published research, conference talks (DEF CON, Black Hat, BSides, AI Village), or a CVE record.
  • Detection engineering experience, or familiarity with CREST, PCI DSS, CBEST/TIBER-EU, or DORA threat-led testing.

Benefits & conditions

You will get an excellent salary, with world class benefits.

As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.

About the company

At Quorum Cyber, we’re on a mission to help good people win. Founded in Edinburgh in 2016, we’re one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents.

We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.

As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.

In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities., In this role you will apply your leadership, innovative thinking, curiosity, and existing deep technical expertise to help Quorum Cyber close the distance between AI speed and efficiency, and human insight. Penetration testing, API and web application testing, and red teaming are delivered the traditional way: a skilled human, a scope document, a fixed number of days, a report at the end. The work is excellent, but it does not scale. Clients want continuous assurance; not la snapshot.

This role exists to change that. You will run real engagements and, from inside that work, build the agentic AI that takes them over stage by stage: reconnaissance, enumeration, attack-path discovery, exploitation of known vulnerability classes, evidence capture, triage, first-draft reporting. Each stage moves from:

  1. “A human does this” to…

  2. “An agent does this and a human signs it off”…

  3. And then to help migrate into a continuously running managed service.

What I Do Is:

Deliver engagements (Phase I, and shrinking over time)

  • Lead network, web application, API, cloud, and full-scope red team engagements.
  • Own them end to end: scoping, rules of engagement, authorisation, execution, evidence, reporting, client debrief.
  • Set the quality bar and be the escalation point on a hard target.

Build the automation (Phase II, growing over time)

  • Build agentic systems that perform discrete stages of a test autonomously, starting narrow and expanding as reliability is proven.
  • Build the evaluation harness before the agent:
  • Engineer for the failure modes that matter here: false positives and negatives, non-determinism, scope escape, destructive actions, runaway cost. Instrument accuracy, coverage, cost, and hours saved.

Turn it into a service (Phase III, growing over time)

  • Work with service management and Product Management to turn working automation into a repeatable, multi-tenant offering with defined SLAs and pricing.
  • Enforce scope and authorisation in code rather than in a document: target validation, blast-radius limits, kill switches, prohibited-action lists, full audit trail.
  • Define where the human stays in the loop, and mentor the team in both directions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:00 min

Misconceptions about TypeScript safety capabilities

Simone Sanfratello · JS Congress

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

1:06 min

Applying traditional quorum systems to LLM reliability

Werner Vogels Werner Vogels +1 · World Congress 2026 Europe

2:55 min

Gaining TypeScript benefits using JSDoc alternatives

Simone Sanfratello · JS Congress

4:12 min

Distilling cross-encoder models into smaller efficient sentence embedding models

Marek Suppa · LIVE

Videos

See all

Related articles

See all