> Markdown version of [/jobs/ext/2838644-senior-offensive-security-engineer-autonomous-testing](https://www.wearedevelopers.com/jobs/ext/2838644-senior-offensive-security-engineer-autonomous-testing). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Offensive Security Engineer (Autonomous testing) - **Company:** Quorum Cyber - **Location:** Edinburgh, UK - **Experience:** Expert - **Salary:** £59,905.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Business Logic, Software System Penetration Testing, Automation of Tests, Code Review, Encodings, Continuous Integration, Intrusion Detection and Prevention, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Quorum, Software Engineering, TypeScript, Large Language Models, Containerization, Infrastructure Automation Frameworks, Free and Open-Source Software, Virtual Agents, Software Version Control, Api Management - **Published:** September 11, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5877477787 ## About the Role Strength in all three areas. Depth in offensive security and demonstrable AI agent-building are both non-negotiable. Offensive security depth * Around 7 years hands-on, including at least 4 delivering client-facing engagements. * Network testing: external and internal, Active Directory attack paths, privilege escalation, lateral movement, post-exploitation. * Web and API testing: the OWASP Top 10 and, more importantly, what it misses, meaning business logic flaws, authentication and session weaknesses, and multi-step chains. * Red teaming: objective-based operations covering initial access, command and control, EDR evasion, and purple-team work, against a client actively trying to catch you. * Excellent written English, with redacted reports or a willingness to sit a writing exercise. The report is the product., * You have shipped a non-trivial LLM agent: something that plans, calls real tools, handles errors, and finishes a multi-step task unsupervised. A private repository or a work project you can describe in detail counts. * You are fluent with tool calling, structured output, the Model Context Protocol, and at least one agent framework or SDK (LangGraph, CrewAI, the OpenAI or Claude Agent SDKs, PydanticAI, or a hand-rolled loop). We are framework-agnostic and interested in your reasoning. * You can describe an evaluation harness you built: the dataset, the scoring, how you caught regressions, and how you handled the fact that the same input does not give the same output twice. * You are honest about the limits and can say with examples which parts of a test agents do well, badly, or should not attempt at all. Software engineering and disposition * Strong Python, the working language of this role. Go, Rust, or TypeScript is useful. * Version control, code review, tests, CI/CD, containerisation, infrastructure as code, one major cloud. This runs unattended against client estates, so build it like production software. * Genuine enthusiasm for automating a craft you spent years mastering, and the honesty to say when it is not good enough yet. * Comfortable with ambiguity and with distributed, written-first working. Much of this role is deciding what to build next., * Consultancy, MSSP, or managed service experience. * Exposure to commercial autonomous or continuous testing platforms (XBOW, Horizon3.ai NodeZero, Pentera) as a user, evaluator, or competitor. * Open-source contributions to offensive or agent tooling, published research, conference talks (DEF CON, Black Hat, BSides, AI Village), or a CVE record. * Detection engineering experience, or familiarity with CREST, PCI DSS, CBEST/TIBER-EU, or DORA threat-led testing. ## Description * Delivering high-quality network, web, API, cloud and red-team engagements that provide clear, actionable outcomes for clients. * Building agentic systems that can safely complete defined stages of offensive testing with increasing levels of autonomy. * Proving that the automation works through robust evaluation, testing and measurement of accuracy, coverage, reliability, cost and time saved. * Convert successful automation into a repeatable, scalable, multi-tenant managed service with clear service levels and commercial value. * Creating a clear understanding of where automation can be trusted, where human expertise is required and where an agent should not be used. * Embedding appropriate safeguards, including scope validation, authorisation controls, kill switches, prohibited-action lists and complete audit trails. * Raising the technical quality bar across the team and sharing your expertise in both offensive security and production-grade software engineering. * Ultimately, you will have helped Quorum Cyber deliver continuous assurance at a scale that traditional penetration testing alone cannot achieve. ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Fireside Chat - In conversation with Werner Vogels, CTO of Amazon.com](https://www.wearedevelopers.com/videos/100265-fireside-chat-in-conversation-with-werner-vogels-cto-of-amazon-com) - [Spot, Squash, Secure: Fighting Security Bugs with GitHub Copilot](https://www.wearedevelopers.com/videos/100052-spot-squash-secure-fighting-security-bugs-with-github-copilot) - [TypeScript Features That Changed the Game](https://www.wearedevelopers.com/videos/100061-typescript-features-that-changed-the-game) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)