Senior Security Engineer (Wordpress & Php) (Remote-Only, Europe)

CloudLinux
Palo Alto, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English

Job location

Remote
Municipality of Madrid, Spain

Tech stack

PHP
Software System Penetration Testing
Linux
Fuzz Testing
Python
WordPress
Delivery Pipeline
Large Language Models
Metasploit
Build Tools
REST
Vulnerability Analysis

Job description

CloudLinux is a global remote?first company driven by our principles: do the right thing, employees first, we are remote first, and we deliver high?volume, low?cost Linux infrastructure and security products that help companies to increase the efficiency of their operations.Every person on our team supports each other and does what we can to ensure we all are successful.Imunify360 Security SuiteImunify360 is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers.Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers.The automated, easy?to?use solution with a six?layer approach to security delivers comprehensive and complete attack prevention.Check out our website for more information about our Imunify360 Product: /We are building an engineering?heavy security platform for protecting WordPress and its plugin ecosystem.The core challenge is turning real attacker behavior into automated, repeatable systems that scale.We are looking for aSenior Security Engineerwho understands exploitation deeply but prefers building tooling and automation over one?off research.You will work on systems that:Automatically generate and validate exploit PoCs for known WordPress / PHP CVEsAnalyze PHP execution traces from real zero?day attacks against WordPress installationsLLMs are a first?class component of this work-not a novelty-used to accelerate exploit reconstruction, PoC generation, and attack workflow automation.This is anengineering role with offensive depth , not a traditional pentesting or red?team position.What You'll BuildSystems to ingest, normalize, and analyze PHP execution traces:Function calls, parameters, control flow, side effectsNo native binary reversing-focus is PHP?level execution and logicTooling that infers:Vulnerable code pathsAuthorization and logic flawsNonce and state?handling weaknessesAutomated pipelines that:Convert CVE descriptions + PHP source code into working PoCsReplay inferred exploit paths deterministicallyLLM?assisted frameworks for:Exploit skeleton generationParameter and payload inferenceExploit mutation and robustness testingHigh?fidelity exploit simulations targeting:admin?ajax.phpWordPress REST APIsPlugin?specific endpointsInfrastructure that transforms exploit mechanics into signals usable by detection and prevention systemsRequirementsMust HaveStrong background in security engineering or offensive security automationHands?on experience exploiting WordPress plugins, themes, or PHP applicationsDeep understanding of:PHP execution model and request lifecycleWordPress internals (nonces, hooks, REST, admin flows)HTTP semantics, sessions, cookies, and authorizationProven ability to read, reason about, and exploit PHP source codeStrong Python engineering skills for building:Automation pipelinesAnalysis toolingExploit frameworksNice to HaveExploit framework usage experience like MSF, Core Impact, Immunity CanvasPrior experience using LLMs to automate exploit development:PoC generationWorkflow automationPayload mutation or inferenceExperience with:Execution traces or application?level call graphsFuzzing or vulnerability discovery pipelinesFamiliarity with tools like WPScan, Nuclei, Metasploit, BurpContributions to exploit tooling, frameworks, or security automationPublic CVEs or PoCs (helpful but not required)What This Role Is Not? Manual pentesting or report?driven consulting? SOC or alert?triage work? Pure vulnerability research without automationWhy This Role Is InterestingYou'll work with real zero?day attack telemetry, not just public CVEsYou'll build repeatable systems, not one?off demosLLMs are used pragmatically, as part of production pipelinesYour work directly shapes how real WordPress attacks are detected and stoppedHigh autonomy, deep technical ownershipBenefitsWhat's in it for you?A focus on professional developmentInteresting and challenging projectsFully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwidePaid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leavesCompensation for private medical insuranceCo?working and gym/sports reimbursementBudget for educationThe opportunity to receive a reward for the most innovative idea that the company can patentBy applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (), which provides detailed information on how we maintain and handle your data.#J-*****-Ljbffr

Requirements

Must Have Strong background in security engineering or offensive security automation Hands?on experience exploiting WordPress plugins, themes, or PHP applications Deep understanding of: PHP execution model and request lifecycle WordPress internals (nonces, hooks, REST, admin flows) HTTP semantics, sessions, cookies, and authorization Proven ability to read, reason about, and exploit PHP source code Strong Python engineering skills for building: Automation pipelines Analysis tooling Exploit frameworks Nice to Have Exploit framework usage experience like MSF, Core Impact, Immunity Canvas Prior experience using LLMs to automate exploit development: PoC generation Workflow automation Payload mutation or inference Experience with: Execution traces or application?level call graphs Fuzzing or vulnerability discovery pipelines Familiarity with tools like WPScan, Nuclei, Metasploit, Burp Contributions to exploit tooling, frameworks, or security automation Public CVEs or PoCs (helpful but not required) What This Role Is Not ? Manual pentesting or report?driven consulting

Benefits & conditions

What's in it for you? A focus on professional development Interesting and challenging projects Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves Compensation for private medical insurance Co?working and gym/sports reimbursement Budget for education The opportunity to receive a reward for the most innovative idea that the company can patent

About the company

Join a company where people build innovative products and thrive in a remote-friendly environment. 

🔗 Learn more:
 cloudlinux.com | imunify360.com | tuxcare.com

Apply for this position