AI Architect (AI for Security)

Neurons Lab

Deutschland

Vor Ort

EUR 120.000 - 180.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Competitive compensation
Regulated industry exposure

Zusammenfassung

Neurons Lab is seeking an experienced Offensive Security domain lead to partner with a regulated iGaming security team. You will challenge and improve their AI-driven offensive pipeline, own the methodology, and deliver concrete discovery outcomes.

The engagement starts with discovery and advisory work, then PoC scaling across the program, with tight perimeters and regulatory constraints. You’ll present findings to CISO-level audiences.

Qualifikationen

  • Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing.
  • Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation.
  • Local / self-hosted open models: running and tuning open weights on rented or private GPU; quantization, throughput and the agentic-performance trade-offs.
  • Exploit & threat intelligence: sourcing and validating exploits (including from underground sources), CVE triage, exploitability and severity assessment.
  • Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.
  • Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.
  • Writes their own code (Python + shell) and can explain methodology to non-security executives.

Aufgaben

  • Join sessions with client security engineers; challenge and harden the AI-driven offensive pipeline end-to-end.
  • Design and refine the exploitation agent: LLM plans attack paths, selects and validates exploits, orchestrates sandboxes.
  • Optimize cost-per-finding of the exploitation pipeline; benchmark models and quantify latency and cost.
  • Shape the runtime anomaly-detection layer; define useful intrusion patterns and automated responses.
  • Stand up a quick-win PoC: automated vulnerability scanning or local-vs-frontier benchmarks.
  • Turn findings into a defensible technical proposal and roadmap for CISO/CTO audiences.
  • Keep sensitive work build-time and perimeter-only; respect regulated-gaming constraints.

Kenntnisse

Hands-on offensive security
Security automation
Cloud security experience
Client-facing delivery
Red-team / vulnerability research

Tools

Nmap
Nuclei
Katana
Acunetix
Metasploit
Burp Suite
Kali tooling

Jobbeschreibung

About The Project (description, Duration, Stage)

Hands-on AI-for-Security engagement with a regulated iGaming / online-gaming group. The client’s security team is genuinely advanced: they already run an AI-driven offensive-security capability continuous external-perimeter scanning feeding an LLM agent that plans exploitation, sources and validates exploits, and executes them in sandboxed environments and a runtime anomaly-detection layer watching for intrusion and privilege-escalation patterns across their products. They built this themselves and have explicitly asked us to challenge and improve it, not just rubber-stamp it.

This is not a generalist AI project. Neurons Lab brings the AI-architecture and engagement depth; what's missing is the offensive-security domain lead who can sit across the table from a hands-on CISO team as a peer, pressure-test their pipeline, and own the methodology. You are that expert. The early work is concrete and consultative: understand what they've built, find where it’s wrong or expensive, and propose a better way.

Stage

pre-engagement / discovery (the immediate next step is a joint technical session with the client’s CISO / security engineers).

Duration

discovery - advisory / PoC, with strong extension probability as the security program scales across the group.

Reporting

Neurons Lab CTO / engagement lead (@Alex Honchar); partners with the Neurons Lab AI Architect on the account. You are the security domain owner for this track.

What You’ll Actually Do (example Tasks)
  • Join joint working sessions with the client’s hands-on security engineers; challenge and harden their AI-driven offensive pipeline end-to-end (recon - verification - AI-planned exploitation - sandboxed execution).
  • Design and refine the exploitation agent: how the LLM plans attack paths, selects and validates exploits, and orchestrates parallel sandboxes safely and reproducibly.
  • Optimise cost-per-finding of the existing exploitation pipeline: benchmark local / sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against frontier models for the recon, exploitation and analysis loops; quantify accuracy - latency - cost trade-offs and recommend hardware sizing.
  • Shape the runtime anomaly-detection layer: define which intrusion / privilege-escalation precursor patterns are worth collecting (signal over raw-log volume), and design the missing pieces - automated response (kill a malicious process - disable an account on detection) and triage routing by criticality.
  • Stand up a quick-win PoC to anchor the engagement - e.g. an automated dependency / PR vulnerability-scanning pass, or a head-to-head local-vs-frontier benchmark of the exploitation agent.
  • Turn findings into a defensible technical proposal and roadmap; present methodology and trade-offs to a technical CISO / CTO audience.
  • Keep all sensitive work build-time and in-perimeter - no pushing intellectual property, configs, or recon-enabling data to external model providers; respect regulated-gaming certification constraints (no uncertified AI in runtime-critical paths).
Skills (hands-on First)
  • Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.
  • Building and operating LLM agents for security work - agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.
  • Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.
  • Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.
  • Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.
  • Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.
  • Writes their own code (Python + shell) and can explain methodology to non-security executives.
Knowledge
  • Modern offensive-security methodology and the current exploit / zero-day landscape.
  • Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task).
  • Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.
  • iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) - strong plus.
  • Defensive side - SIEM, anomaly detection, incident response - plus.
Experience
Key characteristics (ideally 4/4)
  • Hands-on offensive security
  • Built or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbot
  • Cloud hyperscaler experience (AWS preferred)
  • Technology consulting / client-facing delivery - can lead a CISO-level technical conversation
Role-specific characteristics:
  • 3+ years hands-on offensive security / vulnerability research / red-team
  • Demonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligence
  • Has wired LLMs into real security workflows (recon, exploitation, triage)
  • Has run self-hosted / local open models in a real engagement, with a view on cost and hardware
  • Comfortable being the sole domain expert in the room and owning the methodology
Terms & conditions
  • Allocation: ~0.25 - 0.5 FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Staff AI Engineer
Staff AI Engineer

Eye Security • Berlin

Vor Ort
EUR 120.000 - 160.000
Research ownership
Shipped mitigations
Collaborative team
+2
Cloud Security Engineer at YGO GmbH
Cloud Security Engineer at YGO GmbH

YGO GmbH • Deutschland

Vor Ort
EUR 90.000 - 120.000
Offensive Security Lead
Offensive Security Lead

Nebius B.V. • Deutschland

Vor Ort
EUR 150.000 - 190.000
Equity upside
Remote-first culture
Flexible work
+1
Senior Security Architect (Human)
Senior Security Architect (Human)

Neura Robotics GmbH • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security Architect: Threat Modelling for Embedded & Cloud
Security Architect: Threat Modelling for Embedded & Cloud

NEURA Robotics • Deutschland

Remote
USD 140.000 - 180.000
Senior Forward Deployed AI Architect (GenAI, AWS)
Senior Forward Deployed AI Architect (GenAI, AWS)

Embedded Shishya • Deutschland

Vor Ort
EUR 120.000 - 150.000
Remote-friendly culture
Medical insurance
Educational budget
Cybersecurity Expert - Offensive Security
Cybersecurity Expert - Offensive Security

Mercor • Berlin

Vor Ort
EUR 90.000 - 130.000
Forward Deployed Engineer, DACH
Forward Deployed Engineer, DACH

Telnyx • München

Hybrid
EUR 90.000 - 130.000
Senior Applied AI Engineer (all genders)
Senior Applied AI Engineer (all genders)

Accenture DACH • Kronberg im Taunus

Vor Ort
EUR 90.000 - 130.000
Cloud & AppSec Engineer: Secure AI/ML Pipelines
Cloud & AppSec Engineer: Secure AI/ML Pipelines

NEURA Robotics • Deutschland

Remote
USD 120.000 - 160.000