AI Architect (AI for Security)

Neurons Lab

Valencia

Presencial

EUR 60.000 - 90.000

A tiempo parcial

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Neurons Lab is seeking an experienced security consultant to join a hands-on AI-for-Security engagement with a regulated iGaming group. You will challenge and harden the existing AI-driven offensive pipeline, design the exploitation agent, and optimize cost-per-finding across recon, exploitation, and analysis loops.

Working with client security engineers and a CISO audience, you will ensure perimeter containment, define automated responses, and deliver a defensible technical roadmap that

Formación

  • Hands-on offensive security with vulnerability research and exploitation.
  • Experience building or integrating AI/LLM-driven security automation.
  • Experience with cloud security (AWS) and regulated environments.

Responsabilidades

  • Collaborate with client's security engineers to harden AI-driven offensive pipeline end-to-end.
  • Design and refine exploitation agent planning, exploit validation, and sandbox orchestration.
  • Benchmark open models against frontier models for recon and exploitation tasks.
  • Define intrusion and privilege-escalation patterns for automated responses.
  • Deliver a concise defensible technical roadmap for stakeholders.

Conocimientos

Offensive security
Vulnerability research
Exploit development
Penetration testing
Nmap
Nuclei
Burp Suite
Metasploit
Kali tooling
Python
Shell scripting
LLM agents
Sandboxing
AWS
Security automation

Herramientas

Kimi
GPT-OSS
MiniMax
DeepSeek
AWS Bedrock

Descripción del empleo

About The Project (description, Duration, Stage)

Hands-on AI-for-Security engagement with a regulated iGaming / online-gaming group. The client's security team is genuinely advanced: they already run an AI-driven offensive-security capability — continuous external-perimeter scanning feeding an LLM agent that plans exploitation, sources and validates exploits, and executes them in sandboxed environments — plus a runtime anomaly-detection layer watching for intrusion and privilege-escalation patterns across their products. They built this themselves and have explicitly asked us to challenge and improve it, not just rubber-stamp it.

What You'll Actually Do (example Tasks)
  • Join joint working sessions with the client's hands-on security engineers; challenge and harden their AI-driven offensive pipeline end-to-end (recon → verification → AI-planned exploitation → sandboxed execution).
  • Design and refine the exploitation agent: how the LLM plans attack paths, selects and validates exploits, and orchestrates parallel sandboxes safely and reproducibly.
  • Optimise cost-per-finding of the existing exploitation pipeline: benchmark local / sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against frontier models for the recon, exploitation and analysis loops; quantify accuracy / latency / cost trade-offs and recommend hardware sizing.
  • Shape the runtime anomaly-detection layer: define which intrusion / privilege-escalation precursor patterns are worth collecting (signal over raw-log volume), and design the missing pieces — automated response (kill a malicious process / disable an account on detection) and triage routing by criticality.
  • Stand up a quick-win PoC to anchor the engagement — e.g. an automated dependency / PR vulnerability-scanning pass, or a head-to-head local-vs-frontier benchmark of the exploitation agent.
  • Turn findings into a defensible technical proposal and roadmap; present methodology and trade-offs to a technical CISO / CTO audience.
  • Keep all sensitive work build-time and in-perimeter — no pushing intellectual property, configs, or recon-enabling data to external model providers; respect regulated-gaming certification constraints (no uncertified AI in runtime-critical paths).
Skills (hands-on First)
  • Hands-on offensive security: vulnerability research, exploit development and chaining, web + network penetration testing; fluent with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite and Kali tooling.
  • Building and operating LLM agents for security work — agentic tool-use, sandbox orchestration, prompt / flow design for recon and exploitation, guardrails for autonomous exploitation.
  • Local / self-hosted open models: running and tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; quantization, throughput and the agentic-performance trade-offs that matter for security automation.
  • Exploit & threat intelligence: sourcing and validating exploits (including from underground / forum sources), CVE triage, exploitability and severity assessment.
  • Runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response.
  • Cloud security (AWS preferred): sandboxing, container isolation, secure inference hosting.
  • Writes their own code (Python + shell) and can explain methodology to non-security executives.
Knowledge
  • Modern offensive-security methodology and the current exploit / zero-day landscape.
  • Strengths and limits of frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task).
  • Data-egress / sovereignty constraints: why IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.
  • iGaming / regulated-infrastructure context and certification constraints (build-time vs. run-time AI) — strong plus.
  • Defensive side — SIEM, anomaly detection, incident response — plus.
Experience

Key characteristics (ideally 4/4):

  • Hands-on offensive security
  • Built or operated AI / LLM-driven security automation (agents, pipelines), not just used a chatbot
  • Cloud hyperscaler experience (AWS preferred)
  • Technology consulting / client-facing delivery — can lead a CISO-level technical conversation

Role-specific characteristics:

  • 3+ years hands-on offensive security / vulnerability research / red-team
  • Demonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligence
  • Has wired LLMs into real security workflows (recon, exploitation, triage)
  • Has run self-hosted / local open models in a real engagement, with a view on cost and hardware
  • Comfortable being the sole domain expert in the room and owning the methodology
Terms & conditions
  • Allocation: ~0.25 – 0.5 FTE initially (discovery/advisory + joint CISO sessions), scaling with the engagement
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

AI Security Architect for Offensive Automation
AI Security Architect for Offensive Automation

Neurons Lab • Valencia

Presencial
EUR 60.000 - 90.000
AI Architect (AI for Security)
AI Architect (AI for Security)

Neurons Lab • Madrid

Presencial
EUR 80.000 - 110.000
AI Architect (UA/RU Language speaking)
AI Architect (UA/RU Language speaking)

Neurons Lab • España

Presencial
EUR 120.000 - 180.000
AI Analyst (UA/RU Language speaking)
AI Analyst (UA/RU Language speaking)

Neurons Lab • España

Presencial
EUR 60.000 - 100.000
AI Security Architect - Offensive AI & PoC Leader
AI Security Architect - Offensive AI & PoC Leader

Neurons Lab • Madrid

Presencial
EUR 80.000 - 110.000
AI Architect (iGaming)
AI Architect (iGaming)

Neurons-Lab • España

Presencial
EUR 120.000 - 170.000
AI Security Architect - Offensive AI for Regulated Gaming
AI Security Architect - Offensive AI for Regulated Gaming

Neurons Lab • España

Presencial
EUR 80.000 - 110.000
AI Operations Engineer
AI Operations Engineer

United States Digital Space LLC • Amer

Presencial
EUR 70.000 - 95.000
AI Software Engineer | Spain
AI Software Engineer | Spain

Accenture España • Madrid

Presencial
EUR 90.000 - 130.000
Technical AI Engagement Lead
Technical AI Engagement Lead

Neurons Lab • Madrid

Presencial
EUR 70.000 - 110.000