Back to Jobs
Neurons Lab
AI & Machine Learning 1d ago

AI-for-Security Domain Lead (Offensive Security & LLM Expert)

Neurons Lab
RomaniaRomania
SloveniaSlovenia
GermanyGermany
SpainSpain
HungaryHungary
GeorgiaGeorgia
SlovakiaSlovakia
LatviaLatvia
LithuaniaLithuania
GreeceGreece
AlbaniaAlbania
PolandPoland
🌍Czechia
MoldovaMoldova
BulgariaBulgaria
EstoniaEstonia
🌍North Macedonia
Contract
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Machine Learning41mFree Trial ✨
Start 10-Day Free Trial
Python ScriptingAI EngineerNLPOpenAI API

Want to know if you're a match for this job?

Calculate My Match Score

About the Project

This is a hands-on AI-for-Security engagement with a regulated iGaming/online-gaming group. The client’s security team operates an advanced AI-driven offensive-security capability, including:

  • Continuous external-perimeter scanning feeding an LLM agent for exploitation planning, sourcing, validation, and sandboxed execution.
  • A runtime anomaly-detection layer monitoring intrusion and privilege-escalation patterns across their products.

The client explicitly seeks to challenge and improve their existing systems—not just validate them. This is not a generalist AI project; the focus is on the offensive-security domain lead who can peer with their CISO team, pressure-test their pipeline, and own the methodology.

Stage: Pre-engagement/discovery (next step: joint technical session with the client’s CISO/engineers). Duration: Discovery → advisory/PoC, with potential to scale as the security program expands.

Reporting: To Neurons Lab’s CTO/engagement lead (@Alex Honchar), collaborating with the Neurons Lab AI Architect on the account.

What You’ll Do

  • Join joint sessions with the client’s security engineers to challenge and harden their AI-driven offensive pipeline (recon → verification → AI-planned exploitation → sandboxed execution).

  • Design and refine the exploitation agent, including LLM-based attack path planning, exploit selection/validation, and safe orchestration of parallel sandboxes.

  • Optimize cost-per-finding by benchmarking local/sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against frontier models for recon, exploitation, and analysis. Quantify accuracy/latency/cost trade-offs and recommend hardware sizing.

  • Shape the runtime anomaly-detection layer, defining intrusion/privilege-escalation patterns to monitor and designing automated responses (e.g., killing malicious processes/disabling accounts) and triage routing by criticality.

  • Stand up a quick-win PoC, such as automated dependency/PR vulnerability scanning or a local-vs-frontier benchmark of the exploitation agent.

  • Deliver a defensible technical proposal and roadmap, presenting methodology and trade-offs to a CISO/CTO audience.

  • Ensure all sensitive work remains build-time and in-perimeter—no external model providers receive IP, configs, or recon-enabling data. Respect regulated-gaming certification constraints (no uncertified AI in runtime-critical paths).

Skills

  • Hands-on offensive security: Vulnerability research, exploit development/chaining, web/network penetration testing. Tools: Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite, Kali.

  • LLM agents for security: Agentic tool-use, sandbox orchestration, prompt/flow design for recon/exploitation, and guardrails for autonomous exploitation.

  • Local/self-hosted open models: Running/tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented/private GPU, with focus on quantization, throughput, and agentic-performance trade-offs.

  • Exploit & threat intelligence: Sourcing/validating exploits (including underground/forum sources), CVE triage, and exploitability/severity assessment.

  • Runtime detection: Designing intrusion/privilege-escalation pattern detection, anomaly detection, and automated response.

  • Cloud security (AWS preferred): Sandboxing, container isolation, secure inference hosting.

  • Writes custom code (Python + shell) and can explain methodology to non-security executives.

Knowledge

  • Modern offensive-security methodology and the current exploit/zero-day landscape.

  • Frontier vs. local LLMs for security automation (agentic tool-use, reasoning depth, cost-per-task).

  • Data-egress/sovereignty constraints: IP and recon-enabling data must stay in-perimeter; private-cloud (AWS Bedrock) vs. rented-hardware trade-offs.

  • iGaming/regulated-infrastructure context and certification constraints (build-time vs. runtime AI)—strong plus.

  • Defensive side (SIEM, anomaly detection, incident response)—plus.

Experience

Key characteristics (ideally 4/4):

  • Hands-on offensive security.

  • Built/operated AI/LLM-driven security automation (agents, pipelines), not just used a chatbot.

  • Cloud hyperscaler experience (AWS preferred).

  • Technology consulting/client-facing delivery—able to lead CISO-level technical conversations.

Role-specific requirements:

  • 3+ years hands-on offensive security/vulnerability research/red-team.

  • Demonstrable exploit development and chaining; comfortable with zero-day research and exploit intelligence.

  • Wired LLMs into real security workflows (recon, exploitation, triage).

  • Run self-hosted/local open models in real engagements, with hardware/cost awareness.

  • Comfortable being the sole domain expert and owning the methodology.

How would you rate this job post?

See what other professionals think about this role.

banner

Neurons Lab (operating at neurons-lab.com) is a leading AI consultancy platform engineered for AI transformation services. Founded by Igor Sydorenko and headquartered in London, United Kingdom, Neurons Lab helps financial institutions move from AI-curious to AI-enabled. Under the hood, the company delivers AI training programs and custom AI agents designed for regulated environments. This allows financial institutions to leverage AI technology effectively. Backed by no publicly disclosed funding information.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More