
AI Architect – AI for Security
Posted Jun 25

Posted Jun 25
This is a fully remote position, open to applicants in Romania.
• Participate in collaborative working sessions with the client's on-the-ground security engineers; critically assess and fortify their AI-driven offensive pipeline from start to finish (recon → verification → AI-planned exploitation → sandboxed execution).
• Create and enhance the exploitation agent: determining how the LLM devises attack paths, selects and verifies exploits, and safely orchestrates parallel sandboxes in a reproducible manner.
• Improve the cost-per-finding of the current exploitation pipeline: evaluate local / sovereign open models (Kimi, GPT-OSS, MiniMax, DeepSeek) against leading-edge models for the recon, exploitation, and analysis processes; assess accuracy / latency / cost trade-offs and suggest appropriate hardware requirements.
• Develop the runtime anomaly-detection layer: identify which intrusion / privilege-escalation precursor patterns are significant to collect (signal versus raw-log volume), and design the essential components — automated responses (terminate a malicious process / disable an account upon detection) and criticality-based triage routing.
• Establish a quick-win Proof of Concept (PoC) to anchor the engagement — for instance, an automated dependency / pull request vulnerability scanning process, or a direct comparison of local versus frontier benchmarks of the exploitation agent.
• Transform findings into a well-supported technical proposal and roadmap; convey methodology and trade-offs to a technical CISO / CTO audience.
• Ensure all sensitive work remains within build-time and in-perimeter — no transferring intellectual property, configurations, or recon-enabling data to external model providers; adhere to regulated-gaming certification requirements (no uncertified AI in runtime-critical paths).
• Practical experience in offensive security: vulnerability research, exploit development and chaining, web and network penetration testing; proficient with Nmap, Nuclei, Katana, Acunetix, Metasploit, Burp Suite, and Kali tools.
• Experience in constructing and operating LLM agents for security tasks — agentic tool usage, sandbox orchestration, prompt / flow design for reconnaissance and exploitation, and establishing guardrails for autonomous exploitation.
• Familiarity with local / self-hosted open models: running and fine-tuning open weights (Kimi, GPT-OSS, MiniMax, DeepSeek) on rented or private GPU; understanding quantization, throughput, and the agentic-performance trade-offs relevant for security automation.
• Expertise in exploit and threat intelligence: sourcing and validating exploits (including those from underground or forum sources), CVE triage, and assessing exploitability and severity.
• Knowledge in runtime detection: designing intrusion / privilege-escalation pattern detection, anomaly detection, and automated response mechanisms.
• Proficiency in cloud security (AWS preferred): sandboxing, container isolation, and secure inference hosting.
• Ability to write code (Python + shell) and articulate methodology to non-security executives.
• Understanding of modern offensive-security methodologies and the current exploit / zero-day landscape.
• Awareness of the strengths and limitations of frontier versus local LLMs for security automation (agentic tool usage, reasoning depth, cost-per-task).
• Insight into data-egress / sovereignty constraints: the importance of keeping IP and recon-enabling data in-perimeter; comparing private-cloud (AWS Bedrock) versus rented-hardware trade-offs.
• Knowledge of iGaming / regulated-infrastructure contexts and certification constraints (build-time versus run-time AI) — strong plus.
• Experience on the defensive side — SIEM, anomaly detection, incident response — is a plus.
• Health insurance
• Competitive salary
• Flexible working hours
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.