About the project
Neurons Lab is seeking an offensive-security domain lead for a hands-on AI-for-Security engagement with a regulated iGaming group. The client utilizes an advanced AI-driven offensive-security capability, including continuous perimeter scanning, LLM-based exploit planning, and runtime anomaly detection. You will act as the security domain owner, challenging and improving the existing pipeline while advising on methodology, architecture, and PoC development.
What you'll actually do
- Challenge and harden the client's AI-driven offensive pipeline, from recon to sandboxed execution.
- Design and refine exploitation agents, focusing on LLM planning, exploit validation, and safe sandbox orchestration.
- Optimize the exploitation pipeline by benchmarking local open models against frontier models to balance accuracy, latency, and cost.
- Define and refine the runtime anomaly-detection layer, focusing on intrusion and privilege-escalation patterns.
- Develop technical proposals and roadmaps to be presented to CISO/CTO-level audiences.
- Ensure all work remains in-perimeter to meet regulatory and data-sovereignty requirements.
Required Skills
- Hands-on offensive security: Vulnerability research, exploit development, and penetration testing (Nmap, Nuclei, Metasploit, Burp Suite).
- AI/LLM agents: Building and operating agentic pipelines for security work, including sandbox orchestration and prompt/flow design.
- Local/Open models: Running and tuning open-weight models (DeepSeek, etc.) on private hardware, including quantization and throughput optimization.
- Threat Intelligence: Expertise in CVE triage, exploit validation, and exploit chaining.
- Cloud Security: Proficiency in container isolation and secure inference hosting, preferably on AWS.
- Detection Engineering: Experience designing automated response and anomaly detection for privilege escalation.