×
Register Here to Apply for Jobs or Post Jobs. X

Senior Offensive Security Engineer; Autonomous testing

Job in City of Edinburgh, Edinburgh, City of Edinburgh Area, EH1, Scotland, UK
Listing for: Hollybank Trustees Ltd
Full Time position
Listed on 2026-09-18
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant
Salary/Wage Range or Industry Benchmark: 90000 - 130000 GBP Yearly GBP 90000.00 130000.00 YEAR
Job Description & How to Apply Below

Senior Offensive Security Engineer (Autonomous testing)

Location: Hybrid / Redheughs Rigg, Edinburgh EH12 9DQ
, UK
job type: Permanent / Full-time
Sector and subsector: IT | Cybersecurity
Salary: Negotiable salary

At Quorum Cyber, we're on a mission to help good people win.

Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents.

We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.

As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.

In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.

Role

Purpose:

In this role you will apply your leadership, innovative thinking, curiosity, and existing deep technical expertise to help Quorum Cyber close the distance between AI speed and efficiency, and human insight. Penetration testing, API and web application testing, and red teaming are delivered the traditional way: a skilled human, a scope document, a fixed number of days, a report at the end.

The work is excellent, but it does not scale. Clients want continuous assurance; not la snapshot.

This role exists to change that. You will run real engagements and, from inside that work, build the agentic AI that takes them over stage by stage: reconnaissance, enumeration, attack‑path discovery, exploitation of known vulnerability classes, evidence capture, triage, first‑draft reporting. Each stage moves from:

1. "A human does this" to…

2. "An agent does this and a human signs it off"…

3. And then to help migrate into a continuously running managed service.

What I Do Is:

Deliver engagements (Phase I, and shrinking over time)

  • Lead network, web application, API, cloud, and full‑scope red team engagements.
  • Own them end to end: scoping, rules of engagement, authorisation, execution, evidence, reporting, client debrief.
  • Set the quality bar and be the escalation point on a hard target.

Build the automation (Phase II, growing over time)

  • Build agentic systems that perform discrete stages of a test autonomously, starting narrow and expanding as reliability is proven.
  • Build the evaluation harness before the agent:
  • Engineer for the failure modes that matter here: false positives and negatives, non‑determinism, scope escape, destructive actions, runaway cost. Instrument accuracy, coverage, cost, and hours saved.

Turn it into a service (Phase III, growing over time)

  • Work with service management and Product Management to turn working automation into a repeatable, multi‑tenant offering with defined SLAs and pricing.
  • Enforce scope and authorisation in code rather than in a document: target validation, blast‑radius limits, kill switches, prohibited‑action lists, full audit trail.
  • Define where the human stays in the loop, and mentor the team in both directions.
The Skills I Need Are:

Strength in all three areas. Depth in offensive security and demonstrable AI agent‑building are both non‑negotiable.

Offensive security depth

  • Around 7 years hands‑on, including at least 4 delivering client‑facing engagements.
  • Network testing: external and internal, Active Directory attack paths, privilege escalation, lateral movement, post‑exploitation.
  • Web…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary