At a Glance
- Tasks: Lead innovative security projects and develop AI-driven automation for offensive security testing.
- Company: Join Quorum Cyber, a fast-growing leader in cyber security with a mission to protect organisations globally.
- Benefits: Enjoy a competitive salary, world-class benefits, and access to cutting-edge technology.
- Other info: Be part of a diverse team committed to equality and continuous learning.
- Why this job: Make a real impact in cyber security while advancing your skills in a dynamic environment.
- Qualifications: 7+ years in offensive security and experience in building AI systems are essential.
The predicted salary is between 54000 - 66000 £ per year.
At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents. We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.
As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.
In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.
Role Purpose:
In this role you will apply your leadership, innovative thinking, curiosity, and existing deep technical expertise to help Quorum Cyber close the distance between AI speed and efficiency, and human insight. Penetration testing, API and web application testing, and red teaming are delivered the traditional way: a skilled human, a scope document, a fixed number of days, a report at the end. The work is excellent, but it does not scale. Clients want continuous assurance; not a snapshot. This role exists to change that. You will run real engagements and, from inside that work, build the agentic AI that takes them over stage by stage: reconnaissance, enumeration, attack-path discovery, exploitation of known vulnerability classes, evidence capture, triage, first-draft reporting.
What I Do Is:
- Deliver engagements (Phase I, and shrinking over time)
- Lead network, web application, API, cloud, and full-scope red team engagements.
- Own them end to end: scoping, rules of engagement, authorisation, execution, evidence, reporting, client debrief.
- Set the quality bar and be the escalation point on a hard target.
- Build the automation (Phase II, growing over time)
- Build agentic systems that perform discrete stages of a test autonomously, starting narrow and expanding as reliability is proven.
- Build the evaluation harness before the agent: Engineer for the failure modes that matter here: false positives and negatives, non-determinism, scope escape, destructive actions, runaway cost. Instrument accuracy, coverage, cost, and hours saved.
- Turn it into a service (Phase III, growing over time)
- Work with service management and Product Management to turn working automation into a repeatable, multi-tenant offering with defined SLAs and pricing.
- Enforce scope and authorisation in code rather than in a document: target validation, blast-radius limits, kill switches, prohibited-action lists, full audit trail.
- Define where the human stays in the loop, and mentor the team in both directions.
The Skills I Need Are:
- Strength in all three areas. Depth in offensive security and demonstrable AI agent-building are both non-negotiable.
- Offensive security depth: Around 7 years hands-on, including at least 4 delivering client-facing engagements.
- Network testing: external and internal, Active Directory attack paths, privilege escalation, lateral movement, post-exploitation.
- Web and API testing: the OWASP Top 10 and, more importantly, what it misses, meaning business logic flaws, authentication and session weaknesses, and multi-step chains.
- Red teaming: objective-based operations covering initial access, command and control, EDR evasion, and purple-team work, against a client actively trying to catch you.
- Excellent written English, with redacted reports or a willingness to sit a writing exercise. The report is the product.
- Agentic AI capability, the differentiator: We want evidence of building, not of using.
- You have shipped a non-trivial LLM agent: something that plans, calls real tools, handles errors, and finishes a multi-step task unsupervised.
- You are fluent with tool calling, structured output, the Model Context Protocol, and at least one agent framework or SDK (LangGraph, CrewAI, the OpenAI or Claude Agent SDKs, PydanticAI, or a hand-rolled loop).
- You can describe an evaluation harness you built: the dataset, the scoring, how you caught regressions, and how you handled the fact that the same input does not give the same output twice.
- You are honest about the limits and can say with examples which parts of a test agents do well, badly, or should not attempt at all.
- Software engineering and disposition: Strong Python, the working language of this role. Go, Rust, or TypeScript is useful.
- Version control, code review, tests, CI/CD, containerisation, infrastructure as code, one major cloud.
- Genuine enthusiasm for automating a craft you spent years mastering, and the honesty to say when it is not good enough yet.
- Comfortable with ambiguity and with distributed, written-first working. Much of this role is deciding what to build next.
Preferred Qualifications:
- Consultancy, MSSP, or managed service experience.
- Exposure to commercial autonomous or continuous testing platforms (XBOW, Horizon3.ai NodeZero, Pentera) as a user, evaluator, or competitor.
- Open-source contributions to offensive or agent tooling, published research, conference talks (DEF CON, Black Hat, BSides, AI Village), or a CVE record.
- Detection engineering experience, or familiarity with CREST, PCI DSS, CBEST/TIBER-EU, or DORA threat-led testing.
I Know I Have Done A Great Job If:
- Delivering high-quality network, web, API, cloud and red-team engagements that provide clear, actionable outcomes for clients.
- Building agentic systems that can safely complete defined stages of offensive testing with increasing levels of autonomy.
- Proving that the automation works through robust evaluation, testing and measurement of accuracy, coverage, reliability, cost and time saved.
- Convert successful automation into a repeatable, scalable, multi-tenant managed service with clear service levels and commercial value.
- Creating a clear understanding of where automation can be trusted, where human expertise is required and where an agent should not be used.
- Embedding appropriate safeguards, including scope validation, authorisation controls, kill switches, prohibited-action lists and complete audit trails.
- Raising the technical quality bar across the team and sharing your expertise in both offensive security and production-grade software engineering.
- Ultimately, you will have helped Quorum Cyber deliver continuous assurance at a scale that traditional penetration testing alone cannot achieve.
Other Information:
You will get an excellent salary, with world class benefits. As a leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.
Our Commitment to Equality & Diversity:
Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity. We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation.
Senior Offensive Security Engineer (Autonomous testing) in Edinburgh employer: Quorum Cyber
At Quorum Cyber, we pride ourselves on being an exceptional employer, offering a dynamic work environment in the heart of Edinburgh. Our commitment to employee growth is evident through our world-class benefits and access to cutting-edge technology, fostering a culture of curiosity and innovation. Join us to be part of a diverse team dedicated to making a meaningful impact in the cyber security landscape while enjoying a supportive and inclusive workplace.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Offensive Security Engineer (Autonomous testing) in Edinburgh
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Quorum Cyber, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Quorum Cyber
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Quorum Cyber. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Offensive Security Engineer (Autonomous testing) in Edinburgh
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Quorum Cyber insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Quorum Cyber that you’re committed to staying ahead in the game.
How to prepare for a job interview at Quorum Cyber
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Quorum Cyber to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Quorum Cyber.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.