CloudLinux
Senior Security Engineer (Python, WordPress & PHP)
Remote Senior $4.7k–$12.8k/moest.
Summary
CloudLinux is seeking a Senior Security Engineer to build automated systems for exploiting and analyzing WordPress and PHP vulnerabilities. This engineering-focused role emphasizes tooling, automation, and LLM-assisted exploit development rather than traditional pentesting.
What you'll do
Main Responsibilities:
- Design and build systems to ingest, normalize, and analyze PHP execution traces including function calls, parameters, control flow, and side effects
- Develop tooling to infer vulnerable code paths, authorization flaws, and state-handling weaknesses from PHP source code
- Create automated pipelines that convert CVE descriptions and PHP source into working exploits and replay attack paths deterministically
- Build LLM-assisted frameworks for exploit skeleton generation, parameter inference, payload mutation, and robustness testing
- Develop high-fidelity exploit simulations targeting admin-ajax.php, WordPress REST APIs, and plugin-specific endpoints
- Transform exploit mechanics into signals for detection and prevention systems
Requirements
Must Have:
- Strong background in security engineering or offensive security automation
- Hands-on experience exploiting WordPress plugins, themes, or PHP applications
- Deep understanding of PHP execution model, request lifecycle, WordPress internals (nonces, hooks, REST, admin flows), HTTP semantics, sessions, cookies, and authorization
- Proven ability to read, reason about, and exploit PHP source code
- Strong Python engineering skills for building automation pipelines, analysis tooling, and exploit frameworks
Nice to Have:
- Experience with exploit frameworks like MSF, Core Impact, or Immunity Canvas
- Prior experience using LLMs to automate exploit development, PoC generation, workflow automation, or payload mutation
- Experience with execution traces, application-level call graphs, fuzzing, or vulnerability discovery pipelines
- Familiarity with tools like WPScan, Nuclei, Metasploit, or Burp
- Contributions to exploit tooling, frameworks, or security automation
- Public CVEs or PoCs published
Conditions
Work Environment & Benefits:
- Fully remote work with flexible working hours and ability to work from any location worldwide
- 24 days paid vacation per year plus 10 national holidays and unlimited sick leave
- Private medical insurance compensation
- Co-working and gym/sports reimbursement
- Education budget
- Reward opportunity for patentable innovative ideas
- Focus on professional development with interesting and challenging projects
- High autonomy and deep technical ownership