hireclover
All jobs

CloudLinux

Senior Security Engineer (Python, WordPress & PHP)

Remote Senior $4.7k–$12.8k/moest.

Summary

CloudLinux is seeking a Senior Security Engineer to build automated systems for exploiting and analyzing WordPress and PHP vulnerabilities. This engineering-focused role emphasizes tooling, automation, and LLM-assisted exploit development rather than traditional pentesting.

What you'll do

Main Responsibilities:

  • Design and build systems to ingest, normalize, and analyze PHP execution traces including function calls, parameters, control flow, and side effects
  • Develop tooling to infer vulnerable code paths, authorization flaws, and state-handling weaknesses from PHP source code
  • Create automated pipelines that convert CVE descriptions and PHP source into working exploits and replay attack paths deterministically
  • Build LLM-assisted frameworks for exploit skeleton generation, parameter inference, payload mutation, and robustness testing
  • Develop high-fidelity exploit simulations targeting admin-ajax.php, WordPress REST APIs, and plugin-specific endpoints
  • Transform exploit mechanics into signals for detection and prevention systems

Requirements

Must Have:

  • Strong background in security engineering or offensive security automation
  • Hands-on experience exploiting WordPress plugins, themes, or PHP applications
  • Deep understanding of PHP execution model, request lifecycle, WordPress internals (nonces, hooks, REST, admin flows), HTTP semantics, sessions, cookies, and authorization
  • Proven ability to read, reason about, and exploit PHP source code
  • Strong Python engineering skills for building automation pipelines, analysis tooling, and exploit frameworks

Nice to Have:

  • Experience with exploit frameworks like MSF, Core Impact, or Immunity Canvas
  • Prior experience using LLMs to automate exploit development, PoC generation, workflow automation, or payload mutation
  • Experience with execution traces, application-level call graphs, fuzzing, or vulnerability discovery pipelines
  • Familiarity with tools like WPScan, Nuclei, Metasploit, or Burp
  • Contributions to exploit tooling, frameworks, or security automation
  • Public CVEs or PoCs published

Conditions

Work Environment & Benefits:

  • Fully remote work with flexible working hours and ability to work from any location worldwide
  • 24 days paid vacation per year plus 10 national holidays and unlimited sick leave
  • Private medical insurance compensation
  • Co-working and gym/sports reimbursement
  • Education budget
  • Reward opportunity for patentable innovative ideas
  • Focus on professional development with interesting and challenging projects
  • High autonomy and deep technical ownership

Browse jobs