Senior Security Engineer (WordPress & PHP) (remote-only, Europe)

Senior Security Engineer (WordPress & PHP) (remote-only, Europe)

30 jul
|
CloudLinux
|
Madrid

30 jul

CloudLinux

Madrid

CloudLinux is a integral remote‑first company driven by our principles: do the right thing, employees first, we are remote first, and we deliver high‑volume, low‑cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful.

Imunify360 Security Suite Imunify360 is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy‑to‑use solution with a six‑layer approach to security delivers comprehensive and complete attack prevention.

Check out our website for more information about our Imunify360 Product: https://www.imunify360.com/

We are building an engineering‑heavy security platform for protecting WordPress and its plugin ecosystem. The core challenge is turning real attacker behavior into automated, repeatable systems that scale.

We are looking for a

Senior Security Engineer who understands exploitation deeply but prefers building tooling and automation over one‑off research. You will work on systems that:

Automatically generate and validate exploit PoCs for known WordPress / PHP CVEs

Analyze PHP execution traces from real zero‑day attacks against WordPress installations

LLMs are a first‑class component of this work—not a novelty—used to accelerate exploit reconstruction, PoC generation, and attack workflow automation.

This is an engineering role with offensive depth , not a traditional pentesting or red‑team position.

What You’ll Build

Systems to ingest, normalize, and analyze PHP execution traces:

Function calls,



parameters, control flow, side effects

No native binary reversing—focus is PHP‑level execution and logic

Tooling that infers

Vulnerable code paths

Authorization and logic flaws

Nonce and state‑handling weaknesses

Automated pipelines that

Convert CVE descriptions + PHP source code into working PoCs

Replay inferred exploit paths deterministically

LLM‑assisted frameworks for

Exploit skeleton generation

Parameter and payload inference

Exploit mutation and robustness testing

High‑fidelity exploit simulations targeting:

admin‑ajax.php

WordPress REST APIs

Plugin‑specific endpoints

Infrastructure that transforms exploit mechanics into signals usable by detection and prevention systems

Requirements Must Have

Strong background in security engineering or offensive security automation

Hands‑on experience exploiting WordPress plugins, themes, or PHP applications

Deep understanding of

PHP execution model and request lifecycle

WordPress internals (nonces, hooks, REST, admin flows)

HTTP semantics, sessions, cookies, and authorization

Proven ability to read, reason about, and exploit PHP source code

Strong Python engineering skills for building:

Automation pipelines

Analysis tooling

Exploit frameworks

Nice to Have

Exploit framework usage experience like MSF, Core Impact, Immunity Canvas





Prior experience using LLMs to automate exploit development:

PoC generation

Workflow automation

Payload mutation or inference

Experience with

Execution traces or application‑level call graphs

Fuzzing or vulnerability discovery pipelines

Familiarity with tools like WPScan, Nuclei, Metasploit, Burp

Contributions to exploit tooling, frameworks, or security automation

Public CVEs or PoCs (helpful but not required)

What This Role Is Not

❌ Manual pentesting or report‑driven consulting

❌ SOC or alert‑triage work

❌ Pure vulnerability research without automation

Why This Role Is Interesting

You’ll work with real zero‑day attack telemetry, not just public CVEs

You’ll build repeatable systems, not one‑off demos

LLMs are used pragmatically, as part of production pipelines

Your work directly shapes how real WordPress attacks are detected and stopped

High autonomy, deep technical ownership

Benefits What’s in it for you?

A focus on professional development

Interesting and challenging projects

Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide

Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves

Compensation for private medical insurance

Co‑working and gym/sports reimbursement

Budget for education The opportunity to receive a reward for the most innovative idea that the company can patent

By applying for this position, you consent to the processing of your personal data as described in our Privacy Policy (https://cloudlinux.com/candidate-privacy-notice), which provides detailed information on how we maintain and handle your data.

📌 Senior Security Engineer (WordPress & PHP) (remote-only, Europe)
🏢 CloudLinux
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer (wordpress & php) (remote-only, europe) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer (wordpress & php) (remote-only, europe) / madrid