Senior Security Engineer (WordPress & PHP) (remote-only, Europe)

Senior Security Engineer (WordPress & PHP) (remote-only, Europe)

04 ago
|
CloudLinux
|
Valencia

04 ago

CloudLinux

Valencia

ppCloudLinux is a integral remote‑first company driven by our principles: do the right thing, employees first, we are remote first, and we deliver high‑volume, low‑cost Linux infrastructure and security products that help companies to increase the efficiency of their operations. Every person on our team supports each other and does what we can to ensure we all are successful. /p h3Imunify360 Security Suite /h3 pImunify360 is a product of CloudLinux Inc., the maker of the #1 OS in security and stability for hosting providers. Imunify is an innovative security solution designed specifically for shared and VPS/Dedicated servers. The automated, easy‑to‑use solution with a six‑layer approach to security delivers comprehensive and complete attack prevention. /p pCheck out our website for more information about our Imunify360 Product: /p pWe are building an engineering‑heavy security platform for protecting WordPress and its plugin ecosystem. The core challenge is turning real attacker behavior into automated, repeatable systems that scale. /p pWe are looking for a bSenior Security Engineer /b who understands exploitation deeply but prefers building tooling and automation over one‑off research. You will work on systems that: /p ul liAutomatically generate and validate exploit PoCs for known WordPress / PHP CVEs /li liAnalyze PHP execution traces from real zero‑day attacks against WordPress installations /li /ul pLLMs are a first‑class component of this work—not a novelty—used to accelerate exploit reconstruction, PoC generation, and attack workflow automation. /p pThis is an bengineering role with offensive depth /b, not a traditional pentesting or red‑team position. /p h3What You’ll Build /h3 ul liSystems to ingest, normalize, and analyze PHP execution traces: ul liFunction calls, parameters, control flow,



side effects /li liNo native binary reversing—focus is PHP‑level execution and logic /li /ul /li liTooling that infers: ul liVulnerable code paths /li liAuthorization and logic flaws /li liNonce and state‑handling weaknesses /li /ul /li liAutomated pipelines that: ul liConvert CVE descriptions + PHP source code into working PoCs /li liReplay inferred exploit paths deterministically /li /ul /li liLLM‑assisted frameworks for: ul liExploit skeleton generation /li liParameter and payload inference /li liExploit mutation and robustness testing /li /ul /li liHigh‑fidelity exploit simulations targeting: ul liadmin‑ajax.php /li liWordPress REST APIs /li liPlugin‑specific endpoints /li /ul /li liInfrastructure that transforms exploit mechanics into signals usable by detection and prevention systems /li /ul h3Requirements /h3 h3Must Have /h3 ul liStrong background in security engineering or offensive security automation /li liHands‑on experience exploiting WordPress plugins, themes, or PHP applications /li liDeep understanding of: ul liPHP execution model and request lifecycle /li liWordPress internals (nonces, hooks, REST, admin flows) /li liHTTP semantics, sessions, cookies, and authorization /li /ul /li liProven ability to read, reason about, and exploit PHP source code /li liStrong Python engineering skills for building: ul liAutomation pipelines /li liAnalysis tooling /li liExploit frameworks /li /ul /li /ul h3Nice to Have /h3 ul liExploit framework usage experience like MSF, Core Impact,



Immunity Canvas /li liPrior experience using LLMs to automate exploit development: ul liPoC generation /li liWorkflow automation /li liPayload mutation or inference /li /ul /li liExperience with: ul liExecution traces or application‑level call graphs /li liFuzzing or vulnerability discovery pipelines /li /ul /li liFamiliarity with tools like WPScan, Nuclei, Metasploit, Burp /li liContributions to exploit tooling, frameworks, or security automation /li liPublic CVEs or PoCs (helpful but not required) /li /ul h3What This Role Is Not /h3 ul li❌ Manual pentesting or report‑driven consulting /li li❌ SOC or alert‑triage work /li li❌ Pure vulnerability research without automation /li /ul h3Why This Role Is Interesting /h3 ul liYou’ll work with real zero‑day attack telemetry, not just public CVEs /li liYou’ll build repeatable systems, not one‑off demos /li liLLMs are used pragmatically, as part of production pipelines /li liYour work directly shapes how real WordPress attacks are detected and stopped /li liHigh autonomy, deep technical ownership /li /ul h3Benefits /h3 h3What’s in it for you? /h3 ul liA focus on professional development /li liInteresting and challenging projects /li liFully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide /li liPaid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves /li liCompensation for private medical insurance /li liCo‑working and gym/sports reimbursement /liliBudget for education /li liThe opportunity to receive a reward for the most innovative idea that the company can patent /li /ul pBy applying for this position, you consent to the processing of your personal data as described in our Privacy Policy ( which provides detailed information on how we maintain and handle your data. /p /p #J-18808-Ljbffr

📌 Senior Security Engineer (WordPress & PHP) (remote-only, Europe)
🏢 CloudLinux
📍 Valencia

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer (wordpress & php) (remote-only, europe) / valencia

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer (wordpress & php) (remote-only, europe) / valencia