Company Description:
At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents.
We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.
As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.
In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.
Role Purpose:
In this role you will apply your leadership, innovative thinking, curiosity, and existing deep technical expertise to help Quorum Cyber close the distance between AI speed and efficiency, and human insight. Penetration testing, API and web application testing, and red teaming are delivered the traditional way: a skilled human, a scope document, a fixed number of days, a report at the end. The work is excellent, but it does not scale. Clients want continuous assurance; not la snapshot.
This role exists to change that. You will run real engagements and, from inside that work, build the agentic AI that takes them over stage by stage: reconnaissance, enumeration, attack-path discovery, exploitation of known vulnerability classes, evidence capture, triage, first-draft reporting. Each stage moves from:
- "A human does this" to...
- "An agent does this and a human signs it off"...
Preferred Qualifications
- Consultancy, MSSP, or managed service experience.
- Exposure to commercial autonomous or continuous testing platforms (XBOW, Horizon3.ai NodeZero, Pentera) as a user, evaluator, or competitor.
- Open-source contributions to offensive or agent tooling, published research, conference talks (DEF CON, Black Hat, BSides, AI Village), or a CVE record.
- Detection engineering experience, or familiarity with CREST, PCI DSS, CBEST/TIBER-EU, or DORA threat-led testing.
I Know I Have Done A Great Job If:
- Delivering high-quality network, web, API, cloud and red-team engagements that provide clear, actionable outcomes for clients.
- Building agentic systems that can safely complete defined stages of offensive testing with increasing levels of autonomy.
- Proving that the automation works through robust evaluation, testing and measurement of accuracy, coverage, reliability, cost and time saved.
- Convert successful automation into a repeatable, scalable, multi-tenant managed service with clear service levels and commercial value.
- Creating a clear understanding of where automation can be trusted, where human expertise is required and where an agent should not be used.
- Embedding appropriate safeguards, including scope validation, authorisation controls, kill switches, prohibited-action lists and complete audit trails.
- Raising the technical quality bar across the team and sharing your expertise in both offensive security and production-grade software engineering.
- Ultimately, you will have helped Quorum Cyber deliver continuous assurance at a scale that traditional penetration testing alone cannot achieve.
Other Information:
You will get an excellent salary, with world class benefits.
As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.
Our Commitment to Equality & Diversity:
"Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity."
We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation.
The information requested below is collected to help us meet our employment equity and reporting obligations, and to support our ongoing diversity and inclusion initiatives. Providing this information is entirely voluntary. It will not be shared with hiring managers and will not be used in any hiring decision. Declining to provide this information will not affect your application in any way.