armadin logo

Attack Operations Center Analyst

Armadin

Remote

Other

Posted 2 hours ago

midremote

Hiring context

✅ Verified open on Sep 16, 2026 · posted today

📈 16 open roles at Armadin as of Sep 14, 2026: 2 security-specific, 44% remote, 6% show pay (+0 vs last week).

Job Description

About Us

At Armadin, we're a group of engineers, researchers, and hackers on a mission to redefine what proactive security can do in the AI era. Cyberattacks are becoming autonomous and relentless and we believe defending against threats before they materialize is one of the most powerful ways to protect the institutions the world depends on.

We're building autonomous proactive security from the ground up, reinforcing the tradecraft of elite red teamers into purpose-built security models and agents that discover risk and remediate it before organizations are breached.

Led by Kevin Mandia, founder of Mandiant ($5.4B exit to Google), our team brings together researchers and engineers from Google, xAI, Meta, Stanford, and MIT to reinvent security for an adversary that never sleeps.

Role Overview

A successful Attacker Operations Center (AOC) Analyst at Armadin should possess an understanding of both offensive information security and artificial intelligence workflows. They should understand fundamental concepts such as web application architecture, authentication mechanisms, and network security, and be able to learn advanced concepts such as AI safety constraints, attacker data classification, and context-driven exploit validation. This is not a traditional "monitor the dashboard" defensive SOC job; this career is technical, offensive-focused, and challenging, with opportunities to work at the cutting edge of AI-driven red teaming alongside world-class red teamers. A typical shift could involve reviewing an AI attacker's safety disengagement during a complex web application test, bypassing a sophisticated CAPTCHA to unblock an automated attack path, or providing the missing contextual judgment an AI needs to exploit a deep vulnerability. If you can rapidly evaluate applications, make critical safety judgments on the fly, think like a red teamer, and feed data back to engineering teams to improve AI models, then you’re the type of analyst we’re looking for.

As an Armadin AOC Analyst, you’ll get hands-on experience acting as the "human-in-the-loop" for complex security problems on a daily basis. We help our clients protect their most sensitive data through real-world, AI-driven scenario testing. The objective doesn’t end at launching the automated attacker; that is only the start.

What You’ll Do

  • Perform Disengagement Validation by reviewing AI attacker decisions to ensure each proposed action is appropriate and safe given the specific application context.

  • Unblock AI authentication hurdles by providing necessary context, solving CAPTCHAs, or utilizing alternative avenues to establish access.

  • Guide the AI during the reconnaissance phase and ensure Attack Data Classification is accurate and actionable.

  • Serve as a critical feedback contributor, feeding your tactical decisions back into the system to help safety engineers calibrate models, reduce false positives, and maintain rigorous safety guarantees.

  • Navigate and maintain deep context across multiple simultaneous client engagements.

What You’ll Bring

  • 1+ years’ experience, via internships, classes, projects, or professional work, in at least one of the following:

    • Web application or network penetration testing

    • Security Operations Center (SOC) or tactical monitoring environments

    • Manual interaction with complex authentication flows, APIs, or session management

    • Evaluating or auditing automated security tools and vulnerability scanners

  • Ability to rapidly context-switch between multiple live engagements while maintaining strict attention to detail and safety protocols.

  • Must be eligible to work in Mexico without sponsorship.

Even Better With

  • Prior experience working alongside Artificial Intelligence, Machine Learning models, or automated offensive security frameworks.

  • Experience in security competitions, CTFs, and/or testing platforms such as Hack the Box, TryHackMe, PortSwigger Web Security Academy, etc.

  • Strong technical acumen and the ability to quickly assimilate new information to make time-sensitive "human-in-the-loop" judgments.

  • Ability to document and explain technical decisions clearly to internal safety and engineering teams.

Location

Remote in Mexico


Benefits & Perks

🏥 Full Health, Dental, & Vision Coverage

📈 Meaningful Equity Ownership

🥙 In-Office Meals

✂️ Haircuts at the Office
🎉 Company Sponsored Conferences & Events

💸 401(k), HSA, and FSA Plans

🌴 Flexible PTO

 
Share:WhatsAppLinkedIn

Not ready to apply?

Get weekly alerts for new cybersecurity jobs:

Share your cyber salary

Anonymous. No login, no name. Helps everyone see real pay by role and country.

Hiring for a role like this?

Reach cybersecurity professionals browsing the board - your listing goes live instantly.

Post a job →

Related cybersecurity jobs

Stay ahead of the curve. Get new infosec jobs in your inbox.