We are seeking an Offensive Security Engineer to identify, assess, and help remediate security weaknesses across applications, infrastructure,... Read more
We are seeking an Offensive Security Engineer to identify, assess, and help remediate security weaknesses across applications, infrastructure, networks, and cloud environments. You will plan and conduct authorised penetration tests, red-team exercises, vulnerability assessments, and security reviews, using a combination of manual techniques, automation, and industry-standard tooling. The role will involve emulating realistic attacker behaviour while maintaining a strong focus on safety, scope, evidence handling, and clear communication.
You will work closely with engineering, architecture, and security teams to validate vulnerabilities, demonstrate business impact, and provide practical recommendations that improve resilience. Responsibilities will include developing test plans and attack paths; researching emerging threats, exploits, and defensive techniques; creating scripts and tools to improve assessment efficiency; documenting findings and producing high-quality technical reports; and presenting results to both technical and non-technical stakeholders. You may also support threat modelling, secure design reviews, incident investigations, purple-team activities, and the continuous improvement of offensive security processes.
The successful candidate will have professional experience in penetration testing, red teaming, vulnerability research, or a closely related security discipline. Strong knowledge of common web, mobile, network, identity, container, and cloud attack techniques is expected, together with practical experience using tools such as Burp Suite, Nmap, Metasploit, or equivalent platforms. Familiarity with scripting or programming in Python, PowerShell, Bash, or similar languages is desirable. Relevant certifications such as OSCP, OSEP, CREST, or comparable qualifications are advantageous, but demonstrable hands-on ability is equally valued. You should be analytical, curious, ethical, and comfortable explaining complex issues clearly. The role requires sound judgement, attention to detail, a collaborative approach, and the ability to manage multiple assessments while meeting agreed deadlines and maintaining strict confidentiality.
Read lessLondon, England, United KingdomPermanent
We are seeking an Offensive Security Engineer to help identify, validate, and reduce security risks across applications, infrastructure,... Read more
We are seeking an Offensive Security Engineer to help identify, validate, and reduce security risks across applications, infrastructure, cloud environments, and corporate systems. You will work as part of a collaborative security function, conducting authorised penetration tests, red team exercises, vulnerability assessments, and adversary simulations. Your work will help strengthen defensive capabilities, improve detection and response, and provide practical recommendations that support secure business operations.
Key responsibilities include planning and executing engagements across web applications, APIs, networks, endpoints, wireless environments, containers, and cloud platforms. You will research emerging attack techniques, develop or adapt tools and proof-of-concept exploits, assess the potential impact of identified weaknesses, and document clear, actionable findings for both technical and non-technical audiences. You will also collaborate with engineering and operations teams to validate remediation, contribute to threat modelling and security architecture reviews, and help improve testing methodologies, procedures, and internal security standards. Where appropriate, you may support incident investigations, purple team activities, and the development of detection use cases.
The successful candidate will have professional experience in offensive security, penetration testing, red teaming, or a closely related discipline, together with a strong understanding of common attack paths and defensive controls. Practical experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Wireshark, or comparable technologies is expected, along with scripting or programming ability in languages such as Python, PowerShell, Bash, or JavaScript. Familiarity with cloud security, Active Directory, CI/CD environments, and secure software development practices is highly desirable. Relevant certifications such as OSCP, OSEP, CRTO, GXPN, or equivalent experience are welcomed. You should demonstrate sound judgement, meticulous documentation skills, professional integrity, and the ability to communicate technical risks clearly. All testing will be conducted within defined legal and ethical boundaries.
Read lessLondon, England, United KingdomPermanent
We are seeking a Senior Offensive Security Engineer to become the founding security hire and establish the foundations... Read more
We are seeking a Senior Offensive Security Engineer to become the founding security hire and establish the foundations of a high-impact security function. This is a hands-on role for an experienced security professional who enjoys working across product, infrastructure, cloud environments, and organisational processes. You will define and execute a practical offensive security programme, identify meaningful risks, and partner closely with engineering and leadership teams to improve the security of systems, applications, and customer-facing services.
Your responsibilities will include planning and conducting penetration tests, red-team exercises, vulnerability assessments, and threat-led reviews across web applications, APIs, cloud platforms, networks, and internal systems. You will develop repeatable methodologies for security testing, validate remediation, and communicate technical findings clearly to both technical and non-technical stakeholders. You will also help establish vulnerability management and security testing workflows, contribute to secure design reviews, support incident investigations when required, and build internal awareness of realistic attack paths and defensive priorities. As the first dedicated security hire, you will have significant influence over tooling, processes, priorities, and the long-term direction of the security programme.
We are looking for strong experience in offensive security, penetration testing, application security, or a closely related discipline, together with a solid understanding of modern attack techniques and defensive controls. Practical experience with cloud security, containerised environments, APIs, identity and access management, and common web vulnerabilities is highly valued. You should be comfortable scripting or developing tools in languages such as Python, JavaScript, Go, or Bash, and able to work independently in a fast-moving environment. Relevant certifications such as OSCP, OSEP, CREST, GPEN, or equivalent practical experience are welcome but not essential. Curiosity, sound judgement, clear communication, and the ability to turn complex findings into actionable improvements are essential.
Read lessLondon, England, United KingdomPermanent
We are seeking a skilled OT Cybersecurity Engineer specializing in Offensive Security, Security Assessments, and Security Testing to... Read more
We are seeking a skilled OT Cybersecurity Engineer specializing in Offensive Security, Security Assessments, and Security Testing to join our dynamic team. In this role, you will be responsible for conducting thorough security assessments of operational technology (OT) environments, identifying vulnerabilities, and recommending appropriate mitigation strategies. You will work closely with cross-functional teams to ensure that security measures are effectively implemented and aligned with industry best practices.
Your key responsibilities will include performing penetration testing and vulnerability assessments on OT systems, analyzing security controls and configurations, and developing detailed reports on findings with actionable recommendations. You will also participate in incident response activities, providing expertise to diagnose and remediate security incidents affecting OT environments. Collaboration with stakeholders to enhance security awareness and training within the organization will be crucial, as well as staying abreast of emerging threats and regulatory requirements impacting OT cybersecurity.
The ideal candidate will possess a strong background in cybersecurity, particularly in OT systems, along with relevant certifications such as CEH, OSCP, or GICSP. A deep understanding of network protocols, industrial control systems, and security frameworks is essential. You should have excellent analytical skills, a proactive mindset, and the ability to communicate technical information effectively to both technical and non-technical audiences. Join us in our mission to safeguard critical infrastructure and enhance the security posture of our OT environments.
Read lessNewport, Wales, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria