Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
27/07/2026
Full time
Position Overview We are seeking an experienced Cyber Security Analyst to join our cyber security team. The ideal candidate will have a minimum of 5 years cyber security experience and 3+ years in cloud security and/or application security. The candidate will be able to demonstrate a proven track record of protecting enterprise environments against evolving cyber threats. This role requires a technically proficient lead analyst who can lead security initiatives and ensure our cloud and application infrastructure maintains the highest security standards, whilst maintaining business partnerships across the group. Key Responsibilities Monitor and analyze security events across cloud and on premises environments using SIEM and security analytics tools Conduct thorough investigations of security incidents and provide detailed incident reports Develop and maintain incident response playbooks and procedures Experience with threat intelligence platforms and threat hunting Experience with security orchestration, automation and response (SOAR) platforms Understanding of data protection and encryption technologies Experience in regulated industries (financial services, healthcare, energy) Background in offensive security or penetration testing Design, implement, and maintain security controls across cloud platforms (AWS, Azure, GCP) Conduct cloud security assessments and architecture reviews Ensure compliance with cloud security best practices and frameworks (CIS Benchmarks, CSA CCM, NIST) Manage cloud native security tools including CSPM, CWPP, and cloud WAF solutions Implement and maintain identity and access management (IAM) policies and controls Lead cyber security programs and coordinate remediation efforts Collaborate with DevOps teams to integrate security into CI/CD pipelines (DevSecOps) Stay current with emerging threats, vulnerabilities, and security technologies Contribute to security awareness training and documentation Facilitate Supplier Management and security input into bids Support compliance initiatives (SOC2, ISO27001, PCI DSS, GDPR, etc.) Develop and enforce security policies, standards, and procedures Conduct security audits and risk assessments Maintain security documentation and metrics reporting Required Qualifications Minimum of 5 years cyber security experience 3+ years of hands on experience with cloud security (AWS, Azure, or GCP) Proven experience leading security incidents and coordinating response efforts Experience with security frameworks such as NIST CSF, MITRE ATT&CK, or Zero Trust architecture Technical Skills Strong expertise in cloud security services and tools (AWS & Azure) Experience working with SIEM platforms (Splunk, Sentinel) Understanding of network security, firewalls, IDS/IPS, and VPN technologies Familiarity with security testing tools (vulnerability scanners, SAST/DAST, penetration testing tools) Experience with endpoint detection and response (EDR) solutions Soft Skills Strong analytical and problem solving abilities Excellent written and verbal communication skills Ability to explain complex security concepts to technical and non technical audiences Leadership capabilities and experience mentoring team members Strong attention to detail and ability to work under pressure Collaborative mindset with cross functional teams Business partnering experience Certifications (one or more preferred) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Education: Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) Working Conditions Some flexibility for remote work - 2 days minimum in office (Edinburgh preferred) Equal Opportunities We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. We can support you with your application or through the hiring process if you have a physical or mental disability. You can find out more about your rights under the law at .
Penetration TesterApplylocations: London Office, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: JR102006Darktrace is a global leader in AI-driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI. Today, our customers depend on us to stay ahead. At Darktrace, we are energized by that responsibility. We work across teams and rally around a shared goal. We own outcomes end to end - step in, step up and see things through without waiting to be asked. We make decisions with urgency, say the hard thing, and hold each other to high standards with care and directness. We move first and learn fast anticipating where our customers are going next, continuously challenging ourselves. We invest in the skills, learning and opportunities that help people deliver at the level their roles demand, and reward the aptitude and curiosity to grow beyond them.Our Values: Own It Win as One Raise Our Bar Move First. Learn Fast Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in the London office. What will I be doing: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments, Simulating real-world attack scenarios to assess system and infrastructure resilience, Producing detailed technical reports and executive summaries for stakeholders, Collaborating with internal teams to validate findings and support remediation efforts, Staying up to date with emerging threats, vulnerabilities, and offensive security techniques. What experience do I need: To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills, The ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.As a growing business strengthening its governance and controls, this role plays a part in supporting high standards of integrity and accountability. Darktrace is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran or military status, or any other characteristic protected by applicable federal, state, or local law. Darktrace is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. If you require a reasonable accommodation to participate in the application or interview process, please contact your Talent Partner. Our Growth is Creating Great Opportunities! Our team is expanding, and we want to hire the most talented people we can. Continued success depends on it! Once you've had a chance to explore our current open positions, apply to the ones you feel suit you best and keep track of both your progress in the selection process, and new postings that might interest you! Thanks for your interest in working on our team!
27/07/2026
Full time
Penetration TesterApplylocations: London Office, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: JR102006Darktrace is a global leader in AI-driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI. Today, our customers depend on us to stay ahead. At Darktrace, we are energized by that responsibility. We work across teams and rally around a shared goal. We own outcomes end to end - step in, step up and see things through without waiting to be asked. We make decisions with urgency, say the hard thing, and hold each other to high standards with care and directness. We move first and learn fast anticipating where our customers are going next, continuously challenging ourselves. We invest in the skills, learning and opportunities that help people deliver at the level their roles demand, and reward the aptitude and curiosity to grow beyond them.Our Values: Own It Win as One Raise Our Bar Move First. Learn Fast Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in the London office. What will I be doing: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments, Simulating real-world attack scenarios to assess system and infrastructure resilience, Producing detailed technical reports and executive summaries for stakeholders, Collaborating with internal teams to validate findings and support remediation efforts, Staying up to date with emerging threats, vulnerabilities, and offensive security techniques. What experience do I need: To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills, The ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.As a growing business strengthening its governance and controls, this role plays a part in supporting high standards of integrity and accountability. Darktrace is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran or military status, or any other characteristic protected by applicable federal, state, or local law. Darktrace is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. If you require a reasonable accommodation to participate in the application or interview process, please contact your Talent Partner. Our Growth is Creating Great Opportunities! Our team is expanding, and we want to hire the most talented people we can. Continued success depends on it! Once you've had a chance to explore our current open positions, apply to the ones you feel suit you best and keep track of both your progress in the selection process, and new postings that might interest you! Thanks for your interest in working on our team!
The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure. ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox-an explosion of activity in a place that resists human presence-is why we exist. Our solution is autonomy. We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to. Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won't reappear, we'd like to talk. The role We're hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite - cloud infrastructure, applications, identity systems, and the autonomous products we field - spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way. CORE RESPONSIBILITIES Spot, evaluate, and rank security risks across our systems, products, and infrastructure - separating hypothetical worries from genuine threats to the business Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents Work alongside engineering, product, and operations teams as a trusted security partner - offering patterns, guidance, and guardrails rather than acting as a gatekeeper Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems Apply technical rigour to assurance work like audits, certifications, and customer security reviews - making sure our controls hold up in practice, not just on paper WHAT WE VALUE Deep, hands-on skill in one or two security domains - application security, cloud security, identity and access management, cryptography, detection and response, or platform security - backed by real evidence of impact An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title A risk-based approach - weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box Comfort juggling multiple teams and technical domains at once without losing quality or judgement A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces BONUS POINTS Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight Practical offensive security background - red teaming, penetration testing, or adversarial simulation - that shapes how you think about defensive design and threat modelling Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML A hand in building security programmes at scale - security champions networks, secure development lifecycle tooling, or company-wide risk frameworks A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance Experience working with classified data, government security frameworks, or cross-domain security requirements WHAT WE OFFER Competitive compensation Equity - meaningful options as an early employee at an early-stage company Real field exposure - travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick) Mission-driven culture - focus on impact, not hours logged Small team, real ownership - what you build matters and ships A note on who we want to hear from We're building for one of the most demanding environments on Earth and we believe diverse teams build more resilient systems. We actively welcome applications from people who are underrepresented - whether that's by gender, ethnicity, disability, or background.
26/07/2026
Full time
The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure. ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox-an explosion of activity in a place that resists human presence-is why we exist. Our solution is autonomy. We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to. Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won't reappear, we'd like to talk. The role We're hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite - cloud infrastructure, applications, identity systems, and the autonomous products we field - spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way. CORE RESPONSIBILITIES Spot, evaluate, and rank security risks across our systems, products, and infrastructure - separating hypothetical worries from genuine threats to the business Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents Work alongside engineering, product, and operations teams as a trusted security partner - offering patterns, guidance, and guardrails rather than acting as a gatekeeper Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems Apply technical rigour to assurance work like audits, certifications, and customer security reviews - making sure our controls hold up in practice, not just on paper WHAT WE VALUE Deep, hands-on skill in one or two security domains - application security, cloud security, identity and access management, cryptography, detection and response, or platform security - backed by real evidence of impact An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title A risk-based approach - weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box Comfort juggling multiple teams and technical domains at once without losing quality or judgement A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces BONUS POINTS Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight Practical offensive security background - red teaming, penetration testing, or adversarial simulation - that shapes how you think about defensive design and threat modelling Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML A hand in building security programmes at scale - security champions networks, secure development lifecycle tooling, or company-wide risk frameworks A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance Experience working with classified data, government security frameworks, or cross-domain security requirements WHAT WE OFFER Competitive compensation Equity - meaningful options as an early employee at an early-stage company Real field exposure - travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick) Mission-driven culture - focus on impact, not hours logged Small team, real ownership - what you build matters and ships A note on who we want to hear from We're building for one of the most demanding environments on Earth and we believe diverse teams build more resilient systems. We actively welcome applications from people who are underrepresented - whether that's by gender, ethnicity, disability, or background.
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
25/07/2026
Full time
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
25/07/2026
Full time
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
What is a Product Security Engineer? The hardest security problems we face aren't policy problems. They're engineering problems. Supply-chain operators. Prompt-injection campaigns. Financially-motivated attackers who turn a compromised dependency into production access. A well-organised control library doesn't move the needle there. Engineering does. A Product Security Engineer is a software engineer whose specialism is making those attack paths hard, expensive, or impossible. They write production code. They build detections that catch real attacks. They harden the systems other engineers depend on. They reason about specific adversaries with specific failure modes, not abstract categories. We're hiring someone to defend the regulated communications record of thousands of financial firms. The data is a real target. The work is engineering work. What you'll do MirrorWeb is a communications compliance supervision platform. We process hundreds of millions of events a month for thousands of financial-services firms worldwide. Customers trust us with their regulated record, which is a high-value target by any threat model. You'll work across the platform: web capture, largescale data pipelines, archiving, the customer-facing product, and the developer infrastructure all of it ships on. Engineer defence into the product Multi-tenant isolation that holds up to a determined insider. Encryption and key management you'd trust on your own data. IAM modelled as code, reviewed like code, with privilege escalation paths analysed before they ship. Application-layer hardening on the surfaces customers actually use. Security as a property of how the product is built, not a layer on top. Defend the supply chain The path of least resistance into modern SaaS runs through dependencies, build pipelines, and CI providers. You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build pipeline isolation, third party risk as runtime telemetry. When the next big supply chain incident lands, we should know within hours whether it touches us. Detect, respond, contain Runtime detection that catches what actually happens, not what a vendor template guesses might. Incident response codified as automation: containment, rotation, isolation, evidence capture. Forensics tooling that works on our stack. Adversary emulation against our real attack surface. The metric is mean time tocontain, not control coverage. Secure the agentic development surface Our engineers ship with AI agents in the loop on every change. That's leverage, and it's a new attack surface: prompt injection against agent harnesses, untrusted MCP server outputs, IAM scope creep on agent driven tooling, model and prompt supply chain. You'll own the security layer of our agent platform: sandbox boundaries, scoped credentials, provenance trails on agent shipped changes, secure by default code generation patterns. Lead the security craft inside engineering You embed inside the engineering team, not next to it. You pair with platform and product engineers on the work where threat models matter. You raise the bar through the tooling and patterns you ship, not through review gates. Compliance (SOC 2 today, more as we scale) falls out as evidence of real security work, not as a separate workstream. What we're looking for Essential Several years writing production software on AWS Security as your specialism, with a track record of defence systems you've shipped: detections that fired on real attacks, supply chain or build pipeline hardening, hardened product surfaces, IR automation that contained an incident. Be ready to talk about one in depth. Adversarial instincts. You follow supply chain incidents, read post mortems, and reason about real threat actors rather than abstract categories. Hands on experience using AI coding agents (Claude Code, Cursor, Codex, or similar) in production development workflows A clear model for how agent harnesses work (context, tool selection, trust boundaries), and where they break Threat modelling fluency. You can walk a system design and come out with what's worth defending and what isn't. An open communicator who raises concerns early and contributes in group discussions A high bar for resilient systems, in yourself and the people around you Desirable Detection engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply chain security: SLSA, sigstore / cosign, in toto, SBOM tooling used as a real control Cloud native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross account paths, KMS misuse, and the defences for each Incident response leadership end to end on a real incident (containment, eradication, forensics, write up) Authoring MCP servers or custom agent tools with a security lens Product Security Engineer Job Description 3 Familiarity with AGENTS.md / CLAUDE.md patterns and skill authoring Cryptography in practice: key management, KMS / HSM, encryption in use, sensible TLS Large scale data intensive systems: PostgreSQL, ClickHouse, Turbopuffer Observability tooling: Grafana, exception alerting, OpenTracing, Langfuse Regtech, fintech, or regulated record experience Scoping red team and pentest engagements (you commission and consume offensive testing, you don't run it day to day) What you won't find here A GRC role with an engineering title. A queue of CVE tickets to triage. A SOC analyst rota. A compliance automation role rebadged as security engineering. This role exists to defend our product against real adversaries, not to manage a control library. Why MirrorWeb? We're a communications compliance surveillance and supervision platform. We process hundreds of millions of events a month for firms worldwide, and we're scaling fast. Past the scrappy startup stage, still small enough that the work you do this week is in production next. Security Engineering, like Product Engineering, is a first class softwareengineering discipline here. Not an audit function bolted onto one. We protect the regulated record for thousands of financial firms. The threat is real, and the surface is interesting. Our Tech Stack Backend: Go, TypeScript, Python Frontend: React, TypeScript Cloud: AWS (Lambda, EC2, ECS Fargate, Aurora PostgreSQL/MySQL, S3, SQS/SNS), Vercel AI Infrastructure: AWS Bedrock, Langfuse, Vercel AI Gateway Infrastructure: Terraform, GitHub Actions Data: Large scale PostgreSQL, ClickHouse, Turbopuffer Agent tooling: Claude Code, Cursor, Linear, Codex, Sentry, Grafana Cloud, CodeRabbit, Incident.io
25/07/2026
Full time
What is a Product Security Engineer? The hardest security problems we face aren't policy problems. They're engineering problems. Supply-chain operators. Prompt-injection campaigns. Financially-motivated attackers who turn a compromised dependency into production access. A well-organised control library doesn't move the needle there. Engineering does. A Product Security Engineer is a software engineer whose specialism is making those attack paths hard, expensive, or impossible. They write production code. They build detections that catch real attacks. They harden the systems other engineers depend on. They reason about specific adversaries with specific failure modes, not abstract categories. We're hiring someone to defend the regulated communications record of thousands of financial firms. The data is a real target. The work is engineering work. What you'll do MirrorWeb is a communications compliance supervision platform. We process hundreds of millions of events a month for thousands of financial-services firms worldwide. Customers trust us with their regulated record, which is a high-value target by any threat model. You'll work across the platform: web capture, largescale data pipelines, archiving, the customer-facing product, and the developer infrastructure all of it ships on. Engineer defence into the product Multi-tenant isolation that holds up to a determined insider. Encryption and key management you'd trust on your own data. IAM modelled as code, reviewed like code, with privilege escalation paths analysed before they ship. Application-layer hardening on the surfaces customers actually use. Security as a property of how the product is built, not a layer on top. Defend the supply chain The path of least resistance into modern SaaS runs through dependencies, build pipelines, and CI providers. You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build pipeline isolation, third party risk as runtime telemetry. When the next big supply chain incident lands, we should know within hours whether it touches us. Detect, respond, contain Runtime detection that catches what actually happens, not what a vendor template guesses might. Incident response codified as automation: containment, rotation, isolation, evidence capture. Forensics tooling that works on our stack. Adversary emulation against our real attack surface. The metric is mean time tocontain, not control coverage. Secure the agentic development surface Our engineers ship with AI agents in the loop on every change. That's leverage, and it's a new attack surface: prompt injection against agent harnesses, untrusted MCP server outputs, IAM scope creep on agent driven tooling, model and prompt supply chain. You'll own the security layer of our agent platform: sandbox boundaries, scoped credentials, provenance trails on agent shipped changes, secure by default code generation patterns. Lead the security craft inside engineering You embed inside the engineering team, not next to it. You pair with platform and product engineers on the work where threat models matter. You raise the bar through the tooling and patterns you ship, not through review gates. Compliance (SOC 2 today, more as we scale) falls out as evidence of real security work, not as a separate workstream. What we're looking for Essential Several years writing production software on AWS Security as your specialism, with a track record of defence systems you've shipped: detections that fired on real attacks, supply chain or build pipeline hardening, hardened product surfaces, IR automation that contained an incident. Be ready to talk about one in depth. Adversarial instincts. You follow supply chain incidents, read post mortems, and reason about real threat actors rather than abstract categories. Hands on experience using AI coding agents (Claude Code, Cursor, Codex, or similar) in production development workflows A clear model for how agent harnesses work (context, tool selection, trust boundaries), and where they break Threat modelling fluency. You can walk a system design and come out with what's worth defending and what isn't. An open communicator who raises concerns early and contributes in group discussions A high bar for resilient systems, in yourself and the people around you Desirable Detection engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply chain security: SLSA, sigstore / cosign, in toto, SBOM tooling used as a real control Cloud native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross account paths, KMS misuse, and the defences for each Incident response leadership end to end on a real incident (containment, eradication, forensics, write up) Authoring MCP servers or custom agent tools with a security lens Product Security Engineer Job Description 3 Familiarity with AGENTS.md / CLAUDE.md patterns and skill authoring Cryptography in practice: key management, KMS / HSM, encryption in use, sensible TLS Large scale data intensive systems: PostgreSQL, ClickHouse, Turbopuffer Observability tooling: Grafana, exception alerting, OpenTracing, Langfuse Regtech, fintech, or regulated record experience Scoping red team and pentest engagements (you commission and consume offensive testing, you don't run it day to day) What you won't find here A GRC role with an engineering title. A queue of CVE tickets to triage. A SOC analyst rota. A compliance automation role rebadged as security engineering. This role exists to defend our product against real adversaries, not to manage a control library. Why MirrorWeb? We're a communications compliance surveillance and supervision platform. We process hundreds of millions of events a month for firms worldwide, and we're scaling fast. Past the scrappy startup stage, still small enough that the work you do this week is in production next. Security Engineering, like Product Engineering, is a first class softwareengineering discipline here. Not an audit function bolted onto one. We protect the regulated record for thousands of financial firms. The threat is real, and the surface is interesting. Our Tech Stack Backend: Go, TypeScript, Python Frontend: React, TypeScript Cloud: AWS (Lambda, EC2, ECS Fargate, Aurora PostgreSQL/MySQL, S3, SQS/SNS), Vercel AI Infrastructure: AWS Bedrock, Langfuse, Vercel AI Gateway Infrastructure: Terraform, GitHub Actions Data: Large scale PostgreSQL, ClickHouse, Turbopuffer Agent tooling: Claude Code, Cursor, Linear, Codex, Sentry, Grafana Cloud, CodeRabbit, Incident.io
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
23/07/2026
Full time
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
About the role Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be primarily responsible for performing application and network security assessments and will make recommendations to management on effective countermeasures. The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats. This position is to be located in either London or Nottingham. What you'll do Perform penetration testing of APIs, web applications, networks, and cloud services, as well as related applications and infrastructure. Assess Capital One's development practices and help drive corporate security standards. Help triage and test application responsible disclosure findings and newly disclosed vulnerabilities. Work with developers to improve the Software Development Lifecycle (SDLC) for applications. Present findings, risks and conclusions to technical and non-technical audiences. Collaborate closely with the business throughout remediation including influencing stakeholders and delivery teams on prioritization of security activities and issue remediation. Establish effective and productive relationships with colleagues across the Global Cyber organization and technology departments as well as the UK business. What we're looking for Information security experience in one or more of the following areas: red teaming, penetration testing, application security, or network security. Strong knowledge of Web, API and mobile application security testing frameworks and methodologies. Familiarity with penetration testing tools such as BurpSuite, OWASP Zap, SoapUI etc. Strong knowledge of application security best practices including OWASP Top 10. Should have a strong understanding of networking concepts, Windows, Linux and Mac operating systems, cloud and web application vulnerabilities and exploitation. Experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE) Technical knowledge in software engineering, system and network security, authentication and security protocols, cryptography, and network/web related protocols (e.g., TCP, UDP, HTTP, HTTPS) Any of these would be advantageous (but we'd still love to hear from you) Bachelors Degree or equivalent certification Security testing of cloud environments. We're invested with AWS but will consider those who have worked on any other major public cloud provider (Azure, GCP). Experience in offensive security tool development, customization or expansion. Ability to code comfortably in one or more interpreted languages (eg. Python, Bash, PowerShell, Perl, Ruby) and one or more compiled languages (eg. C, C++, C#, Golang, Rust, Java, Objective-C) Penetration testing experience with Internet of Things (IoT) devices, mobile applications, or code review. One or more of the following certifications (OSCP, OSCE, GPEN, GXPN, CRTO, CREST Certified Simulated Attack Manager)
23/07/2026
Full time
About the role Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be primarily responsible for performing application and network security assessments and will make recommendations to management on effective countermeasures. The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats. This position is to be located in either London or Nottingham. What you'll do Perform penetration testing of APIs, web applications, networks, and cloud services, as well as related applications and infrastructure. Assess Capital One's development practices and help drive corporate security standards. Help triage and test application responsible disclosure findings and newly disclosed vulnerabilities. Work with developers to improve the Software Development Lifecycle (SDLC) for applications. Present findings, risks and conclusions to technical and non-technical audiences. Collaborate closely with the business throughout remediation including influencing stakeholders and delivery teams on prioritization of security activities and issue remediation. Establish effective and productive relationships with colleagues across the Global Cyber organization and technology departments as well as the UK business. What we're looking for Information security experience in one or more of the following areas: red teaming, penetration testing, application security, or network security. Strong knowledge of Web, API and mobile application security testing frameworks and methodologies. Familiarity with penetration testing tools such as BurpSuite, OWASP Zap, SoapUI etc. Strong knowledge of application security best practices including OWASP Top 10. Should have a strong understanding of networking concepts, Windows, Linux and Mac operating systems, cloud and web application vulnerabilities and exploitation. Experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE) Technical knowledge in software engineering, system and network security, authentication and security protocols, cryptography, and network/web related protocols (e.g., TCP, UDP, HTTP, HTTPS) Any of these would be advantageous (but we'd still love to hear from you) Bachelors Degree or equivalent certification Security testing of cloud environments. We're invested with AWS but will consider those who have worked on any other major public cloud provider (Azure, GCP). Experience in offensive security tool development, customization or expansion. Ability to code comfortably in one or more interpreted languages (eg. Python, Bash, PowerShell, Perl, Ruby) and one or more compiled languages (eg. C, C++, C#, Golang, Rust, Java, Objective-C) Penetration testing experience with Internet of Things (IoT) devices, mobile applications, or code review. One or more of the following certifications (OSCP, OSCE, GPEN, GXPN, CRTO, CREST Certified Simulated Attack Manager)
About the role Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be primarily responsible for performing application and network security assessments and will make recommendations to management on effective countermeasures. The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats. This position is to be located in either London or Nottingham. What you'll do Perform penetration testing of APIs, web applications, networks, and cloud services, as well as related applications and infrastructure. Assess Capital One's development practices and help drive corporate security standards. Help triage and test application responsible disclosure findings and newly disclosed vulnerabilities. Work with developers to improve the Software Development Lifecycle (SDLC) for applications. Present findings, risks and conclusions to technical and non-technical audiences. Collaborate closely with the business throughout remediation including influencing stakeholders and delivery teams on prioritization of security activities and issue remediation. Establish effective and productive relationships with colleagues across the Global Cyber organization and technology departments as well as the UK business. What we're looking for Information security experience in one or more of the following areas: red teaming, penetration testing, application security, or network security. Strong knowledge of Web, API and mobile application security testing frameworks and methodologies. Familiarity with penetration testing tools such as BurpSuite, OWASP Zap, SoapUI etc. Strong knowledge of application security best practices including OWASP Top 10. Should have a strong understanding of networking concepts, Windows, Linux and Mac operating systems, cloud and web application vulnerabilities and exploitation. Experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE) Technical knowledge in software engineering, system and network security, authentication and security protocols, cryptography, and network/web related protocols (e.g., TCP, UDP, HTTP, HTTPS) Any of these would be advantageous (but we'd still love to hear from you) Bachelors Degree or equivalent certification Security testing of cloud environments. We're invested with AWS but will consider those who have worked on any other major public cloud provider (Azure, GCP). Experience in offensive security tool development, customization or expansion. Ability to code comfortably in one or more interpreted languages (eg. Python, Bash, PowerShell, Perl, Ruby) and one or more compiled languages (eg. C, C++, C#, Golang, Rust, Java, Objective-C) Penetration testing experience with Internet of Things (IoT) devices, mobile applications, or code review. One or more of the following certifications (OSCP, OSCE, GPEN, GXPN, CRTO, CREST Certified Simulated Attack Manager)
22/07/2026
Full time
About the role Capital One Offensive Security reduces cyber risk by uncovering vulnerabilities and weaknesses in the enterprise cyber environment through coordinated ethical hacking and penetration testing scenarios. This position works closely with team members to plan, coordinate, execute and report on sophisticated ethical hacking exercises, to identify cyber vulnerabilities and reduce the risk posture of enterprise systems. This role will be primarily responsible for performing application and network security assessments and will make recommendations to management on effective countermeasures. The successful candidate for this position will be part of an exciting and dynamic environment to build and deliver industry leading ethical hacking capabilities to continuously protect and defend Capital One brand, systems and data. Offensive Security is part of the Cyber Operations and Intelligence program and assists with identifying opportunities to enhance Capital One's information security posture against a broad range of cyber threats, and develop strategies to most effectively address the threats. This position is to be located in either London or Nottingham. What you'll do Perform penetration testing of APIs, web applications, networks, and cloud services, as well as related applications and infrastructure. Assess Capital One's development practices and help drive corporate security standards. Help triage and test application responsible disclosure findings and newly disclosed vulnerabilities. Work with developers to improve the Software Development Lifecycle (SDLC) for applications. Present findings, risks and conclusions to technical and non-technical audiences. Collaborate closely with the business throughout remediation including influencing stakeholders and delivery teams on prioritization of security activities and issue remediation. Establish effective and productive relationships with colleagues across the Global Cyber organization and technology departments as well as the UK business. What we're looking for Information security experience in one or more of the following areas: red teaming, penetration testing, application security, or network security. Strong knowledge of Web, API and mobile application security testing frameworks and methodologies. Familiarity with penetration testing tools such as BurpSuite, OWASP Zap, SoapUI etc. Strong knowledge of application security best practices including OWASP Top 10. Should have a strong understanding of networking concepts, Windows, Linux and Mac operating systems, cloud and web application vulnerabilities and exploitation. Experience with threat modeling concepts and frameworks (CVSS, MITRE ATT&CK, DREAD, or STRIDE) Technical knowledge in software engineering, system and network security, authentication and security protocols, cryptography, and network/web related protocols (e.g., TCP, UDP, HTTP, HTTPS) Any of these would be advantageous (but we'd still love to hear from you) Bachelors Degree or equivalent certification Security testing of cloud environments. We're invested with AWS but will consider those who have worked on any other major public cloud provider (Azure, GCP). Experience in offensive security tool development, customization or expansion. Ability to code comfortably in one or more interpreted languages (eg. Python, Bash, PowerShell, Perl, Ruby) and one or more compiled languages (eg. C, C++, C#, Golang, Rust, Java, Objective-C) Penetration testing experience with Internet of Things (IoT) devices, mobile applications, or code review. One or more of the following certifications (OSCP, OSCE, GPEN, GXPN, CRTO, CREST Certified Simulated Attack Manager)
iProov provides science based biometric solutions that enable the world's most security conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK - (Hybrid - Flexible) Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits As we continue to scale, we are looking for an experienced Red Team Engineer specialising in mobile application security (iOS and/or Android) to join our growing Red Team function. This role will focus on assessing and challenging the security of iProov's mobile SDKs, applications, and biometric identity flows, ensuring we remain resilient against increasingly sophisticated threats, including deepfakes, device compromise, and adversarial manipulation. You will play a critical role in proactively identifying weaknesses, simulating real world attacks, and strengthening our ability to detect and respond to threats across mobile environments. How you can make an impact Design and execute Red Team operations targeting mobile applications, SDKs, and biometric identity flows across iOS and Android Perform advanced mobile application penetration testing, including reverse engineering, runtime manipulation, and bypass techniques Emulator and instrumentation attacks Biometric spoofing and presentation attacks Mobile API abuse and session manipulation Identify vulnerabilities in mobile architectures, authentication flows, and client side controls Conduct research into emerging mobile threat actor tactics, techniques, and procedures (TTPs), particularly in biometric and identity systems Develop proof of concept exploits and tooling to replicate real world attack scenarios Produce clear, actionable reports with risk ranked remediation guidance for engineering and product teams Collaborate closely with mobile engineers, product, and security teams to translate findings into practical fixes Provide code level and architectural guidance to improve mobile application security Validate remediations and ensure vulnerabilities are effectively addressed Contribute to improving detection capabilities within iProov's security ecosystem (including iSOC) Mentor engineers on secure mobile development practices and threat modelling Ensure all activities align with rules of engagement, legal, and regulatory requirements What we would like to see from you 5+ years' experience in Red Teaming, penetration testing, or mobile security research Strong hands on expertise in mobile application security (iOS and/or Android) Experience with: Reverse engineering tools (e.g. Frida, Objection, Ghidra, Hopper, IDA Pro) Mobile testing frameworks and interception tools (e.g. Burp Suite, mitmproxy) Analysing mobile binaries (APK/IPA), obfuscation, and runtime protections Deep understanding of: Mobile OS internals (Android/iOS security models) Secure storage, keychains/keystores, and cryptographic implementations Authentication protocols and identity flows (OAuth, biometrics, session handling) Experience identifying and exploiting: Client side trust issues Certificate pinning bypasses Anti tampering and anti debugging controls Ability to build or customise tooling and scripts for mobile security testing Experience communicating complex technical findings to both technical and non technical audiences A passion for offensive security and creatively breaking systems to make them stronger Comfortable operating in a high growth, fast paced environment 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Benefit from personalized 1:1 career coaching with our in house Occupational Psychologist Award winning L&D platform with personal allocated training budgets Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well being sessions Vitality Health - a range of options available on this below Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted as member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for free Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers Our Culture & Recruitment Process At iProov, we're incredibly proud of the culture we've carefully curated. Our culture enables diverse thought, curiosity and innovation. Our team strives to do everything to the highest standard possible to achieve the remarkable. To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work. We firmly believe psychological safety is key to building and nurturing great teams. We're a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected. As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world. Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role. We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process. If you need an adjustment for a disability or any other reason during the hiring process, please send a request to .
20/07/2026
Full time
iProov provides science based biometric solutions that enable the world's most security conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK - (Hybrid - Flexible) Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits As we continue to scale, we are looking for an experienced Red Team Engineer specialising in mobile application security (iOS and/or Android) to join our growing Red Team function. This role will focus on assessing and challenging the security of iProov's mobile SDKs, applications, and biometric identity flows, ensuring we remain resilient against increasingly sophisticated threats, including deepfakes, device compromise, and adversarial manipulation. You will play a critical role in proactively identifying weaknesses, simulating real world attacks, and strengthening our ability to detect and respond to threats across mobile environments. How you can make an impact Design and execute Red Team operations targeting mobile applications, SDKs, and biometric identity flows across iOS and Android Perform advanced mobile application penetration testing, including reverse engineering, runtime manipulation, and bypass techniques Emulator and instrumentation attacks Biometric spoofing and presentation attacks Mobile API abuse and session manipulation Identify vulnerabilities in mobile architectures, authentication flows, and client side controls Conduct research into emerging mobile threat actor tactics, techniques, and procedures (TTPs), particularly in biometric and identity systems Develop proof of concept exploits and tooling to replicate real world attack scenarios Produce clear, actionable reports with risk ranked remediation guidance for engineering and product teams Collaborate closely with mobile engineers, product, and security teams to translate findings into practical fixes Provide code level and architectural guidance to improve mobile application security Validate remediations and ensure vulnerabilities are effectively addressed Contribute to improving detection capabilities within iProov's security ecosystem (including iSOC) Mentor engineers on secure mobile development practices and threat modelling Ensure all activities align with rules of engagement, legal, and regulatory requirements What we would like to see from you 5+ years' experience in Red Teaming, penetration testing, or mobile security research Strong hands on expertise in mobile application security (iOS and/or Android) Experience with: Reverse engineering tools (e.g. Frida, Objection, Ghidra, Hopper, IDA Pro) Mobile testing frameworks and interception tools (e.g. Burp Suite, mitmproxy) Analysing mobile binaries (APK/IPA), obfuscation, and runtime protections Deep understanding of: Mobile OS internals (Android/iOS security models) Secure storage, keychains/keystores, and cryptographic implementations Authentication protocols and identity flows (OAuth, biometrics, session handling) Experience identifying and exploiting: Client side trust issues Certificate pinning bypasses Anti tampering and anti debugging controls Ability to build or customise tooling and scripts for mobile security testing Experience communicating complex technical findings to both technical and non technical audiences A passion for offensive security and creatively breaking systems to make them stronger Comfortable operating in a high growth, fast paced environment 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Benefit from personalized 1:1 career coaching with our in house Occupational Psychologist Award winning L&D platform with personal allocated training budgets Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well being sessions Vitality Health - a range of options available on this below Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted as member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for free Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers Our Culture & Recruitment Process At iProov, we're incredibly proud of the culture we've carefully curated. Our culture enables diverse thought, curiosity and innovation. Our team strives to do everything to the highest standard possible to achieve the remarkable. To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work. We firmly believe psychological safety is key to building and nurturing great teams. We're a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected. As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world. Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role. We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process. If you need an adjustment for a disability or any other reason during the hiring process, please send a request to .
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for A bit about the role This role strengthens the Security Testing function by adding senior hands on capability across application security testing and targeted offensive security work. The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes. The role is weighted towards application security. Around 70 percent of the time will be spent on testing and assuring modern applications, APIs, backend services and cloud hosted workloads. Around 30 percent will be spent on offensive security activity that supports purple team development, adversary informed assessments and selected deeper technical work such as binary analysis, operating system exploitation and ATT&CK aligned testing. What you'll be doing Application security testing and assurance, around 70 percent Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms. Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers. Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys. Carry out security testing across cloud hosted and containerised application environments, ideally on AWS, where platform or configuration weaknesses affect application risk. Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first. Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage. Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs. Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery. Offensive security and purple team development, around 30 percent Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises. Support offensive security planning with Security Testing leadership and Cyber Defence so that simulations and adversary led assessments are tied to the maturity of defensive controls and operational priorities. Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services. Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments. Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases. Use knowledge of exploit chaining, post exploitation tradecraft, EDR and AV evasion concepts, and other offensive security techniques where they improve the realism and value of testing. Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need and the activity supports the wider security testing plan. Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements. Team contribution and capability building Act as a senior technical point of reference within the Security Testing function. Coach others in the team and help raise the standard of testing, reporting and technical analysis. Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale What experience we're looking for Essential Strong hands on experience in application penetration testing across web applications, APIs and service based architectures. Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns. Experience testing API gateways and Backend for Frontend layers, including authentication, authorisation, orchestration and data validation. Practical knowledge of cloud hosted applications, ideally on AWS, including containerised services and common platform security controls. Good understanding of modern web and mobile application patterns, enough to assess API consumption, session handling, trust boundaries and data exposure risk. Strong practical knowledge of Linux and Windows operating systems, including privilege escalation paths, host weaknesses, credential handling risks and exploitation approaches relevant to application environments. Working knowledge of binary exploitation and lower level vulnerability analysis where relevant to application, runtime or platform risk. Ability to carry out manual testing beyond automated tooling, including business logic weakness, exploit chaining and cross layer issues. Ability to explain findings clearly to both technical and non technical stakeholders and provide practical remediation advice. Experience shaping testing approach, methodology or standards rather than only delivering assessments. Desirable Experience with mobile application assessment. Experience with secure code review or code assisted testing. Experience with ATT&CK informed assessments, adversary emulation support or purple team exercises. Familiarity with EDR and AV evasion concepts, exploit development, vulnerability research or offensive tooling beyond standard application testing. Exposure to hardware, embedded or other specialist low level testing techniques. Experience in regulated, high availability or transaction critical environments. Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience. Experience with WAF technology and implementation About us At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet. Innovation - We pride ourselves on it! We're constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all. Giving back - Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK? Our aim is to have doubled this number by the end of the first 10-year license. Sustainability - Our aim is to become a net zero national lottery. We have 2030 targets to decarbonise our operations and energy. We've already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles. In addition, we're working with our value chain partners to develop a net zero target date. Empowering every voice - We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes. Our diverse teams are working hard to make all parts of The National Lottery inclusive - whether people play a game in a store or online, because when everyone can play, everyone wins. An inclusive reward offering with wellbeing at the centre At Allwyn, inclusion is built into how we care for our people. Our benefits and policies support colleagues and their families at every stage of life and career. By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed. Our people are more than colleagues - they're winners, driving positive change and making a real difference in communities. Benefits Company Bonus Scheme Matched pension contributions up to 8.5% 26 days annual leave + 2 Life Days (and bank holidays) Single Private Health Cover Complimentary Private Medical Income Protection Flexible Benefits - EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes. Enhanced Family Leave (Maternity, Paternity, Adoption) Wellness Allowance £500 Employee Assistance Programme Discounted Health Assessments Volunteering Days Matched Funding . click apply for full job details
19/07/2026
Full time
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for A bit about the role This role strengthens the Security Testing function by adding senior hands on capability across application security testing and targeted offensive security work. The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes. The role is weighted towards application security. Around 70 percent of the time will be spent on testing and assuring modern applications, APIs, backend services and cloud hosted workloads. Around 30 percent will be spent on offensive security activity that supports purple team development, adversary informed assessments and selected deeper technical work such as binary analysis, operating system exploitation and ATT&CK aligned testing. What you'll be doing Application security testing and assurance, around 70 percent Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms. Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers. Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys. Carry out security testing across cloud hosted and containerised application environments, ideally on AWS, where platform or configuration weaknesses affect application risk. Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first. Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage. Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs. Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery. Offensive security and purple team development, around 30 percent Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises. Support offensive security planning with Security Testing leadership and Cyber Defence so that simulations and adversary led assessments are tied to the maturity of defensive controls and operational priorities. Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services. Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments. Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases. Use knowledge of exploit chaining, post exploitation tradecraft, EDR and AV evasion concepts, and other offensive security techniques where they improve the realism and value of testing. Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need and the activity supports the wider security testing plan. Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements. Team contribution and capability building Act as a senior technical point of reference within the Security Testing function. Coach others in the team and help raise the standard of testing, reporting and technical analysis. Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale What experience we're looking for Essential Strong hands on experience in application penetration testing across web applications, APIs and service based architectures. Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns. Experience testing API gateways and Backend for Frontend layers, including authentication, authorisation, orchestration and data validation. Practical knowledge of cloud hosted applications, ideally on AWS, including containerised services and common platform security controls. Good understanding of modern web and mobile application patterns, enough to assess API consumption, session handling, trust boundaries and data exposure risk. Strong practical knowledge of Linux and Windows operating systems, including privilege escalation paths, host weaknesses, credential handling risks and exploitation approaches relevant to application environments. Working knowledge of binary exploitation and lower level vulnerability analysis where relevant to application, runtime or platform risk. Ability to carry out manual testing beyond automated tooling, including business logic weakness, exploit chaining and cross layer issues. Ability to explain findings clearly to both technical and non technical stakeholders and provide practical remediation advice. Experience shaping testing approach, methodology or standards rather than only delivering assessments. Desirable Experience with mobile application assessment. Experience with secure code review or code assisted testing. Experience with ATT&CK informed assessments, adversary emulation support or purple team exercises. Familiarity with EDR and AV evasion concepts, exploit development, vulnerability research or offensive tooling beyond standard application testing. Exposure to hardware, embedded or other specialist low level testing techniques. Experience in regulated, high availability or transaction critical environments. Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience. Experience with WAF technology and implementation About us At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet. Innovation - We pride ourselves on it! We're constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all. Giving back - Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK? Our aim is to have doubled this number by the end of the first 10-year license. Sustainability - Our aim is to become a net zero national lottery. We have 2030 targets to decarbonise our operations and energy. We've already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles. In addition, we're working with our value chain partners to develop a net zero target date. Empowering every voice - We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes. Our diverse teams are working hard to make all parts of The National Lottery inclusive - whether people play a game in a store or online, because when everyone can play, everyone wins. An inclusive reward offering with wellbeing at the centre At Allwyn, inclusion is built into how we care for our people. Our benefits and policies support colleagues and their families at every stage of life and career. By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed. Our people are more than colleagues - they're winners, driving positive change and making a real difference in communities. Benefits Company Bonus Scheme Matched pension contributions up to 8.5% 26 days annual leave + 2 Life Days (and bank holidays) Single Private Health Cover Complimentary Private Medical Income Protection Flexible Benefits - EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes. Enhanced Family Leave (Maternity, Paternity, Adoption) Wellness Allowance £500 Employee Assistance Programme Discounted Health Assessments Volunteering Days Matched Funding . click apply for full job details
About Freetrade Freetrade's mission is to become the default place to invest. Investing has been too complicated and expensive for too long, keeping millions from making the most of their savings. We're changing that. We're building our team and looking for people who are excited to reshape how our customers invest and grow their wealth. If you're driven by solving complex problems and building innovative products, you'll fit right in. 2026 is a big year for us. Last year, we announced a game changing deal to become part of the IG Group. We'll continue to operate as an independent business while gaining access to the resources and support of an established leader in the space. This year, we're accelerating our roadmap and taking our products to the next level. We're building new features like mutual funds, bonds, and family investment tools. We're also exploring how we can leverage AI to deliver an even better experience for our customers. At Freetrade, we're on a mission to make investing accessible to everyone. We operate in a highly regulated financial environment where security isn't just a function, it's a foundation. As we scale, we're looking for a sharp, motivated Security Intern to join our Security, Privacy and Infrastructure team for the summer and contribute to real, meaningful work from day one. About the Role This is a hands on internship, not a shadowing exercise. Whether you're a student, a recent graduate, or making your first move into security, you'll be embedded in the security team, working on operational tasks and a dedicated project designed to directly improve security at Freetrade. Your time will be split roughly 50/50 between supporting ongoing security operations and owning a scoped project with a clear outcome. You'll be supported throughout, with a defined onboarding plan, pre scoped tasks, daily check ins with your manager, and weekly visibility with the Director of SPI. What You'll Work On Remediation: Vulnerability triage and proof of concept testing, putting your offensive security and pentesting skills to practical use. GRC: Supporting vendor security review processes, assessing third party risk against our security standards. Automation: Assisting with AI tool adoption assessments, helping evaluate new tools for security and privacy risk. What You Bring Technical skills: Foundational knowledge of offensive security, pentesting, or bug bounty practices. Comfortable writing scripts or code in any language, Python preferred. Solid understanding of core security concepts and principles. Any hands on experience with vulnerability assessment tools or CTFs is a plus. Soft skills: Open to feedback and acts on it quickly. Fast learner who is comfortable with ambiguity and can ramp up independently. Clear and concise communicator, written and verbal. Reliable, organised, and takes ownership of their time and commitments. Collaborative and comfortable working across teams. Programme Structure Duration: 10 weeks Onboarding: Weeks 1 to 2, structured ramp plan with a pre defined task list so you hit the ground running. Split: 50% operational security work, 50% dedicated project to improve security at Freetrade. Support and Management Direct reporting line to the Security function lead. Daily check ins with your intern manager. Weekly skip level with the Director of SPI for feedback, alignment, and visibility. All work will be well scoped and documented before you start, no vague briefs. What's in it for You Paid internship with real responsibilities from day one. Work on live security challenges in a highly regulated fintech environment. Learn from an experienced security team with deep expertise across offensive security, privacy, and infrastructure. Build a portfolio of tangible, real world security work to accelerate your career. A genuine pathway to a full time role as part of Freetrade's 2027 headcount plan for high performers. Please note, applicants must be 18 years of age or older at the time of application and legally eligible to work in the relevant location. We are an Equal Opportunity employer committed to a diverse and representative team. Whatever your race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability - we want to hear from you. To find out more about how we look after your personal data when you apply for a job with us, please see our Recruitment Privacy Policy here. Please note we are not accepting agency CVs.
18/07/2026
Full time
About Freetrade Freetrade's mission is to become the default place to invest. Investing has been too complicated and expensive for too long, keeping millions from making the most of their savings. We're changing that. We're building our team and looking for people who are excited to reshape how our customers invest and grow their wealth. If you're driven by solving complex problems and building innovative products, you'll fit right in. 2026 is a big year for us. Last year, we announced a game changing deal to become part of the IG Group. We'll continue to operate as an independent business while gaining access to the resources and support of an established leader in the space. This year, we're accelerating our roadmap and taking our products to the next level. We're building new features like mutual funds, bonds, and family investment tools. We're also exploring how we can leverage AI to deliver an even better experience for our customers. At Freetrade, we're on a mission to make investing accessible to everyone. We operate in a highly regulated financial environment where security isn't just a function, it's a foundation. As we scale, we're looking for a sharp, motivated Security Intern to join our Security, Privacy and Infrastructure team for the summer and contribute to real, meaningful work from day one. About the Role This is a hands on internship, not a shadowing exercise. Whether you're a student, a recent graduate, or making your first move into security, you'll be embedded in the security team, working on operational tasks and a dedicated project designed to directly improve security at Freetrade. Your time will be split roughly 50/50 between supporting ongoing security operations and owning a scoped project with a clear outcome. You'll be supported throughout, with a defined onboarding plan, pre scoped tasks, daily check ins with your manager, and weekly visibility with the Director of SPI. What You'll Work On Remediation: Vulnerability triage and proof of concept testing, putting your offensive security and pentesting skills to practical use. GRC: Supporting vendor security review processes, assessing third party risk against our security standards. Automation: Assisting with AI tool adoption assessments, helping evaluate new tools for security and privacy risk. What You Bring Technical skills: Foundational knowledge of offensive security, pentesting, or bug bounty practices. Comfortable writing scripts or code in any language, Python preferred. Solid understanding of core security concepts and principles. Any hands on experience with vulnerability assessment tools or CTFs is a plus. Soft skills: Open to feedback and acts on it quickly. Fast learner who is comfortable with ambiguity and can ramp up independently. Clear and concise communicator, written and verbal. Reliable, organised, and takes ownership of their time and commitments. Collaborative and comfortable working across teams. Programme Structure Duration: 10 weeks Onboarding: Weeks 1 to 2, structured ramp plan with a pre defined task list so you hit the ground running. Split: 50% operational security work, 50% dedicated project to improve security at Freetrade. Support and Management Direct reporting line to the Security function lead. Daily check ins with your intern manager. Weekly skip level with the Director of SPI for feedback, alignment, and visibility. All work will be well scoped and documented before you start, no vague briefs. What's in it for You Paid internship with real responsibilities from day one. Work on live security challenges in a highly regulated fintech environment. Learn from an experienced security team with deep expertise across offensive security, privacy, and infrastructure. Build a portfolio of tangible, real world security work to accelerate your career. A genuine pathway to a full time role as part of Freetrade's 2027 headcount plan for high performers. Please note, applicants must be 18 years of age or older at the time of application and legally eligible to work in the relevant location. We are an Equal Opportunity employer committed to a diverse and representative team. Whatever your race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability - we want to hear from you. To find out more about how we look after your personal data when you apply for a job with us, please see our Recruitment Privacy Policy here. Please note we are not accepting agency CVs.
iProov provides science-based biometric solutions that enable the world's most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK - Hybrid Compensation: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits As we continue to scale and grow, we are looking for an experienced Red Team Engineer focused on web platforms to join our growing Red Team function and ensure our system continues to deliver outstanding levels of biometric security and performance globally. Our system has to provide the highest levels of biometric security to defend against the numerous and growing threats, while ensuring that we deliver outstanding performance for our millions of users worldwide. This is an exceptionally challenging problem as the nature of the threats evolves rapidly and there is a constant and growing need to track new threats, develop new defences and deploy in a timely and efficient manner. How you can make an impact Design and execute Red Team Operations against iProov's biometric platform, web apps, APIs, identity flows Strengthen the company's security posture through offensive security assessments including the identification and exploitation of vulnerabilities across the web platform Perform penetration testing and realistic security exercises to simulate various attack scenarios, to test and improve our detection and response capabilities, and to identify weaknesses in our infrastructure and products. Execute technical security assessments to identify risk, likelihood and impact an attacker may have on the System due to weak or missing controls Conduct research into real-world threat actor tactics, techniques, and procedures (TTP's) to develop proof of concept tools and replicate real world attacks. Present findings and operational work to groups in a clear and professional manner Produce clear, actionable reports, risk ranked remediation plans, and executive summaries aimed at product and engineering stakeholders. Collaborate with defenders, product teams, and leadership to translate findings into prioritized, actionable remediation and risk reduction. Bring insight into all aspects of modern security issues to our products and rapidly developing prototypes for mitigations. Mentor engineers in secure by design patterns, client side security, and secure API design. Work hand in hand with developers to propose pragmatic mitigations, remediation plans, and detection logic for vulnerabilities discovered during engagements. Translate findings into engineering friendly fix guidance (code level suggestions, configuration changes, library upgrades, secure design alternatives) and where required create reproducible PoCs that safely demonstrate impact. Validate and re test remediations and detection improvements (verify fixes, tune rules/signatures, confirm telemetry coverage). Integrate offensive findings into the SDLC: enable SCA (software composition analysis), SAST/DAST pipelines, pre merge checks, and secure CI/CD practices. Ensure all work follows company policies, rules of engagement (ROE), and legal/regulatory requirements. What we would like to see from you 5+ years of experience in ethical hacking, vulnerability research, exploit development, penetration testing or being a member of a red team, with significant focus on web application security. Strong hands on experience attacking and defending modern web tech stacks Proficient with offensive web toolsets (Burp Suite, OWASP ZAP) and experienced building extensions/scripts. Experience with developing and maintaining web focused tooling and automation (Burp extensions, custom scanners, authenticated API fuzzers, GraphQL mutation explorers, Puppeteer/Playwright scripts). Experience with source code reviewing for control flow and security flaws A passion for constructively break things Want to be part of an ambitious, high growth startup company Written and verbal communication skills in English 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Award winning L&D platform with personal allocated training budgets Benefit from personalized 1:1 career coaching with our in house Occupational Psychologist Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well being sessions Vitality Health - a range of options available on this below Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted based member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for free Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world.
17/07/2026
Full time
iProov provides science-based biometric solutions that enable the world's most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance. This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose. The Role Reports to: Head of Red Team Location: UK - Hybrid Compensation: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits As we continue to scale and grow, we are looking for an experienced Red Team Engineer focused on web platforms to join our growing Red Team function and ensure our system continues to deliver outstanding levels of biometric security and performance globally. Our system has to provide the highest levels of biometric security to defend against the numerous and growing threats, while ensuring that we deliver outstanding performance for our millions of users worldwide. This is an exceptionally challenging problem as the nature of the threats evolves rapidly and there is a constant and growing need to track new threats, develop new defences and deploy in a timely and efficient manner. How you can make an impact Design and execute Red Team Operations against iProov's biometric platform, web apps, APIs, identity flows Strengthen the company's security posture through offensive security assessments including the identification and exploitation of vulnerabilities across the web platform Perform penetration testing and realistic security exercises to simulate various attack scenarios, to test and improve our detection and response capabilities, and to identify weaknesses in our infrastructure and products. Execute technical security assessments to identify risk, likelihood and impact an attacker may have on the System due to weak or missing controls Conduct research into real-world threat actor tactics, techniques, and procedures (TTP's) to develop proof of concept tools and replicate real world attacks. Present findings and operational work to groups in a clear and professional manner Produce clear, actionable reports, risk ranked remediation plans, and executive summaries aimed at product and engineering stakeholders. Collaborate with defenders, product teams, and leadership to translate findings into prioritized, actionable remediation and risk reduction. Bring insight into all aspects of modern security issues to our products and rapidly developing prototypes for mitigations. Mentor engineers in secure by design patterns, client side security, and secure API design. Work hand in hand with developers to propose pragmatic mitigations, remediation plans, and detection logic for vulnerabilities discovered during engagements. Translate findings into engineering friendly fix guidance (code level suggestions, configuration changes, library upgrades, secure design alternatives) and where required create reproducible PoCs that safely demonstrate impact. Validate and re test remediations and detection improvements (verify fixes, tune rules/signatures, confirm telemetry coverage). Integrate offensive findings into the SDLC: enable SCA (software composition analysis), SAST/DAST pipelines, pre merge checks, and secure CI/CD practices. Ensure all work follows company policies, rules of engagement (ROE), and legal/regulatory requirements. What we would like to see from you 5+ years of experience in ethical hacking, vulnerability research, exploit development, penetration testing or being a member of a red team, with significant focus on web application security. Strong hands on experience attacking and defending modern web tech stacks Proficient with offensive web toolsets (Burp Suite, OWASP ZAP) and experienced building extensions/scripts. Experience with developing and maintaining web focused tooling and automation (Burp extensions, custom scanners, authenticated API fuzzers, GraphQL mutation explorers, Puppeteer/Playwright scripts). Experience with source code reviewing for control flow and security flaws A passion for constructively break things Want to be part of an ambitious, high growth startup company Written and verbal communication skills in English 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service) Growth Shares allocated after passing probation (6 months of service) Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme Nursery Sacrifice Scheme Work Overseas Perk - Work globally for up to 2 weeks Life Assurance SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family Award winning L&D platform with personal allocated training budgets Benefit from personalized 1:1 career coaching with our in house Occupational Psychologist Enhanced paid family leave Flexible hybrid working environment Free Barista Coffee/Tea, biscuits with fruit in the WeWork office Free access to WeWork discounts and free online well being sessions Vitality Health - a range of options available on this below Private Health cover including Dental, Optical, and Audiology 50% off monthly gym memberships Apple watches significantly discounted based member vitality status Half price trainers with Runners Need Weekly rewards - Free coffee with Café Nero Monthly rewards - Free Cinema ticket Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on members vitality status Amazon prime free months based on activity Up to 25% cashback at Waitrose when buying healthy foods 75% off stays at Champneys Health Spas Allen Carr's £299 no smoking programme for free Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace Discounts on Weight Watchers As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world.
Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Penetration Testing team, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. As part of the team, your primary responsibility will be performing hands on penetration testing of some of JPMC's most critical applications, platforms, and the perimeter. You will work with application developers to not only understand root cause and mitigate vulnerabilities, but also to identify where vulnerabilities can be identified earlier in the SDLC. Successful candidates are expected to demonstrate an eagerness to learn, the drive to excel, excellent technical knowledge of security concepts and proven expertise in penetration testing. Job responsibilities Design and execute testing and simulations - such as penetration tests and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics Required qualifications, capabilities, and skills 5+ years of experience in conducting manual penetration tests against a wide variety of applications and technologies including web, mobile and thick clients, internal and external facing infrastructures, cloud Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels Preferred qualifications, capabilities, and skills Experience in testing Public cloud environments like AWS, Azure and GCP with proficiency in at least one platform. Experience in reverse engineering standalone, thick client and mobile applications. Proficiency in security concepts for both Windows and Unix-like Operating Systems. Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.). Certifications like CREST (CRT, CCT), OSCP, OSCE, GXPN, GRE.
16/07/2026
Full time
Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement. As an Assessments & Exercises Vice President in the Penetration Testing team, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. As part of the team, your primary responsibility will be performing hands on penetration testing of some of JPMC's most critical applications, platforms, and the perimeter. You will work with application developers to not only understand root cause and mitigate vulnerabilities, but also to identify where vulnerabilities can be identified earlier in the SDLC. Successful candidates are expected to demonstrate an eagerness to learn, the drive to excel, excellent technical knowledge of security concepts and proven expertise in penetration testing. Job responsibilities Design and execute testing and simulations - such as penetration tests and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics Required qualifications, capabilities, and skills 5+ years of experience in conducting manual penetration tests against a wide variety of applications and technologies including web, mobile and thick clients, internal and external facing infrastructures, cloud Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels Preferred qualifications, capabilities, and skills Experience in testing Public cloud environments like AWS, Azure and GCP with proficiency in at least one platform. Experience in reverse engineering standalone, thick client and mobile applications. Proficiency in security concepts for both Windows and Unix-like Operating Systems. Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.). Certifications like CREST (CRT, CCT), OSCP, OSCE, GXPN, GRE.
Senior Cyber Security Engineer Ref. 3790 Department Technology Roles Location(s) Greater Manchester, London Salary: £64,005 for Manchester and £66,332 for London In addition, there will be opportunities to qualify for additional allowances and a skills related payment under the Government Digital and Data Profession Capability Framework (GDDPCF), formerly the (DDaT) Digital, Data and Technology Capability Framework. Flexible working: We support full time, part time, compressed hours, and other flexible working patterns. We recognise the importance of achieving a positive work home balance and will work with colleagues to consider flexible working arrangements where possible, taking individual circumstances and business needs into account. Some homeworking opportunities may be available; however, this role is primarily office based due to the sensitive nature of the work, and home working is not guaranteed. About us MI5 keeps the country safe from serious threats like terrorism and attempts by states to harm the UK, its people and way of life. We carry out investigations by obtaining, analysing, and assessing intelligence, and then work with a range of partners including MI6 and GCHQ to disrupt these threats. Through our protective security arm, we provide advice and guidance to government, businesses and other organisations about how to keep themselves safe. A role in MI5 means you'll do unique and challenging work in a supportive and encouraging environment, making a real difference to UK national security. The role As a Senior Cyber Security Engineer, you'll play a central role in protecting the organisation's digital products, embedding security into how systems are designed and built. The role combines engineering and security expertise, applying practical skills to identify weaknesses, validate controls and help teams deliver secure, resilient systems from the outset. Working within a highly collaborative environment, you'll contribute to organisation wide security capability, tackling complex challenges across a diverse and evolving technology landscape. Early engagement in the development lifecycle is vital, shaping design decisions, influencing architecture and ensuring security is integrated into modern engineering practices. This role combines technical depth with real influence. Threat modelling, vulnerability assessment and security testing form a core part of the work, applying an adversarial mindset to uncover risks. Just as important is working directly with engineers, architects and stakeholders to resolve those risks, improve practices and raise the organisation's overall security maturity. You'll take a "purple team" approach, combining elements of red team testing and defensive security - identifying vulnerabilities and working with teams to fix them, building better, more secure systems. The role also extends to the wider direction of security engineering: supporting less experienced colleagues, influencing technical decisions and helping stakeholders understand risk, trade offs and priorities. With a high degree of autonomy, you'll take ownership of complex problems and play a key role in how security is delivered across the organisation. About you You'll bring practical experience in a security focused role, such as cyber security engineering, penetration testing or a closely related technical discipline. This could be supported by a STEM degree with relevant experience, or a technical role with a strong security focus. Experience with real world systems is essential, identifying and solving security issues, alongside a solid understanding of core security principles such as Secure by Design. You'll have applied techniques such as threat modelling, vulnerability assessment or security testing, and be confident thinking critically about how systems can be exploited and secured. You communicate clearly with both technical and non technical stakeholders and are comfortable working collaboratively to resolve issues. Curious and pragmatic, you're motivated to keep learning and apply your expertise to complex, high impact challenges. Training and development From the moment you join, you'll be supported to develop your expertise in cyber security through a blend of hands on experience and structured learning. You'll work closely with experienced colleagues across a range of security challenges, gaining exposure to different systems, tools and approaches. A wide range of development opportunities is available, including on demand learning platforms, virtual cyber ranges and formal training aligned to your role. There is also support available to achieve industry recognised certifications, such as SANS (The Sans Institute), GIAC (Global Information Assurance Certification), CISSP (Certified Information Systems Security Professional Qualification) or Offensive Security qualifications, alongside opportunities to attend UK based and international security conferences. As you grow in the role, you'll take on increasingly detailed work, building both technical depth and influence, with the support of your team, mentoring opportunities and exposure to real world threat intelligence. Rewards and benefits You'll receive a starting salary from £64,005 to £66,332, depending on location, plus other benefits including: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days public and privilege holidays opportunities to be recognised through our employee performance scheme dedicated development budget interest free season ticket loan cycle to work scheme facilities such as a gym, restaurant, and on site coffee bars (at some locations) paid parental and adoption leave Equal opportunities At MI5 diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Find out more about our culture, working environment and diversity on our website. We're Disability Confident MI5 is proud to have achieved Leader status within the Department for Work and Pensions Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain, and develop disabled people. Being Disability Confident, we aim to offer a fair and proportionate number of person to person interviews to any candidate who self identifies as disabled and meets the essential criteria for the role. This is our 'Offer of Interview' (OOI). To secure an interview for this vacancy, the essential criteria (in order of application process) are: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation Demonstrate practical familiarity in a security focused role - to be assessed at application sift Demonstrate the ability to identify and solve real world security issues including applying threat modelling, vulnerability assessment, or security testing, and a solid understanding of Secure by Design principles - to be assessed at application sift There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see our website for information on reasonable adjustments we can offer.
16/07/2026
Full time
Senior Cyber Security Engineer Ref. 3790 Department Technology Roles Location(s) Greater Manchester, London Salary: £64,005 for Manchester and £66,332 for London In addition, there will be opportunities to qualify for additional allowances and a skills related payment under the Government Digital and Data Profession Capability Framework (GDDPCF), formerly the (DDaT) Digital, Data and Technology Capability Framework. Flexible working: We support full time, part time, compressed hours, and other flexible working patterns. We recognise the importance of achieving a positive work home balance and will work with colleagues to consider flexible working arrangements where possible, taking individual circumstances and business needs into account. Some homeworking opportunities may be available; however, this role is primarily office based due to the sensitive nature of the work, and home working is not guaranteed. About us MI5 keeps the country safe from serious threats like terrorism and attempts by states to harm the UK, its people and way of life. We carry out investigations by obtaining, analysing, and assessing intelligence, and then work with a range of partners including MI6 and GCHQ to disrupt these threats. Through our protective security arm, we provide advice and guidance to government, businesses and other organisations about how to keep themselves safe. A role in MI5 means you'll do unique and challenging work in a supportive and encouraging environment, making a real difference to UK national security. The role As a Senior Cyber Security Engineer, you'll play a central role in protecting the organisation's digital products, embedding security into how systems are designed and built. The role combines engineering and security expertise, applying practical skills to identify weaknesses, validate controls and help teams deliver secure, resilient systems from the outset. Working within a highly collaborative environment, you'll contribute to organisation wide security capability, tackling complex challenges across a diverse and evolving technology landscape. Early engagement in the development lifecycle is vital, shaping design decisions, influencing architecture and ensuring security is integrated into modern engineering practices. This role combines technical depth with real influence. Threat modelling, vulnerability assessment and security testing form a core part of the work, applying an adversarial mindset to uncover risks. Just as important is working directly with engineers, architects and stakeholders to resolve those risks, improve practices and raise the organisation's overall security maturity. You'll take a "purple team" approach, combining elements of red team testing and defensive security - identifying vulnerabilities and working with teams to fix them, building better, more secure systems. The role also extends to the wider direction of security engineering: supporting less experienced colleagues, influencing technical decisions and helping stakeholders understand risk, trade offs and priorities. With a high degree of autonomy, you'll take ownership of complex problems and play a key role in how security is delivered across the organisation. About you You'll bring practical experience in a security focused role, such as cyber security engineering, penetration testing or a closely related technical discipline. This could be supported by a STEM degree with relevant experience, or a technical role with a strong security focus. Experience with real world systems is essential, identifying and solving security issues, alongside a solid understanding of core security principles such as Secure by Design. You'll have applied techniques such as threat modelling, vulnerability assessment or security testing, and be confident thinking critically about how systems can be exploited and secured. You communicate clearly with both technical and non technical stakeholders and are comfortable working collaboratively to resolve issues. Curious and pragmatic, you're motivated to keep learning and apply your expertise to complex, high impact challenges. Training and development From the moment you join, you'll be supported to develop your expertise in cyber security through a blend of hands on experience and structured learning. You'll work closely with experienced colleagues across a range of security challenges, gaining exposure to different systems, tools and approaches. A wide range of development opportunities is available, including on demand learning platforms, virtual cyber ranges and formal training aligned to your role. There is also support available to achieve industry recognised certifications, such as SANS (The Sans Institute), GIAC (Global Information Assurance Certification), CISSP (Certified Information Systems Security Professional Qualification) or Offensive Security qualifications, alongside opportunities to attend UK based and international security conferences. As you grow in the role, you'll take on increasingly detailed work, building both technical depth and influence, with the support of your team, mentoring opportunities and exposure to real world threat intelligence. Rewards and benefits You'll receive a starting salary from £64,005 to £66,332, depending on location, plus other benefits including: 25 Days Annual Leave automatically rising to 30 days after 5 years' service, and an additional 10.5 days public and privilege holidays opportunities to be recognised through our employee performance scheme dedicated development budget interest free season ticket loan cycle to work scheme facilities such as a gym, restaurant, and on site coffee bars (at some locations) paid parental and adoption leave Equal opportunities At MI5 diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Find out more about our culture, working environment and diversity on our website. We're Disability Confident MI5 is proud to have achieved Leader status within the Department for Work and Pensions Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain, and develop disabled people. Being Disability Confident, we aim to offer a fair and proportionate number of person to person interviews to any candidate who self identifies as disabled and meets the essential criteria for the role. This is our 'Offer of Interview' (OOI). To secure an interview for this vacancy, the essential criteria (in order of application process) are: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation Demonstrate practical familiarity in a security focused role - to be assessed at application sift Demonstrate the ability to identify and solve real world security issues including applying threat modelling, vulnerability assessment, or security testing, and a solid understanding of Secure by Design principles - to be assessed at application sift There is a wide range of extra support available throughout the recruitment process to enable you to do your best, see our website for information on reasonable adjustments we can offer.
Technical Vulnerability Management Engineer (Offensive Security/Penetration Testing) London (3 days onsite / 2 days remote) Up-to 450 per day PAYE equivalent (Inside IR35) Initial 3 months with strong expectation of long-term extension To start ASAP About the role We're supporting one of the world's leading technology companies in hiring a contractor to join their Information Security Assurance team. This is an excellent opportunity for someone with a background in penetration testing or offensive security who enjoys understanding how vulnerabilities work and helping engineering teams reduce security risk at scale. Rather than carrying out traditional penetration testing engagements, you'll analyse newly disclosed vulnerabilities, assess their potential impact across a large enterprise environment and work with internal stakeholders to drive remediation. Responsibilities Analyse newly published CVEs and security advisories to understand technical impact and exploitability. Assess the potential impact of vulnerabilities across enterprise infrastructure and systems. Identify affected assets using internal tooling and vulnerability data sources. Work closely with engineering and system owners to prioritise and coordinate remediation activities. Write Python, Bash or similar scripts to automate repetitive analysis and operational tasks. Produce clear technical documentation , vulnerability assessments and remediation guidance. Support ongoing improvements to vulnerability management processes. About you You'll ideally have experience in a technical security role such as Penetration Testing, Offensive Security, Application Security or Vulnerability Management , together with: Hands-on experience in penetration testing or offensive security. Good understanding of how vulnerabilities are discovered, exploited and remediated. Strong Linux knowledge and confidence working from the command line. Scripting experience using Python, Bash or similar. Familiarity with CVE, CVSS, NVD and common vulnerability management practices. A methodical approach to analysing technical risk and prioritising remediation. Strong communication skills with the ability to explain technical issues to non-security stakeholders. Desirable Experience with one or more of the following would be beneficial: Vulnerability management platforms ( Tenable, Qualys, Rapid7, Microsoft Defender VM or similar). OWASP Top 10. Security automation . Enterprise vulnerability management . Cloud infrastructure security . Relevant certifications such as OSCP, CREST CRT, GPEN or similar .
16/07/2026
Contractor
Technical Vulnerability Management Engineer (Offensive Security/Penetration Testing) London (3 days onsite / 2 days remote) Up-to 450 per day PAYE equivalent (Inside IR35) Initial 3 months with strong expectation of long-term extension To start ASAP About the role We're supporting one of the world's leading technology companies in hiring a contractor to join their Information Security Assurance team. This is an excellent opportunity for someone with a background in penetration testing or offensive security who enjoys understanding how vulnerabilities work and helping engineering teams reduce security risk at scale. Rather than carrying out traditional penetration testing engagements, you'll analyse newly disclosed vulnerabilities, assess their potential impact across a large enterprise environment and work with internal stakeholders to drive remediation. Responsibilities Analyse newly published CVEs and security advisories to understand technical impact and exploitability. Assess the potential impact of vulnerabilities across enterprise infrastructure and systems. Identify affected assets using internal tooling and vulnerability data sources. Work closely with engineering and system owners to prioritise and coordinate remediation activities. Write Python, Bash or similar scripts to automate repetitive analysis and operational tasks. Produce clear technical documentation , vulnerability assessments and remediation guidance. Support ongoing improvements to vulnerability management processes. About you You'll ideally have experience in a technical security role such as Penetration Testing, Offensive Security, Application Security or Vulnerability Management , together with: Hands-on experience in penetration testing or offensive security. Good understanding of how vulnerabilities are discovered, exploited and remediated. Strong Linux knowledge and confidence working from the command line. Scripting experience using Python, Bash or similar. Familiarity with CVE, CVSS, NVD and common vulnerability management practices. A methodical approach to analysing technical risk and prioritising remediation. Strong communication skills with the ability to explain technical issues to non-security stakeholders. Desirable Experience with one or more of the following would be beneficial: Vulnerability management platforms ( Tenable, Qualys, Rapid7, Microsoft Defender VM or similar). OWASP Top 10. Security automation . Enterprise vulnerability management . Cloud infrastructure security . Relevant certifications such as OSCP, CREST CRT, GPEN or similar .
Ready to identify vulnerabilities before attackers do? Join a cybersecurity services provider recognised for delivering penetration testing, advisory, and compliance solutions to enterprises. With a reputation for technical expertise and trusted delivery, the organisation continues to help businesses strengthen resilience and protect critical systems against evolving threats. The team is hiring a Penetration Tester to conduct security assessments across applications, networks, and infrastructure. The role will focus on simulating real-world attacks, identifying weaknesses, and providing actionable recommendations to improve overall security posture. Turn offensive skills into defensive strength. Apply now! Responsibilities Conduct hands-on penetration testing for a range of clients Provide expert guidance on Cyber Essentials assessments and compliance Help to build a sustainable and effective Penetration Testing team Work closely with senior management and progress into a leadership role over time Skills / Must have 2-4 years of penetration testing experience CREST certification Knowledge and experience with Cyber Essentials Ability to work independently and contribute to the growth of a cybersecurity practice Strong communication skills to engage with clients Ambition to take on a leadership role and contribute to business growth Benefits Flexibility to work remotely or from our Sheffield office Work with a range of industry sectors - tech, finance and professional sports teams Supportive environment for professional development and certification renewal Salary £60,000 - £75,000 base salary per annum
06/07/2026
Full time
Ready to identify vulnerabilities before attackers do? Join a cybersecurity services provider recognised for delivering penetration testing, advisory, and compliance solutions to enterprises. With a reputation for technical expertise and trusted delivery, the organisation continues to help businesses strengthen resilience and protect critical systems against evolving threats. The team is hiring a Penetration Tester to conduct security assessments across applications, networks, and infrastructure. The role will focus on simulating real-world attacks, identifying weaknesses, and providing actionable recommendations to improve overall security posture. Turn offensive skills into defensive strength. Apply now! Responsibilities Conduct hands-on penetration testing for a range of clients Provide expert guidance on Cyber Essentials assessments and compliance Help to build a sustainable and effective Penetration Testing team Work closely with senior management and progress into a leadership role over time Skills / Must have 2-4 years of penetration testing experience CREST certification Knowledge and experience with Cyber Essentials Ability to work independently and contribute to the growth of a cybersecurity practice Strong communication skills to engage with clients Ambition to take on a leadership role and contribute to business growth Benefits Flexibility to work remotely or from our Sheffield office Work with a range of industry sectors - tech, finance and professional sports teams Supportive environment for professional development and certification renewal Salary £60,000 - £75,000 base salary per annum