We are seeking an Offensive Security Researcher to identify, investigate, and help mitigate security weaknesses across applications, infrastructure,... Read more
We are seeking an Offensive Security Researcher to identify, investigate, and help mitigate security weaknesses across applications, infrastructure, devices, and emerging technologies. You will conduct authorised penetration tests, vulnerability research, red-team activities, and security assessments to uncover realistic attack paths and evaluate the effectiveness of existing controls. The role involves researching new exploitation techniques, developing proof-of-concept code in controlled environments, analysing vulnerabilities, and translating technical findings into practical recommendations.
You will collaborate with software engineers, security specialists, infrastructure teams, and other stakeholders throughout the assessment lifecycle. Responsibilities include defining test objectives and scope, conducting reconnaissance, performing manual and automated testing, validating findings, documenting evidence, and presenting clear reports to both technical and non-technical audiences. You will also contribute to threat modelling, detection improvement, secure design reviews, and the development of internal tools, testing methodologies, and repeatable assessment processes. Where appropriate, you may support incident investigations and help reproduce real-world attack techniques for defensive testing.
The successful candidate will have demonstrable experience in offensive security, penetration testing, vulnerability research, or a closely related field. Strong knowledge of common web, API, cloud, network, operating system, and authentication vulnerabilities is expected, together with practical experience using tools such as Burp Suite, Nmap, Metasploit, or equivalent technologies. Programming or scripting skills in languages such as Python, PowerShell, JavaScript, or Go are desirable. You should be comfortable working independently, challenging assumptions, and explaining complex issues clearly. Professional certifications such as OSCP, OSEP, CREST, or equivalent experience are advantageous. All activities must be performed ethically, legally, and within clearly defined authorisation and confidentiality requirements.
Read lessLondon, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria