Offensive Security Engineering Manager
Job Description
[Up to c. £300k Comp Package | Office-Led Working]
Role Overview
We’re representing an elite quantitative technology firm with a progressive AI strategy, looking for an experienced offensive-security leader to build and evolve its internal penetration-testing capability across critical research, engineering, infrastructure and corporate systems. This is a hands-on leadership role focused on moving the function beyond reactive, request-driven assessments towards proactive, threat-led testing, continuous attack-path validation and measurable security assurance. You will shape the strategy, grow the team and work closely with security engineering, incident response and technology teams to ensure weaknesses are understood, prioritised and driven through to effective remediation...
Key Responsibilities
- Lead, coach and develop a team of offensive-security engineers and penetration testers, setting clear technical standards, performance expectations and development plans
- Define and deliver a firm-wide offensive-security strategy covering critical applications, internal networks, APIs, cloud platforms, infrastructure, identity systems and emerging technology environments
- Shift the testing programme from end-of-cycle, scope-based assessments towards proactive testing informed by credible external threats, attack paths and the firm’s evolving technology landscape
- Own testing intake, prioritisation, planning and resourcing, balancing recurring assurance activity with new services, significant changes and high-risk engineering initiatives
- Establish mature methodologies for scoping, rules of engagement, safe exploitation, attack-chain validation and evidence-based assessment of control effectiveness
- Build continuous purple-team exercises with detection, response and security-engineering teams to test monitoring coverage, response capability and resilience against realistic adversary behaviours
- Introduce automation, breach-and-attack simulation, adversary-emulation tooling and AI-assisted testing approaches to extend coverage beyond traditional point-in-time assessments
- Maintain ownership of identified weaknesses through remediation, influencing engineering teams, validating fixes and ensuring systemic issues are addressed rather than closed as isolated findings
What You’ll Bring…
- Around 8-15 years of experience across penetration testing, red teaming, adversary emulation or offensive-security engineering, including meaningful responsibility for leading people or technical programmes
- Strong recent hands-on capability across internal networks, web applications, APIs, cloud environments, infrastructure and enterprise identity systems
- Experience leading, coaching or building technical teams while retaining sufficient practical credibility to challenge methodology, review technical work and guide complex engagements
- A track record of designing threat-led assessments, defining realistic attack scenarios and testing complete attack chains rather than relying on vulnerability scanning or checklist-based exercises
- Deep understanding of how modern engineering environments are designed and operated, including CI/CD pipelines, Kubernetes, cloud platforms, authentication systems and privileged access
- Experience partnering directly with software, infrastructure, platform and security teams to explain attack paths, influence technical decisions and drive remediation through to completion
- Strong judgement around testing safety, business impact, prioritisation, coverage and escalation within complex, high-availability technology environments
- (Preferred) Exposure to offensive automation, breach-and-attack simulation, AI or agentic systems, physical testing, social engineering or regulated red-team frameworks
...
Apply for this role
All fields marked with * are required.