Penetration Tester - Offensive Security Engineering

Europe, United Kingdom, London
Permanent
Job ID: 2554

Job Description


[Up to c. £225k Comp Package | Office-Led Working]


Role Overview

We’re representing an elite quantitative research and technology firm expanding its internal penetration-testing capability across a highly complex engineering environment. The organisation operates sophisticated research platforms, developer tooling, infrastructure and security controls supporting valuable intellectual property and business-critical systems. This role sits within a growing offensive-security function moving beyond reactive, request-driven assessments towards more continuous and threat-informed testing. You will conduct technically deep internal assessments, demonstrate realistic attack paths and work closely with engineering, security and control owners to ensure identified weaknesses are understood, prioritised and properly resolved...


Key Responsibilities

  • Plan and conduct end-to-end penetration tests across internal infrastructure, applications, identity services, engineering platforms and security controls
  • Assess technologies including Kubernetes, Jenkins, Windows Domain Services and associated developer or CI/CD environments
  • Perform discovery, exploitation, privilege escalation and lateral movement to demonstrate realistic internal attack paths and control weaknesses
  • Translate technical findings into practical remediation guidance that considers root cause, wider systemic exposure and the operational realities of the affected platform
  • Partner with application, infrastructure and business owners to assess whether controls operate effectively and support improvements through remediation and retesting
  • Provide technically credible assurance to Risk, Compliance, Detection Engineering and wider security teams through configuration reviews, control assessments and evidence-led testing
  • Develop and maintain Python-based tooling, automation, integrations and repeatable testing workflows that improve the coverage and efficiency of the team
  • Contribute to threat-informed assessments, purple-team activity and knowledge sharing while providing practical guidance to less experienced team members


What You’ll Bring…

  • Typically 4-8 years across penetration testing, offensive security or adjacent technical-security positions, with substantial hands-on assessment experience
  • Strong practical capability across the full testing lifecycle, including scoping, reconnaissance, exploitation, reporting, stakeholder debriefing and validation of remediation
  • Demonstrable internal infrastructure-testing experience covering Windows environments, Active Directory attack paths, privilege escalation and lateral movement
  • Good understanding of infrastructure and application vulnerabilities, including how weaknesses combine across systems to create broader compromise paths
  • Experience assessing DevOps or engineering technologies such as Kubernetes, Jenkins, CI/CD pipelines, configuration-management tooling or containerised environments
  • Ability to validate security controls through a combination of manual testing, technical review, automation and realistic attacker-focused techniques
  • Working Python skills and experience developing scripts, integrations or testing utilities, with exposure to Ansible or comparable automation tooling
  • OSCP certification, with CRT, OSEP or another advanced offensive-security qualification considered advantageous


...


Apply for this role

All fields marked with * are required.

I confirm I have a pre-existing right to work in the role’s location *
I require visa sponsorship now or will require it in the future

Back to Job Listings