Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team
We Are Orbis Group Ltd
Aug 19, 2026
Contractor
Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team requirement for an urgent start. The Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team will be working for a major global financial client, supporting an offensive security function focused on deep manual testing, vulnerability research and frontier-model-assisted discovery across a complex, highly regulated technology estate. Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team Key Skills: Strong hands-on offensive security background, with proven senior-level experience delivering manual penetration tests across web applications, APIs, infrastructure, cloud and internal networks Demonstrable vulnerability research capability, including source code review, reverse engineering, fuzzing and the discovery of novel issues beyond automated scanner output Practical experience using frontier AI/LLM tooling to accelerate reconnaissance, code and log analysis, payload generation and hypothesis testing, with the judgement to validate and discard model output Proven exploit development and validation experience, safely proving impact and chaining findings to demonstrate realistic attack paths rather than reporting theoretical risk Risk-based triage and prioritisation skills, translating technical findings into business impact, exploitability ratings and clear, actionable remediation guidance for engineering teams Strong understanding of MITRE ATT&CK, OWASP Top 10/ASVS, CVSS and threat modelling techniques, with experience running structured, objective-led testing campaigns Experience testing cloud-native and hybrid environments (Azure, AWS, GCP), containers, CI/CD pipelines and identity layers (eg Entra ID, OAuth/OIDC, SAML, MFA) Excellent written and verbal communication skills, with the ability to defend findings to engineering, risk, audit and senior leadership stakeholders; industry certifications (eg OSCP, OSCE/OSEP, Crest CCT, GXPN) advantageous Penetration on Tester - Vulnerability Research - AI-Assisted Offensive Security - Exploit Development - Red Team - Contract inside IR35 - Hybrid - Long-term Programme - Urgent Start