Our client isseeking an experienced Cyber Security Analyst/Red Team Specialist to conduct safe, controlled and intelligence-led cyber-attack simulations across complex technology estates.
Working as a real-world adversary might, the successful candidate will identify weaknesses, test defensive capabilities and provide expert cyber security insight to support strategic security decision-making. The role requires strong hands-on offensive security experience, with the ability to tactically assess and execute sophisticated attack scenarios across traditional enterprise environments and modern digital services.
You will be comfortable conducting complex, multi-stage operations, including chained attacks, evasion techniques, persistence, post-exploitation and lateral movement, while maintaining a strong focus on operational security and avoiding unnecessary disruption to live services.
Key Responsibilities
- Design and execute threat intelligence-led, full-spectrum cyber-attack simulations, including long-term campaign planning, persistence and post-exploitation activity.
- Adopt a Red Team/adversary simulation approach to identify high-impact vulnerabilities across critical technology estates and business areas.
- Validate the effectiveness of the organisation's wider cyber security controls, defensive capabilities and security architecture.
- Conduct scenario-driven engagements based on realistic threat actor capabilities, behaviours and tradecraft.
- Perform exploitation across infrastructure, web applications, cloud platforms and enterprise technology environments.
- Identify and analyse attack paths towards high-value systems, data and business services.
- Apply appropriate evasion and operational security techniques to ensure engagements are controlled and do not unnecessarily disrupt business operations.
- Communicate technical findings clearly, translating complex vulnerabilities and attack paths into business risk, impact and remediation requirements for senior stakeholders.
- Develop, enhance and automate offensive security tools, techniques and methodologies.
- Build and maintain attack infrastructure, including C2 frameworks and supporting infrastructure-as-code.
- Mentor junior Red Team colleagues, supporting the development of their technical capability and understanding of offensive security.
- Share knowledge with wider cyber security and non-security teams to help strengthen the organisation's overall security culture.
- Contribute to vulnerability management, threat mitigation and risk-based security decision-making.
Essential Experience & Skills
The successful candidate will demonstrate:
- Proven experience planning and executing complex, multi-phase offensive security operations.
- Strong experience delivering scenario-driven adversary simulations and Red Team engagements.
- Excellent threat intelligence analysis and assessment capability.
- Extensive hands-on exploitation experience across a broad range of technologies, including:
- Microsoft Entra ID
- Active Directory
- Microsoft 365
- macOS
- Kubernetes
- CI/CD environments
- AWS
- Azure
- Infrastructure and web applications
- Strong understanding of post-exploitation, persistence and lateral movement, including tactical analysis of attack paths to high-value targets.
- Experience conducting engagements in accordance with operational security best practice and within a range of threat actor capabilities and tradecraft.
- Deep technical understanding of security technologies within end-user and server operating systems, together with supporting infrastructure and enterprise architecture.
- Experience working across complex Legacy and modern enterprise environments at scale.
- Experience developing, deploying and using tools to support Red Team activities.
- Practical experience with attack infrastructure, C2 frameworks and Infrastructure as Code (IaC) technologies.
- Excellent written and verbal communication skills, with the ability to explain complex technical vulnerabilities, risks and attack scenarios to both technical and non-technical audiences, including senior stakeholders.
- Experience contributing to or participating in GCASE, GBEST, CBEST or TIBER engagements.
Desirable Experience
- Experience in threat research and/or vulnerability research, including publishing research or presenting findings to the wider cyber security community.
- Previous experience in a related security discipline, such as:
- Protective Monitoring
- Incident Response
- Security Engineering
- Security Architecture
- Experience working within large, complex public sector, government or highly regulated environments.
- Experience mentoring or developing junior offensive security professionals.
Professional Qualifications
Relevant Red Team and offensive security certifications are desirable, including:
- CCSAS
- CRTL
- Other recognised offensive security/Red Team certifications would also be considered.
What We're Looking For
This is a technically demanding role for an experienced offensive security professional who can combine deep technical exploitation capability with strategic security thinking.
The successful candidate will be able to operate confidently across complex enterprise, cloud and modern digital environments, understand how sophisticated attacks can be chained together, and communicate the resulting risks in a way that enables senior decision-makers to take effective action.
If you have substantial experience in Red Teaming, adversary simulation, threat intelligence, exploitation, post-exploitation and attack-path analysis, we would be keen to hear from you.