Role: Principal Offensive Security Operator
Salary/Rate: £640 - £740 per day inside IR35
Location: Mainly remote - occasional London
Contract Duration: 12-months
We are currently looking for a Principal Offensive Security Operator for our government client.
The Principal Offensive Security Operator role is mainly remote, with occasional travel to London (estimated once or twice per quarter) depending on business needs. No expenses would be available for this travel. There is no further flexibility with expected time on site, or the office location.
The contract for this Principal Offensive Security Operator position is for 12-months, with potential to extend, operating inside IR35.
This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution.
Security Clearance: Security Check ("SC Clearance")
Essential Skills / Experience required:
- Experience using, developing and deploying tools in support of red teaming activities, including attack infrastructure, C2 frameworks and infrastructure-as-code technologies.
- Proven ability to plan and execute complex, multi-phase operations.
- Scenario-driven adversary simulation
- Threat intelligence analysis and assessment
- Exploitation of a wide range of technologies, including infrastructure, web application and cloud platforms: Microsoft Entra, Active Directory, M365, macOS. Kubernetes, CI/CD, AWS, Azure.
- Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets
- Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft
- Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex legacy and modern enterprise environments.
- Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences, including senior stakeholders, in support of vulnerability management, threat mitigation, and risk-based decision-making.
- Participation in GCASE / GBEST / CBEST / TIBER engagements.
Desirable:
- Experience in threat /vulnerability research, including publication and presentation to the wider cyber security community.
- Background in a related a discipline, such as protective monitoring, incident response, security engineering or security architecture.
- Certifications in the field of red team: CCSAS/CCRTS, CRTL
Role / Responsibilities:
- Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the organisation.
- Adopting a red team approach, discovering high-impact weaknesses across the organisation's most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively.
- Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making.
- Development and implementation of tools and methodologies to augment and to automate team offensive and analytical capability.
- Mentoring junior Red Team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in the department.
If you are interested in the above role, please click Apply Now and send a CV for quick review.
As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs [at] circlerecruitment [dot] com. We will be in touch to discuss your suitability and arrange your guaranteed interview.
Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know.
Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter - @Circle_Rec and LinkedIn - Circle Recruitment.