At a Glance
- Tasks: Lead exciting red team engagements and enhance offensive security capabilities.
- Company: Join Bridewell, a top cyber security firm with a collaborative culture.
- Benefits: Enjoy flexible working, generous holiday, and a dedicated training budget.
- Why this job: Make a real impact in cyber security while developing your skills.
- Qualifications: 6+ years in red teaming, with strong offensive security skills.
- Other info: Hybrid work model with opportunities for travel and career growth.
The predicted salary is between 72000 - 108000 ÂŁ per year.
Company Overview
Bridewell is a leading cyber security services company specialising in protecting and transforming critical business functions for some of the world’s most trusted organisations. We are the trusted partner for operators of essential services and provide end‑to‑end cyber security capabilities that help our clients overcome their security challenges, allowing them to operate safely and securely. Bridewell holds the Gold level Investors in People award.
Position Summary
We are looking for a passionate technology‑focused individual with an honest and empathic approach to customer conversations. The successful candidate will be an experienced Red Team Lead with solid involvement in leading and delivering offensive security engagements such as threat‑led penetration testing (TLPT), adversary simulation, adversary emulation, purple teaming and social engineering. This is an excellent opportunity for a highly motivated Red Team Lead to continue their development and work on a range of exciting projects.
Responsibilities
- Lead complex red team engagements covering the whole engagement lifecycle – scoping, project initiation, delivery, reporting and post‑engagement debrief.
- Demonstrate advanced knowledge of attack methodologies, including privilege escalation, lateral movement, persistence and exfiltration techniques.
- Prepare comprehensive reports detailing red team findings, including identified vulnerabilities, successful exploits and recommendations for remediation.
- Support the sales team with pre‑sales and assist with technical input into tenders and proposals.
- Conduct research and participate in knowledge‑sharing activities to enhance the organisation’s offensive security capabilities.
- Actively collaborate with Bridewell’s Blue Team to share knowledge and techniques.
- Work with teams across the business, providing the latest technical knowledge to collaborate on interesting client projects.
- Stay up to date with the latest attack techniques, vulnerability trends and industry best practices.
- Showcase Bridewell’s capabilities in public speaking, webinars and other marketing initiatives.
- Continuously develop technical skills and expertise through training and certifications.
- Perform R&D to improve capability, development of payloads.
- Line manage, mentor, coach and upskill team members.
Qualifications
- Minimum of 6 years of experience in a dedicated red teaming role.
- Highly proficient in performing a variety of offensive security engagements such as adversary simulation, threat emulation, purple teaming and infrastructure assessments.
- Experience performing regulated Threat‑Led Penetration Testing (TLPT), especially within Financial Services (CBEST, TIBER‑EU frameworks).
- Hold industry recognised qualifications such as CREST CCT, CCSAS/CCRTS and CCSAM/CCRTM (or actively working towards).
- Proficiency in programming or scripting (Python, Bash, PowerShell, C, C#).
- Demonstrable experience in threat simulations, phishing, social engineering and physical security.
- Advanced C2 frameworks knowledge (Cobalt Strike / Outflank OST).
- Blue team and defensive knowledge.
- Experience with Cloud red teaming and identity‑based attacks.
- Aware of the Mitre ATT&CK framework and how it can be used to learn an adversary’s tactics and techniques and focus incident response.
- Adept at infrastructure deployment, including Infrastructure as Code (IaC) – Terraform, Ansible.
- Malware development.
- Proficiency across a range of operating systems (Windows, Linux, macOS).
Benefits
- 25 Days Holiday – plus buy and sell options.
- Flexible Working (around core office hours).
- Performance Incentive Bonus.
- Company Pension.
- Employee Shareholder Scheme.
- Personal Day & Birthday Off – after 1 year of service.
- Family Leave – after 1 year of service.
- Enhanced Maternity based on length of service.
- Dedicated Training Budget.
- Life Assurance.
- Electric Vehicle Scheme & Cycle to Work Scheme.
- Private Healthcare (incl. Gym discounts and vision care).
Location and Travel
Bridewell operates a hybrid and flexible working policy; however, you will be required to travel to different sites on occasion.
Security Clearance
To be eligible for this role you must either hold SC clearance or be eligible and willing to go through security clearance.
Equal Opportunity
Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.
Principal Red Team Specialist employer: Bridewell
Contact Detail:
Bridewell Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Red Team Specialist
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security scene. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio that highlights your red teaming projects, methodologies, and any cool findings. This will not only impress potential employers but also give them a taste of what you can bring to the table.
✨Tip Number 3
Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss your experience with adversary simulations and threat-led penetration testing. Remember, they want to see how you think and approach problems!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Bridewell.
We think you need these skills to ace Principal Red Team Specialist
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Principal Red Team Specialist role. Highlight your relevant experience in offensive security engagements and any specific qualifications that match the job description.
Showcase Your Skills: Don’t just list your skills; demonstrate them! Use examples from your past work to illustrate your expertise in areas like threat-led penetration testing and adversary simulation. This will help us see how you can contribute to our team.
Be Authentic: We love a genuine approach! When writing your application, let your personality shine through. Share your passion for cyber security and how it drives you to excel in your work. We want to know the real you!
Apply Through Our Website: For the best chance of success, make sure to apply directly through our website. This helps us keep track of your application and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Bridewell
✨Know Your Stuff
Make sure you brush up on your knowledge of attack methodologies and the latest trends in offensive security. Be ready to discuss specific techniques like privilege escalation and lateral movement, as well as your experience with threat-led penetration testing.
✨Showcase Your Leadership Skills
As a Principal Red Team Specialist, you'll be leading engagements. Prepare examples of how you've successfully managed projects from scoping to delivery. Highlight your mentoring experience and how you've helped team members grow their skills.
✨Prepare for Technical Questions
Expect in-depth technical questions about your proficiency in programming languages like Python or PowerShell, and your experience with tools like Cobalt Strike. Practise explaining complex concepts clearly, as you may need to communicate these to non-technical stakeholders.
✨Engage with the Interviewers
Don’t just wait for questions; engage in a conversation! Ask insightful questions about Bridewell’s approach to red teaming and how they collaborate with Blue Teams. This shows your genuine interest in the role and the company.