At a Glance
- Tasks: Lead exciting red and purple teaming engagements to enhance cyber security.
- Company: Bridewell, a top player in the UK cyber security sector.
- Benefits: Flexible working, 25 days holiday, performance bonuses, and personal development budget.
- Why this job: Join a passionate team making a real impact in cyber security.
- Qualifications: 5+ years in penetration testing, with strong technical skills and industry certifications.
- Other info: Hybrid working model with opportunities for travel and continuous learning.
The predicted salary is between 48000 - 84000 £ per year.
One of the most exciting prospects in the UK cyber security sector today, Bridewell is a leading cyber security services company specialising in protecting and transforming critical business functions for some of the world’s most trusted organisations. We are the trusted partner for operators of essential services and provide end-to-end cyber security capabilities that help our clients overcome their security challenges, allowing them to operate safely and securely.
Bridewell holds the Gold level, Investors in People award which we feel solidifies and reflects on the outstanding calibre that makes us truly one team.
Who are we looking for?
A passionate technology focused individual, with an honest and empathic approach to customer conversations and able to communicate with all levels of an organisation with appropriate technical content. You’ll be an experienced Red Team Lead with solid involvement of leading and delivering offensive security engagements such as threat led penetration testing (TLPT), adversary simulation, adversary emulation, purple teaming and social engineering. This is an excellent opportunity for a highly motivated Red Team Lead to continue their development and work on a range of exciting projects.
Requirements
- You’ll be leading red and purple teaming engagements as part of Bridewell’s Red Team services, providing guidance, mentorship and technical expertise across Bridewell and to our clients.
- Demonstrate advanced knowledge of attack methodologies, including privilege escalation, lateral movement, persistence, and exfiltration techniques.
- Prepare comprehensive reports detailing red team findings, including identified vulnerabilities, successful exploits, and recommendations for remediation.
- Support the sales team with pre-sales and assist with technical input into tenders and proposals.
- Conduct research and participate in knowledge-sharing activities to enhance the organisations offensive security capabilities.
- Actively collaborating with Bridewell’s Blue Team to share knowledge and techniques.
- Work with teams across the business, providing the latest technical knowledge to collaborate on interesting client projects.
- Stay up to date with the latest attack techniques, vulnerability trends, and industry best practices.
- Continuously develop technical skills and expertise through training and certifications.
- Performing R&D to improve capability, development of payloads.
- Mentor and upskill other members of the team.
- Flexibility to deliver strong network and infrastructure pentest engagements.
What we’re looking for
- Minimum of 5 years' experience in a penetration testing and/or red teaming role.
- Proficient in performing a variety of offensive security engagements such as adversary simulation, threat emulation, purple teaming and infrastructure assessments.
- Experience of performing regulated Threat Led Penetration Testing (TLPT), especially within Financial Services - CBEST, TIBER-EU frameworks.
- Hold industry recognised qualifications such as CREST CCT, CCSAS/CCRTS and CCSAM/CCRTM (or actively working towards).
- Proficiency in programming or scripting (Python, Bash, Powershell, C, C#).
- Demonstratable experience in threat simulations, phishing, social engineering and physical security.
- Advanced C2 framework knowledge (Cobalt Strike).
- Blue team and defensive knowledge.
- Experience with Cloud red teaming and identity-based attacks.
- Awareness of the Mitre ATT&CK framework and how it can be used to learn an adversary’s tactics and techniques and focus incident response.
- Adept at infrastructure deployment, including Infrastructure as Code (IaC) – Terraform, Ansible.
- Malware Development.
- Proficiency across a range of operating systems (Windows, Linux, macOS).
Our vision is to create a safe, inclusive digital world where people and organisations can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasises the importance of the part we play in society, and our commitment to our people and clients. Our story to-date has been phenomenal, but success doesn’t end here and as we continue to grow and scale, we want to keep the same culture, passion and commitment to high quality that has enabled us to get this far.
Bridewell will provide a great career opportunity with continual development as well as the following:
- 25 Days Holiday - Plus buy and sell options.
- Flexible Working (around core office hours).
- Performance Incentive Bonus.
- Company Pension.
- Employee Shareholder Scheme.
- Personal Day & Birthday Off - After 1 year of service.
- Family Leave – After 1 year of service.
- Enhanced Maternity based on length of service.
- Dedicated Training Budget.
- Life Assurance.
- Electric Vehicle Scheme & Cycle to Work Scheme.
- Private Healthcare (incl. Gym discounts and vision care).
Location: Bridewell operates a hybrid and flexible working policy, however you will be required to travel to different sites on occasion.
Note: To be eligible for this job you must either hold SC Clearance or be eligible and willing to go through security clearance.
Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.
Senior Red Team Specialist employer: Bridewell
Contact Detail:
Bridewell Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Red Team Specialist
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security scene. Attend meetups, conferences, or even online webinars. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your red teaming projects, reports, and any cool tools you've developed. This will give potential employers a taste of what you can bring to the table and set you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss your experience with threat simulations and how you approach problem-solving. Remember, they want to see your passion for cyber security!
✨Tip Number 4
Don't forget to apply through our website! We love seeing applications directly from candidates who are excited about joining Bridewell. Plus, it shows you're genuinely interested in being part of our team.
We think you need these skills to ace Senior Red Team Specialist
Some tips for your application 🫡
Show Your Passion: When writing your application, let your enthusiasm for cyber security shine through! We want to see that you’re genuinely excited about the role and the impact you can make at Bridewell.
Tailor Your Experience: Make sure to highlight your relevant experience in red teaming and offensive security. We’re looking for specific examples of your work, so don’t hold back on those impressive projects you've led!
Be Clear and Concise: While we love detail, clarity is key! Keep your application straightforward and to the point. Use bullet points where necessary to make it easy for us to read through your qualifications.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity at Bridewell!
How to prepare for a job interview at Bridewell
✨Know Your Attack Methodologies
Make sure you brush up on your knowledge of attack methodologies like privilege escalation and lateral movement. Be ready to discuss specific techniques you've used in past engagements, as this will show your depth of understanding and experience.
✨Prepare for Technical Questions
Expect technical questions that dive deep into your experience with red teaming and offensive security. Practise explaining complex concepts in a way that's easy to understand, as you'll need to communicate effectively with various stakeholders.
✨Showcase Your Collaboration Skills
Bridewell values teamwork, so be prepared to discuss how you've collaborated with blue teams or other departments in the past. Share examples of how you’ve mentored others or contributed to knowledge-sharing activities.
✨Stay Updated on Industry Trends
Demonstrate your commitment to continuous learning by discussing recent trends in cyber security, such as new attack vectors or emerging technologies. This shows you're proactive and passionate about staying at the forefront of the industry.