Senior Security Consultant, Emergent Threat & Exploit Researcher
Senior Security Consultant, Emergent Threat & Exploit Researcher

Senior Security Consultant, Emergent Threat & Exploit Researcher

Full-Time 70000 - 90000 ÂŁ / year (est.) Home office (partial)
Divvy Cloud Corp.

At a Glance

  • Tasks: Join our team to attack networks and improve client security through innovative penetration testing.
  • Company: Rapid7, a leader in cybersecurity with a dynamic and collaborative culture.
  • Benefits: Competitive salary, professional development, and opportunities to attend industry conferences.
  • Why this job: Make a real impact by uncovering vulnerabilities and enhancing security for diverse clients.
  • Qualifications: 5+ years in security roles, expert in penetration testing, and strong communication skills.
  • Other info: Be part of a multi-dimensional team that values diverse backgrounds and experiences.

The predicted salary is between 70000 - 90000 ÂŁ per year.

Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defence strategies.

About the Team: Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defence-in-depth strategy.

In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.

About the Role: Your primary responsibility is to deliver Rapid7’s Vector Command Continuous Red Teaming service. In this role, you will investigate emerging threats, uncover novel vulnerabilities across large external attack surfaces, and attempt to breach customer perimeter defenses to gain initial access. When new N-day or zero-day vulnerabilities emerge, this role rapidly analyzes them, recreates proof-of-concepts, and assesses customer environments for exposure. Between these high-priority efforts, the researcher actively hunts for novel vulnerabilities and unique attack paths across customer attack surfaces to support initial access operations. Specifically, your focus will be to:

  • Evaluate large external attack surfaces to identify vulnerabilities that enable initial access.
  • Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.
  • Analyze, develop, and exploit N-day and newly released zero-day vulnerabilities relevant to customer environments.
  • Identify novel attacks through black-box evaluation of customer web applications, leading to initial access or exposure of sensitive data.
  • Develop and maintain positive relationships with clients and understand their business and needs.
  • Participate in industry conferences and professional organizations.
  • Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices.
  • Translate technical concepts and convey them to non-security personnel.
  • Mentor and coach junior staff to promote growth, project contributions, and knowledge sharing.
  • Meet professional practice standards and demonstrate exceptional skill in core service areas.

The skills and qualities you’ll bring include:

  • 5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience.
  • Expert knowledge of modern penetration testing tools and methods.
  • Network and web-based application security concepts.
  • Windows/Linux/UNIX internals.
  • Exploit research and development.
  • Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.).
  • Technical competencies, including previous technical consulting experience.
  • High quality report writing and peer reviewing.
  • Strong knowledge of common regulatory structures and obligations and common I.T. governance.
  • The ability to effectively lead teams of penetration testers while on engagements.
  • Be comfortable explaining findings and recommendations to technical and non-technical audiences including C-Level and Board briefings.
  • Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet-facing attack surfaces.
  • Certifications such as OSCP, OSCE, GXPN, OSEE, CREST.
  • Experience with Red & Purple Teams.
  • Excellent communication skills both with internal and external stakeholders.
  • Collaborative mindset, contributing to knowledge sharing and cross training.
  • Demonstrate a commitment to the “end-to-end” testing process, from the initial pre-engagement planning to providing accountable support during the final remediation phase.

Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

Senior Security Consultant, Emergent Threat & Exploit Researcher employer: Divvy Cloud Corp.

At Rapid7, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture. As a Senior Security Consultant in our Global Services team, you will not only engage in cutting-edge security research but also have ample opportunities for professional growth through mentorship and participation in industry conferences. Our commitment to employee development, coupled with a dynamic environment that values diverse perspectives, makes Rapid7 a rewarding place to advance your career in cybersecurity.
Divvy Cloud Corp.

Contact Detail:

Divvy Cloud Corp. Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Security Consultant, Emergent Threat & Exploit Researcher

✨Tip Number 1

Network, network, network! Get out there and connect with professionals in the security field. Attend industry conferences, join online forums, and engage on social media platforms like LinkedIn. The more people you know, the better your chances of landing that dream job!

✨Tip Number 2

Show off your skills! Create a portfolio showcasing your penetration testing projects, including any bug bounties or personal research. This not only demonstrates your expertise but also gives potential employers a taste of what you can bring to their team.

✨Tip Number 3

Practice makes perfect! Keep honing your skills by participating in Capture The Flag (CTF) competitions or contributing to open-source security projects. This hands-on experience is invaluable and can set you apart from other candidates.

✨Tip Number 4

Don’t forget to apply through our website! We’re always on the lookout for talented individuals who are passionate about security. Your next big opportunity could be just a click away, so don’t hesitate to put yourself out there!

We think you need these skills to ace Senior Security Consultant, Emergent Threat & Exploit Researcher

Penetration Testing
Network Security
Web Application Security
Exploit Research and Development
Technical Consulting
Report Writing
Regulatory Knowledge
Team Leadership
Communication Skills
Bug Bounty Experience
Familiarity with Modern Penetration Testing Tools
Experience with Multiple Programming Languages (Ruby, Python, PHP, Java, C, C++, Assembly)
Collaboration and Knowledge Sharing
Understanding of Attack Surface Analysis

Some tips for your application 🫡

Show Off Your Skills: When you're writing your application, make sure to highlight your technical skills and experience in penetration testing. We want to see how you've tackled challenges in the past and what tools you’ve used to get the job done.

Tailor Your Application: Don’t just send a generic application! Take the time to tailor your CV and cover letter to match the job description. We love seeing candidates who understand our needs and can demonstrate how their experience aligns with the role.

Be Clear and Concise: Keep your writing clear and to the point. We appreciate well-structured applications that are easy to read. Avoid jargon unless it’s relevant, and make sure your key achievements stand out!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at Divvy Cloud Corp.

✨Know Your Tools Inside Out

Make sure you’re well-versed in the modern penetration testing tools and methods mentioned in the job description. Familiarise yourself with how to use them effectively, as you might be asked to demonstrate your skills or discuss your experience with these tools during the interview.

✨Showcase Your Problem-Solving Skills

Prepare to discuss specific examples of how you've tackled complex security challenges in the past. Think about times when you identified vulnerabilities or crafted novel attack chains, and be ready to explain your thought process and the impact of your actions.

✨Understand the Client's Perspective

Since building positive relationships with clients is key, brush up on how to translate technical concepts into layman's terms. Be prepared to discuss how you would approach understanding a client's business needs and how you can add value through your insights.

✨Stay Current with Emerging Threats

Keep yourself updated on the latest vulnerabilities and trends in the cybersecurity landscape. You might be asked about recent zero-day vulnerabilities or emerging threats, so having a few examples ready will show that you’re proactive and knowledgeable in your field.

Senior Security Consultant, Emergent Threat & Exploit Researcher
Divvy Cloud Corp.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>