At a Glance
- Tasks: Join our Offensive Security team to enhance security through innovative testing and assessments.
- Company: Experian, a global leader in data and technology, empowering businesses and individuals.
- Benefits: Competitive salary, bonus plans, flexible working, and comprehensive health benefits.
- Other info: Dynamic work environment with opportunities for professional growth and development.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Experience in offensive security, penetration testing, and knowledge of cyber threats required.
The predicted salary is between 60000 - 60000 £ per year.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realize their financial goals and help them save time and money. We invest in people and new advanced technologies to unlock the power of data.
Experian's Offensive Security team charges itself with improving the organisation's security posture through clarifying risk and verifying the efficacy of our technical, people, physical and process controls from an attacker perspective. The team perform regular Adversary Simulation (Red Team) testing and a range of Ad-Hoc and Tactical Assessments based on changes to the threat landscape and organisational needs. To succeed in this role, you have breadth and depth of knowledge in security. This knowledge will include operating systems, networking and protocols, firewalls, databases, and middleware applications. Additionally, you will have expertise in forensics, scripting and programming, vulnerabilities, and the usage of GenAI / social engineering techniques. This is a Hybrid, Nottingham or London based role (40% in office) reporting to the Head of Offensive Security.
Responsibilities
- Collaborate with other teams within the Cyber Fusion Centre and the wider organisation to understand and articulate Cyber Risks in a threat-informed manner.
- Support Offensive Security's engagement at multiple organizational levels, from senior leaders to technical analysts to help improve risk understanding and verify the efficacy of remediation/mitigative actions.
- Participate in performing physical exploitation, network exploitation and social engineering assessments against authorized targets.
- Use CyberThreat Intelligence, Offensive Security Research, previous Adversary Simulation (Red Team) findings and internal risk intelligence to develop test cases demonstrating TTP effectiveness against Experian's control environment.
- Research and stay up to date with the latest cyber threats, attack vectors and attacker methodologies.
- Develop scripts, tools and methodologies to increase Offensive Security's capabilities and educate other team members around automation and AI.
- Use MITRE ATT&CK Framework and other structured attack analysis tools to describe and classify attacker methodology and significance.
Qualifications
Background in offensive security and adversary simulation. Detailed knowledge of global cyber threats and the procedures used by cyber adversaries. Two or more of the following skills:
- Network penetration testing and manipulation of network infrastructure
- Web application penetration testing assessments
- Email, phone, or physical social-engineering assessments
- Development, extension, or modifying of exploits, shecode or exploit tools
- Covert physical intrusion
- Cloud security or penetration testing (any major provider)
- AI Red Teaming/Testing and usage of Agentic AI for automation.
Industry certifications such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN or equivalent experience.
Specialist skills:
- Proficient in attacker tooling, including post-exploitation frameworks and tooling.
- Proficient in any of the following programming languages (C, C++, C#, Python, PowerShell, Bash, or Ruby)
- Proficient in Social Engineering techniques across OSINT, phishing, vishing and impersonation.
- Knowledge of current cloud attack methodologies and mitigations.
- Experience of Windows Operating System architecture and internals and use thereof in an enterprise environment.
- Core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux, Mainframe, Cloud Service Providers, Relational Databases, Data Warehouses, and filesystems.
- Knowledge of IT technologies and methods to secure them i.e. databases, SharePoint, storage area networks and cloud-based storage.
Benefits package includes:
- Great compensation package and discretionary bonus plan
- Core benefits include pension, Bupa healthcare, sharesave scheme and more
- 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age.
Senior Offensive Security Engineer in London employer: Experian Ltd
Experian is an exceptional employer that prioritises employee growth and development, offering a dynamic work culture where innovation thrives. With a commitment to investing in advanced technologies and a diverse range of markets, employees can expect meaningful opportunities to make an impact while enjoying a supportive environment that values collaboration and creativity.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Offensive Security Engineer in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Experian Ltd, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Experian Ltd
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Experian Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Offensive Security Engineer in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Experian Ltd insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Experian Ltd that you’re committed to staying ahead in the game.
How to prepare for a job interview at Experian Ltd
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Experian Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Experian Ltd.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.