Senior Consultant, Red Team, Offensive Security

Senior Consultant, Red Team, Offensive Security

Full-Time 70000 - 90000 £ / year (est.) No working from home possible
Kroll

At a Glance

  • Tasks: Lead offensive security engagements and enhance client cyber resilience through innovative strategies.
  • Company: Join Kroll, a leader in cybersecurity with a diverse and inclusive culture.
  • Benefits: Enjoy hybrid working, competitive salary, and opportunities for professional growth.
  • Other info: Mentor junior consultants and contribute to a dynamic team environment.
  • Why this job: Make a real impact in cybersecurity while collaborating with top professionals in the field.
  • Qualifications: 5+ years in offensive cybersecurity and strong technical skills required.

The predicted salary is between 70000 - 90000 £ per year.

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We help our clients discover, understand, and remediate security risks across their networks, systems, applications, cloud environments, and identity platforms. Our clients trust us to use advanced offensive security tools, creativity, imagination, and expert knowledge to identify realistic attack paths and improve cyber resilience.

We are looking to grow our UK Red Team capability with a Senior Consultant / L3 Red Team Operator. Our expertise in red team operations, purple team engagements, assumed‑breach testing, adversary emulation, and threat‑intelligence‑led penetration testing is in high demand. Our collaborative ties to our forensic and incident response team, detection engineering team, threat intelligence team, and wider Cyber Risk practice enable us to deliver high‑impact offensive security engagements for clients across a range of sectors. This role will be based in the UK, with a hybrid working model requiring two days per week in one of our UK offices: London, Leeds, or Birmingham.

What you’ll do:

  • Deliver red team, purple team, assumed‑breach, and adversary emulation engagements for clients across multiple sectors.
  • Support engagement planning, including threat‑informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria.
  • Execute hands‑on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective‑based testing.
  • Assess and exploit attack paths across Microsoft Entra ID, Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms where in scope.
  • Build, adapt, and operate red team infrastructure, command‑and‑control tooling, payloads, and scripts during authorised client engagements.
  • Apply detection‑aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations.
  • Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability.
  • Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios.
  • Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting.
  • Produce clear, evidence‑based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions.
  • Present technical findings to security teams and communicate business risk to senior stakeholders.
  • Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance.
  • Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering.

What you’ll need to succeed:

  • 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed‑breach engagements.
  • Existing SC clearance, or the ability and willingness to obtain SC clearance.
  • A relevant CREST red team certification aligned to CBEST‑style delivery, such as CREST Certified Red Team Specialist, formerly CCSAS, or the ability to obtain this within the probation period.
  • Strong experience with Windows enterprise environments, Active Directory exploitation, privilege escalation, and lateral movement.
  • Experienced and comfortable with performing social engineering techniques in support of red team operations, including email and voice phishing.
  • Experience operating command‑and‑control frameworks such as Mythic, Cobalt Strike, or similar tooling in authorised client engagements.
  • Experience developing, modifying, or extending offensive security tooling, scripts, or payloads.
  • Practical understanding of evasion techniques, endpoint security controls, operational security, and detection‑aware tradecraft.
  • Strong understanding of networking and web protocols, including TCP/IP, DNS, HTTP, HTTPS, and authentication flows.
  • Experience conducting reconnaissance, attack path development, and objective‑based testing.
  • Excellent written and verbal communication skills, with the ability to explain complex technical issues clearly to technical and non‑technical audiences.
  • The ability to manage risk during live client engagements and operate within agreed rules of engagement.
  • Work remote, but have the ability to come into the office at either London, Leeds, or Birmingham, on occasion for team building or administration.

Nice to have:

  • CREST Certified Red Team Specialist, OSEP, OSCE3, CRTO, CRTL, GPEN, GXPN, or equivalent experience.
  • Experience delivering CBEST, STAR‑FS, TIBER, DORA‑aligned, TLPT, or regulated financial‑sector red team engagements.
  • Strong working knowledge of Microsoft Entra ID, Microsoft 365, and hybrid identity attack paths.
  • Working knowledge of cloud platforms such as AWS, Azure, or GCP, including identity, privilege escalation, misconfiguration abuse, and cloud‑native attack paths.
  • Experience with exploit development, reverse engineering, malware analysis, or assembly‑level debugging.
  • Experience with macOS or Linux endpoint tradecraft.
  • Experience with Kubernetes, Docker, CI/CD platforms, DevOps environments, or containerised workloads.
  • Experience with physical security.
  • Experience with employing modern AI tooling to support offensive engagements.
  • Experience writing blogs, presenting at industry events, publishing research, or contributing to offensive security tooling.
  • Experience leading small teams or technical workstreams during complex offensive security engagements.

Kroll is committed to creating an inclusive work environment. We are proud to be an equal opportunity employer and will consider all qualified applicants regardless of gender, gender identity, race, religion, colour, nationality, ethnic origin, sexual orientation, marital status, veteran status, age, or disability.

Senior Consultant, Red Team, Offensive Security employer: Kroll

Kroll is an exceptional employer that fosters a collaborative and empowering work culture, ideal for professionals seeking to make a meaningful impact in the field of restructuring and insolvency. With a commitment to employee growth, Kroll offers extensive training and mentorship opportunities, ensuring that you can develop your skills while working on diverse and challenging projects. Located in a dynamic environment, you'll have the chance to engage with a wide range of stakeholders, enhancing your professional network and career trajectory.

Kroll

Contact Details:

Kroll Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Consultant, Red Team, Offensive Security

Tip Number 1

Network like a pro! Attend cybersecurity meetups, conferences, or local events. It's a great way to meet industry folks and get your name out there—plus, you might just bump into someone from Kroll!

Tip Number 2

Show off your skills! Create a portfolio showcasing your red team projects, tools you've developed, or any cool offensive security techniques you've mastered. This will give potential employers a taste of what you can bring to the table.

Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice explaining complex concepts in simple terms—this is key when communicating with both techies and non-techies alike.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're serious about joining the Kroll team and contributing to our mission of making the world a safer place.

We think you need these skills to ace Senior Consultant, Red Team, Offensive Security

Offensive Cybersecurity
Red Team Operations
Purple Team Engagements
Adversary Emulation
Assumed-Breach Testing
Active Directory Exploitation
Privilege Escalation

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Senior Consultant role. Highlight your experience in offensive security, red teaming, and any relevant certifications. We want to see how your skills align with what we’re looking for!

Showcase Your Technical Skills:Don’t hold back on detailing your technical expertise! Whether it’s Active Directory exploitation or cloud security, let us know how you’ve applied these skills in real-world scenarios. We love seeing practical examples.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use straightforward language to explain complex concepts. Remember, we appreciate good communication skills, so make sure your writing reflects that!

Apply Through Our Website:Don’t forget to submit your application via careers.kroll.com. It’s the best way to ensure your application gets into the right hands. Plus, it shows you’re serious about joining our team!

How to prepare for a job interview at Kroll

Know Your Stuff

Make sure you brush up on your offensive security knowledge, especially around red team operations and the specific tools mentioned in the job description. Be ready to discuss your hands-on experience with Active Directory exploitation and cloud platforms like AWS and Azure.

Showcase Your Communication Skills

Since you'll need to explain complex technical issues to both technical and non-technical audiences, practice articulating your thoughts clearly. Prepare examples of how you've communicated findings or risks to stakeholders in previous roles.

Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past engagements where you had to develop attack paths or conduct social engineering activities, and be ready to walk through your thought process.

Demonstrate Team Spirit

This role emphasises collaboration, so be prepared to discuss how you've worked with other teams in the past. Highlight any mentoring experiences or times when you contributed to a supportive work environment, as this aligns with their 'One team, One Kroll' ethos.