Senior Security Specialist

Senior Security Specialist

City of London Full-Time 48000 - 84000 £ / year (est.) No home office possible
L

At a Glance

  • Tasks: Lead offensive security tests and support bug bounty programmes to combat cyber threats.
  • Company: Join LSEG, a global leader in financial markets infrastructure with over 300 years of excellence.
  • Benefits: Enjoy healthcare, retirement planning, paid volunteering days, and a commitment to wellbeing.
  • Why this job: Make a real impact in cybersecurity while working in a dynamic, collaborative culture.
  • Qualifications: Requires a tech degree, security certifications, and 3+ years in penetration testing.
  • Other info: Be part of a diverse team dedicated to sustainability and innovation in finance.

The predicted salary is between 48000 - 84000 £ per year.

This Security Testing Operations (STO) Senior Associate role is a crucial role for the offensive testing programme across the group, which protects the business from our most sophisticated cyber threats! The role holder will plan and complete offensive security simulations targeting assets across the enterprise as well as provide technical support for our bug bounty and perimeter asset monitoring programmes. Finally, the candidate will find opportunities for and support the development of tools or processes which drive high impact risk mitigation through automation. The applicant will be a domain authority on vulnerability exploitation. This role requires working in a tight-knit technical team, with external partners, BISOs, the GSOC, and other entities.

Role Responsibilities & Key Accountabilities:

  • Plan, lead and carry out red teams / purple teams and penetration tests where you assume the role of a threat actor to meet specified objectives.
  • Co-ordinate with external 3rd party vendors to enable vulnerability discovery.
  • Provide constructive feedback to the team responsible for incident response and product development on their successes, failures and potential areas of improvement.
  • Study and replicate tactics, techniques and procedures used by modern attackers to improve the security of our products and corporate environment.
  • Efficiently report analysis and findings in the most accessible way (written reports, Jira, tickets, presentations etc).
  • Develop, modify and extend tools/exploits that assist with execution of security assessments, including custom tools and automation.

Experience:

  • Technology related Bachelor's Degree or equivalent experience and certifications in cyber security.
  • One or more of the following security certifications OSCP, OSCE, OSEE, OSWE, CREST, GXPEN preferred.
  • Demonstrable experience in Red Teaming and Penetration Testing.
  • Minimum 3 years of deep, hands-on, technical security experience with at least one of: multiple security technologies such as Firewalls, IDS/IPS, Web Proxies and DLP among others, Web Applications and Services, Cryptography, Social Engineering and Open Source Intelligence Gathering (OSINT), Mobile platforms, Software Security, malware reverse engineering.
  • Deep technical understanding of enterprise operating system environments, Active Directory and networking.
  • Validated understanding of security vulnerabilities and common software engineering flaws.
  • Familiarity with red teaming related regulations and frameworks (DORA/CBEST/TIBER) nice to have.
  • Familiarity with Network Defence analytical models (Kill Chain, ATT&CK, etc.).
  • Familiarity with popular scripting languages and ability to automate simple tasks.
  • Experience working with Financial Services and Critical Infrastructure a plus.
  • Strong verbal & written communication skills & presentation skills.
  • Ability to work in a fast-paced environment.
  • Problem solver and barrier breaker with initiative.

Do you have a background in penetration testing or red teaming, and are looking for your career's next step? This is a superb opportunity for you to move into a high impact role in industry!

Senior Security Specialist employer: LSEG (London Stock Exchange Group)

LSEG is an exceptional employer, offering a dynamic work environment in the heart of London where innovation and collaboration thrive. With a strong commitment to employee growth, LSEG provides tailored benefits, including healthcare and wellbeing initiatives, while fostering a culture of integrity and excellence. Join a diverse team dedicated to driving financial stability and sustainable economic growth, where your individuality is valued and your contributions make a meaningful impact.
L

Contact Detail:

LSEG (London Stock Exchange Group) Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Security Specialist

✨Tip Number 1

Familiarise yourself with the latest tactics, techniques, and procedures (TTPs) used by modern attackers. This knowledge will not only help you in interviews but also demonstrate your commitment to staying updated in the ever-evolving field of cybersecurity.

✨Tip Number 2

Engage with the cybersecurity community through forums, webinars, and local meetups. Networking with professionals in the field can provide valuable insights and potentially lead to referrals for the Senior Security Specialist role.

✨Tip Number 3

Showcase your hands-on experience with red teaming and penetration testing by discussing specific projects or challenges you've tackled. Be prepared to explain your approach and the tools you used, as this will highlight your practical skills during discussions.

✨Tip Number 4

Research LSEG's values and recent initiatives related to cybersecurity. Tailoring your conversations to align with their mission and demonstrating how your expertise can contribute to their goals will make a strong impression during the interview process.

We think you need these skills to ace Senior Security Specialist

Red Teaming
Penetration Testing
Vulnerability Exploitation
Offensive Security Simulations
Technical Support for Bug Bounty Programs
Automation of Security Processes
Knowledge of Security Technologies (Firewalls, IDS/IPS, etc.)
Web Application Security
Cryptography
Social Engineering
Open Source Intelligence Gathering (OSINT)
Malware Reverse Engineering
Active Directory Management
Networking Fundamentals
Security Vulnerabilities and Software Engineering Flaws
Familiarity with Red Teaming Regulations (DORA/CBEST/TIBER)
Network Defence Analytical Models (Kill Chain, ATT&CK)
Scripting Languages for Automation
Strong Verbal and Written Communication Skills
Presentation Skills
Problem-Solving Skills
Ability to Work in a Fast-Paced Environment

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing and red teaming. Use specific examples that demonstrate your technical skills and familiarity with security technologies mentioned in the job description.

Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and how your background aligns with LSEG's mission. Mention any relevant certifications and experiences that showcase your expertise in offensive security simulations.

Showcase Technical Skills: When detailing your experience, focus on your hands-on technical skills with security technologies like Firewalls, IDS/IPS, and Web Applications. Provide concrete examples of how you've used these skills to mitigate risks or improve security.

Prepare for Technical Questions: Anticipate technical questions related to vulnerability exploitation and red teaming methodologies. Be ready to discuss specific tactics, techniques, and procedures you have employed in past roles.

How to prepare for a job interview at LSEG (London Stock Exchange Group)

✨Showcase Your Technical Expertise

Be prepared to discuss your hands-on experience with penetration testing and red teaming. Highlight specific tools and techniques you've used, and be ready to explain how you've applied them in real-world scenarios.

✨Understand the Company’s Security Landscape

Research LSEG's security protocols and recent initiatives. Familiarise yourself with their approach to cyber threats and be ready to discuss how your skills can enhance their existing security measures.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving abilities in high-pressure situations. Practice articulating your thought process when faced with hypothetical security breaches or vulnerabilities.

✨Communicate Clearly and Effectively

Since the role involves reporting findings and collaborating with various teams, demonstrate your communication skills. Practice explaining complex technical concepts in a way that is accessible to non-technical stakeholders.

L
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>