Senior Security Consultant in Cheltenham
Senior Security Consultant

Senior Security Consultant in Cheltenham

Cheltenham Full-Time 48000 - 84000 £ / year (est.) No home office possible
Go Premium
Prism Infosec

At a Glance

  • Tasks: Lead Red Team engagements and enhance offensive security methodologies.
  • Company: Join Prism Infosec, a passionate cybersecurity company focused on collaboration and innovation.
  • Benefits: Enjoy remote work flexibility, competitive salary, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 2+ years in Red Team operations and strong technical skills in offensive security.
  • Other info: Dynamic team environment with mentorship opportunities and continuous learning.

The predicted salary is between 48000 - 84000 £ per year.

ABOUT THE COMPANY: Prism Infosec is an established cybersecurity company that has created a working environment driven by people passionate about information/cyber security and technology. Through collaboration and teamwork, Prism Infosec strives to ensure that new skills can be learnt and knowledge and experiences shared.

TYPE OF INDIVIDUAL WE ARE LOOKING FOR: We are seeking an experienced Senior Security Consultant to join our Red Team and help clients understand their true security posture beyond traditional penetration testing. You will lead and deliver sophisticated Red Team engagements, support blended offensive operations with our Penetration Testing team, and contribute directly to the continual evolution of Prism Infosec’s offensive security methodologies, tooling, and tradecraft. This position is ideally suited to someone who thrives on adversarial thinking, technical depth, autonomy, and creativity.

KEY AREAS OF RESPONSIBILITY:

  • Red Team Engagement Delivery: End-to-end ownership of covert and overt offensive security operations, ensuring engagements meet defined objectives and maintain operational security.
  • Infrastructure & Tooling Management: Deployment, maintenance, and secure operation of Red Team infrastructure, C2 systems, custom tooling, and automation capabilities.
  • Technical Execution Across Attack Lifecycles: Reconnaissance, initial access, exploitation, privilege escalation, credential harvesting, lateral movement, cloud persistence, and data access.
  • Reporting & Communication: Production of high-quality technical and executive-level reports, and delivery of clear verbal debriefs to varied audiences.
  • Collaboration & Knowledge Sharing: Working with internal security teams—Penetration Testing, OT, and IR—to support joint assessments, share offensive insights, and improve overall defensive posture.
  • Research & Development: Continuous investigation of new techniques, vulnerabilities, adversary tradecraft, cloud attack paths, and contributions to internal Red Team methodology and tooling.
  • Team Development & Mentorship: Supporting growth of colleagues through technical guidance, knowledge sharing, review, and encouragement of offensive security skill development.

KEY TASKS:

  • Work with the red team manager to plan, design, and deliver full-scope Red Team engagements, from reconnaissance through to achieving agreed objectives.
  • Build, configure, and operate Red Team infrastructure, including command-and-control frameworks such as Mythic, Cobalt Strike, or Havoc.
  • Conduct exploitation, post-exploitation, lateral movement, and persistence activities across on-premises, hybrid, and cloud estates.
  • Identify weaknesses across infrastructure, Active Directory, cloud platforms (Azure/AWS/GCP), and application layers.
  • Develop or modify offensive tooling, scripts, payloads, and automation to support engagements.
  • Produce clear, detailed, and technically accurate Red Team reports, including findings, impact assessments, and remediation advice.
  • Support client briefings and debriefings, explaining attack paths and defensive recommendations to both technical and non-technical stakeholders.
  • Collaborate with penetration testers during blended or purple team operations.
  • Stay current with emerging attacker TTPs, threat intelligence, cloud exploitation techniques, and novel abuse paths.
  • Mentor junior consultants and support capability development across the offensive security team.

KEY RESULTS/OBJECTIVES:

  • Successfully deliver full-scope Red Team engagements that meet defined objectives, maintain operational security, and provide meaningful, actionable outcomes for clients.
  • Consistently produce high-quality technical and executive reporting that clearly communicates attack paths, business impact, and remediation priorities.
  • Demonstrate measurable improvements in client detection, response, and resilience through collaborative purple team activities and post-engagement reviews.
  • Enhance Prism Infosec’s offensive capability by contributing to methodology development, tooling improvements, research, and internal knowledge sharing.
  • Maintain a strong understanding of emerging attacker techniques, cloud exploitation paths, and relevant threat intelligence, applying this knowledge to ongoing operations.
  • Support the delivery of penetration testing engagements when required, ensuring the same high standard of technical execution and reporting.
  • Promote a culture of continuous learning by mentoring junior consultants, participating in internal training sessions, and contributing to team development.
  • Strengthen client relationships through professionalism, technical credibility, and consistent delivery excellence.
  • Achieve or maintain CCRTS/CCRTM qualifications to support regulated testing in the UK.

RESPONSIBLE FOR STAFF/EQUIPMENT: Any assets provided by the company e.g. Laptop, hard drives etc. Testing and lab systems, Office keys and entry fob.

CONSULTS WITH: Head of Red Team, members of the test team.

TERM OF EMPLOYMENT: Permanent Full Time.

WORKPLACE TYPE: Based in the UK - Remote, able to travel into Cheltenham office sporadically.

QUALIFICATION:

  • 2+ years of hands-on experience delivering Red Team operations, advanced penetration testing, or adversary simulation engagements.
  • Strong proficiency with at least one major C2 framework (e.g., Mythic, Cobalt Strike, Havoc) and a solid understanding of operational security and detection evasion.
  • Demonstrable ability to conduct end-to-end offensive operations: reconnaissance, exploitation, post-exploitation, privilege escalation, lateral movement, and persistence.
  • Practical experience targeting cloud environments including Azure, AWS, and/or GCP, with understanding of hybrid identity and cloud-native attack paths.
  • Strong technical knowledge of Active Directory, identity abuse, Kerberos-based attacks, and common enterprise exploitation routes.
  • Experience writing or modifying offensive tools, scripts, payloads, automation, or implants in languages such as Python, PowerShell, or C#.
  • Excellent written and verbal communication skills, capable of producing high-quality reports and presenting findings to technical and non-technical stakeholders.
  • Ability to work within a team environment, collaborate effectively with penetration testers, and support blended offensive engagements.
  • Willingness and capability to conduct traditional penetration testing engagements when required.
  • Strong analytical thinking, creativity, and a proven ability to approach problems from an adversary’s perspective.
  • Industry recognised certifications such as CCT-APP, CCT-INF, CCRTS, OSCP, OSEP, OSCE, RTO / RTO-II, CREST-equivalent quals, or similar high‑rigour offensive credentials.
  • Experience delivering or supporting intelligence‑led or regulatory‑driven assessments such as CBEST, STAR‑FS, TIBER‑EU, or iCAST.
  • Knowledge of containerisation and orchestration technologies (e.g., Docker, Kubernetes) from both an attacker and defender perspective.
  • Experience contributing to open‑source offensive tooling, blog posts, conference talks, or broader community engagement.
  • Understanding of defensive operations, detection engineering, logging pipelines, and SOC methodologies, particularly in purple team scenarios.
  • Experience operating within consultancy environments where autonomy, breadth of skill, and adaptability are highly valued.

Senior Security Consultant in Cheltenham employer: Prism Infosec

At Prism Infosec, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to excel in the dynamic field of cybersecurity. As a Senior Security Consultant, you will not only lead cutting-edge Red Team engagements but also benefit from continuous learning opportunities, mentorship, and the chance to contribute to the evolution of our offensive security methodologies. With a flexible remote working arrangement and the option to connect with colleagues at our Cheltenham office, you'll be part of a passionate team dedicated to making a meaningful impact in the cybersecurity landscape.
Prism Infosec

Contact Detail:

Prism Infosec Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Security Consultant in Cheltenham

✨Network Like a Pro

Get out there and connect with people in the cybersecurity field! Attend meetups, conferences, or even online webinars. The more you engage with like-minded folks, the better your chances of landing that Senior Security Consultant role.

✨Show Off Your Skills

When you get the chance to chat with potential employers, don’t hold back! Share your experiences with Red Team engagements and any cool projects you've worked on. Let them see your passion for offensive security and how you think like an adversary.

✨Tailor Your Approach

Before any interview, do your homework on Prism Infosec. Understand their values and what they’re looking for in a Senior Security Consultant. Tailor your conversation to show how your skills and experiences align with their mission and culture.

✨Apply Through Our Website

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Prism Infosec team.

We think you need these skills to ace Senior Security Consultant in Cheltenham

Red Team Engagement Delivery
C2 Framework Proficiency (Mythic, Cobalt Strike, Havoc)
Offensive Security Operations
Cloud Environment Targeting (Azure, AWS, GCP)
Active Directory Knowledge
Scripting and Tool Development (Python, PowerShell, C#)
Technical Report Writing
Communication Skills
Collaboration with Penetration Testers
Adversarial Thinking
Analytical Skills
Creativity
Industry Recognised Certifications (OSCP, CREST-equivalent)
Containerisation and Orchestration Knowledge (Docker, Kubernetes)
Defensive Operations Understanding

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Security Consultant role. Highlight your relevant experience in Red Team operations and any specific tools you've worked with, like Mythic or Cobalt Strike. We want to see how your skills align with what we're looking for!

Show Off Your Technical Skills: When detailing your experience, be specific about the technical skills you bring to the table. Mention your hands-on experience with offensive security techniques and any programming languages you're proficient in. This is your chance to shine, so don't hold back!

Communicate Clearly: Since you'll be producing reports and presenting findings, it's crucial to demonstrate your communication skills in your application. Use clear and concise language, and make sure your writing reflects your ability to explain complex concepts to both technical and non-technical audiences.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at Prism Infosec!

How to prepare for a job interview at Prism Infosec

✨Know Your Stuff

Make sure you brush up on your technical skills, especially around Red Team operations and the specific tools mentioned in the job description like Mythic or Cobalt Strike. Be ready to discuss your hands-on experience with these frameworks and how you've applied them in real-world scenarios.

✨Showcase Your Adversarial Thinking

Prepare to demonstrate your ability to think like an attacker. Bring examples of past engagements where you identified vulnerabilities and exploited them creatively. This will show that you can approach problems from an adversary's perspective, which is crucial for this role.

✨Communicate Clearly

Since you'll be producing reports and presenting findings, practice explaining complex technical concepts in simple terms. Think about how you would communicate your findings to both technical and non-technical stakeholders, as this is a key part of the job.

✨Be a Team Player

Collaboration is key at Prism Infosec, so be prepared to discuss how you've worked with others in previous roles. Highlight any experiences where you supported blended offensive operations or mentored junior colleagues, as this aligns with their team development goals.

Senior Security Consultant in Cheltenham
Prism Infosec
Location: Cheltenham
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>