At a Glance
- Tasks: Join our Red Team to attack networks and improve client security.
- Company: Rapid7, a leader in cybersecurity with a collaborative culture.
- Benefits: Competitive salary, professional development, and opportunities to attend industry conferences.
- Why this job: Make a real impact by uncovering vulnerabilities and enhancing security for clients.
- Qualifications: 5+ years in security roles, expert in penetration testing, and strong communication skills.
- Other info: Dynamic team environment with opportunities for mentorship and growth.
The predicted salary is between 48000 - 72000 £ per year.
Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defence strategies.
About the Team
Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defence-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.
About the Role
Your primary responsibility is to deliver Rapid7’s Vector Command Continuous Red Teaming service. In this role, you will investigate emerging threats, uncover novel vulnerabilities across large external attack surfaces, and attempt to breach customer perimeter defenses to gain initial access. When new N-day or zero-day vulnerabilities emerge, this role rapidly analyzes them, recreates proof-of-concepts, and assesses customer environments for exposure. Between these high-priority efforts, the researcher actively hunts for novel vulnerabilities and unique attack paths across customer attack surfaces to support initial access operations.
- Evaluate large external attack surfaces to identify vulnerabilities that enable initial access.
- Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.
- Analyze, develop, and exploit N-day and newly released zero-day vulnerabilities relevant to customer environments.
- Identify novel attacks through black-box evaluation of customer web applications, leading to initial access or exposure of sensitive data.
- Develop and maintain positive relationships with clients and understand their business and needs.
- Participate in industry conferences and professional organizations.
- Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices.
- Translate technical concepts and convey them to non-security personnel.
- Mentor and coach junior staff to promote growth, project contributions, and knowledge sharing.
- Meet professional practice standards and demonstrate exceptional skill in core service areas.
The skills and qualities you’ll bring include:
- 5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience.
- Expert knowledge of modern penetration testing tools and methods.
- Network and web-based application security concepts.
- Windows/Linux/UNIX internals.
- Exploit research and development.
- Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.).
- Technical competencies, including previous technical consulting experience.
- High quality report writing and peer reviewing.
- Strong knowledge of common regulatory structures and obligations and common I.T. governance.
- The ability to effectively lead teams of penetration testers while on engagements.
- Be comfortable explaining findings and recommendations to technical and non-technical audiences including C-Level and Board briefings.
- Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet-facing attack surfaces.
- Certifications such as OSCP, OSCE, GXPN, OSEE, CREST.
- Experience with Red & Purple Teams.
- Excellent communication skills both with internal and external stakeholders.
- Collaborative mindset, contributing to knowledge sharing and cross training.
- Demonstrate a commitment to the "end-to-end" testing process, from the initial pre-engagement planning to providing accountable support during the final remediation phase.
Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.
Senior Security Consultant, Emergent Threat & Exploit Researcher in Belfast employer: Rapid7
Contact Detail:
Rapid7 Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Consultant, Emergent Threat & Exploit Researcher in Belfast
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the industry. Attend meetups, conferences, or even online webinars. The more people you know, the better your chances of landing that dream job.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects or any cool exploits you've developed. This is your chance to demonstrate your expertise and make a lasting impression on potential employers.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each company. Research their security posture and mention how your skills can specifically help them improve. This shows you're genuinely interested and not just sending out generic applications.
✨Tip Number 4
Finally, apply through our website! We love seeing candidates who are proactive about their job search. Plus, it gives you a direct line to us, making it easier for you to stand out from the crowd.
We think you need these skills to ace Senior Security Consultant, Emergent Threat & Exploit Researcher in Belfast
Some tips for your application 🫡
Show Off Your Skills: When you're writing your application, make sure to highlight your technical skills and experience in penetration testing. We want to see how you’ve tackled challenges in the past and what tools you’re comfortable using.
Tailor Your Application: Don’t just send a generic application! Tailor it to the role by mentioning specific experiences that relate to the job description. We love seeing how your background aligns with our needs at Rapid7.
Be Clear and Concise: Keep your writing clear and to the point. We appreciate well-structured applications that are easy to read. Avoid jargon unless it’s relevant, and make sure your passion for security shines through!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team!
How to prepare for a job interview at Rapid7
✨Know Your Tools Inside Out
Make sure you’re well-versed in modern penetration testing tools and methods. Familiarise yourself with the latest exploits and how they can be applied to real-world scenarios. This will not only help you answer technical questions but also demonstrate your hands-on experience.
✨Showcase Your Problem-Solving Skills
Prepare to discuss specific instances where you've identified vulnerabilities or crafted novel attack chains. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it clear how your actions led to successful outcomes.
✨Understand the Client's Perspective
Research the company and its clients before the interview. Be ready to discuss how you would approach their unique security challenges and how your experience aligns with their needs. This shows that you’re not just technically skilled but also client-focused.
✨Communicate Clearly and Confidently
Practice explaining complex technical concepts in simple terms. You might need to convey findings to non-technical stakeholders, so being able to articulate your thoughts clearly is crucial. Mock interviews with friends or colleagues can help you refine this skill.