At a Glance
- Tasks: Uncover high-impact vulnerabilities in cloud and SaaS environments while collaborating with elite security practitioners.
- Company: Join a cutting-edge Offensive Security team focused on real-world attack surfaces.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Ideal for tech-savvy individuals who thrive in dynamic, autonomous environments.
- Why this job: Make a real impact by discovering novel attack paths and enhancing security methodologies.
- Qualifications: Experience in offensive security, red teaming, and vulnerability research is essential.
The predicted salary is between 70000 - 90000 £ per year.
Join a cutting-edge Offensive Security team focused on uncovering high-impact vulnerabilities across modern attack surfaces. We’re looking for an experienced Offensive Security Researcher / Red Team Operator who thrives in complex, real-world environments and enjoys discovering novel attack paths beyond known CVEs.
This is a highly technical opportunity for someone passionate about vulnerability research, cloud exploitation, adversary simulation, exploit development, offensive automation, and advanced tradecraft across cloud-native and internet-facing environments.
About the Role
As an Offensive Security Researcher, you’ll identify and weaponise real-world attack paths across Cloud, SaaS, CI/CD pipelines, modern web applications, identity systems, and internet-exposed infrastructure. You’ll collaborate with elite offensive practitioners to conduct deep technical research, develop new offensive methodologies, and scale successful attack techniques through automation and tooling.
This role is ideal for senior-level offensive security professionals who enjoy autonomy, creative problem solving, vulnerability discovery, exploit research, red teaming, and advanced offensive engineering.
Key Responsibilities
- Hunt for high-value vulnerabilities across cloud platforms, SaaS environments, internet-facing infrastructure, APIs, identity systems, and modern applications.
- Discover and exploit complex attack chains beyond publicly known CVEs and commodity techniques.
- Conduct advanced offensive security research into emerging attack vectors, adversary tradecraft, and exploitation methodologies.
- Perform red team operations and adversary emulation against modern enterprise environments.
- Develop offensive tooling, PoCs, exploit automation, and research frameworks using Python, Go, or similar languages.
- Automate vulnerability discovery, exploit validation, reconnaissance, and offensive workflows at scale.
- Collaborate with Offensive Engineering teams to operationalise successful techniques and improve offensive capability.
- Research cloud-native attack paths across AWS, Azure, GCP, SaaS ecosystems, CI/CD pipelines, and identity providers.
- Contribute to blogs, whitepapers, technical research, or conference talks (optional but encouraged).
Required Skills & Experience
- Proven hands-on experience in Offensive Security, Red Teaming, Vulnerability Research, or Adversary Simulation.
- Strong understanding of modern attack surfaces including cloud infrastructure, SaaS platforms, APIs, identity systems, and web applications.
- Demonstrated ability to discover high-impact vulnerabilities and complex attack paths beyond known CVEs.
- Experience exploiting cloud identities, IAM misconfigurations, CI/CD pipelines, SSO environments, or internet-exposed services.
- Strong knowledge of adversary tradecraft, post-exploitation, lateral movement, privilege escalation, and modern offensive methodologies.
- Scripting or development capability in Python, Go, or similar languages for automation, tooling, exploit development, or offensive research.
- Ability to operate autonomously in highly technical offensive environments.
- Deep technical curiosity with a research-driven attacker mindset.
Desirable / Bonus Experience
- Exploit development experience.
- Cloud exploitation and cloud-native offensive security research.
- Public vulnerability disclosures, bug bounty achievements, or original security research.
- Experience building offensive security tooling or frameworks.
- Conference presentations, technical blogs, or published research.
- Knowledge of detection evasion, offensive automation, or large-scale attack surface analysis.
Offensive Security Researcher | Red Team | Cloud & SaaS Exploitation in York employer: Unity Systems
Join a pioneering Offensive Security team that values innovation and technical excellence, where your expertise in vulnerability research and cloud exploitation will be highly regarded. Our collaborative work culture fosters creativity and autonomy, providing ample opportunities for professional growth through challenging projects and knowledge sharing. Located in a vibrant tech hub, we offer a dynamic environment that encourages continuous learning and the development of cutting-edge offensive methodologies.
StudySmarter Expert Advice🤫
We think this is how you could land Offensive Security Researcher | Red Team | Cloud & SaaS Exploitation in York
✨Tip Number 1
Network like a pro! Attend industry meetups, conferences, or online webinars. Chat with fellow offensive security enthusiasts and share your experiences; you never know who might have a lead on your dream job!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, research, or any cool exploits you've developed. This is your chance to demonstrate your technical prowess and creativity in real-world scenarios.
✨Tip Number 3
Don’t just apply anywhere—apply through our website! Tailor your application to highlight how your experience aligns with the role of Offensive Security Researcher. We love seeing candidates who are genuinely interested in what we do.
✨Tip Number 4
Prepare for technical interviews by brushing up on your knowledge of cloud exploitation and modern attack surfaces. Practice explaining your thought process while solving problems, as this will showcase your deep technical curiosity and research-driven mindset.
We think you need these skills to ace Offensive Security Researcher | Red Team | Cloud & SaaS Exploitation in York
Some tips for your application 🫡
Show Your Passion:When writing your application, let your enthusiasm for offensive security shine through! We want to see your genuine interest in vulnerability research and cloud exploitation. Share any personal projects or experiences that highlight your passion for the field.
Tailor Your CV:Make sure your CV is tailored to the role of Offensive Security Researcher. Highlight relevant skills and experiences that align with our job description, especially those related to cloud platforms, SaaS environments, and exploit development. We love seeing how your background fits with what we do!
Be Specific About Your Skills:Don’t just list your skills; provide examples of how you’ve used them in real-world scenarios. Whether it’s discovering vulnerabilities or developing offensive tooling, we want to know the nitty-gritty details of your experience. This helps us understand your capabilities better!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re proactive and keen to join our team!
How to prepare for a job interview at Unity Systems
✨Know Your Attack Vectors
Before the interview, brush up on the latest attack vectors and vulnerabilities in cloud environments and SaaS platforms. Be ready to discuss specific examples of how you've discovered and exploited these vulnerabilities in your past work.
✨Showcase Your Technical Skills
Prepare to demonstrate your scripting or development skills in Python or Go. You might be asked to solve a technical problem on the spot, so practice coding challenges related to exploit development or automation to showcase your expertise.
✨Discuss Your Research Mindset
Be prepared to talk about your approach to vulnerability research and how you stay updated with emerging threats. Share any personal projects or contributions to the security community, like blogs or conference talks, to highlight your passion for the field.
✨Collaborative Spirit is Key
This role involves working closely with other offensive practitioners. Be ready to discuss how you’ve collaborated in the past, whether it’s through red teaming exercises or developing offensive methodologies, and emphasise your ability to work autonomously while still being a team player.