via Lever · 14 September 2026 ·5 days ago

Senior Security Engineer, Offensive Security

jobgether
UK Full-time
This listing is from Lever
View original listing ↗

Accountabilities:

As a Senior Security Engineer, you will combine hands-on offensive security work with strategic security engineering, helping teams identify risks early and embed security into product and infrastructure development.

  • Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises across products and services.

  • Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance.

  • Retest vulnerabilities to validate that remediation has been successfully implemented.

  • Conduct security reviews and threat modeling across application architecture, designs, code, and emerging AI products.

  • Build and maintain offensive security tooling, automation, security tests, and exploit capabilities to expand testing coverage.

  • Partner with engineering teams to design and implement security architecture, controls, Zero Trust practices, and least-privilege access.

  • Support security programs including automated security design reviews and vulnerability management.

  • Investigate security events, participate in incident response, and contribute to a rotating on-call schedule.

  • Collaborate with product, engineering, and other stakeholders to promote security-by-design practices.

  • Contribute to security roadmaps, monitoring improvements, anomaly detection, compliance initiatives, and security documentation.

  • Own recurring penetration tests and adversary-emulation activities while engaging with external security researchers where appropriate.

  • Help strengthen security practices for cloud infrastructure, containerized environments, and AI/ML systems.

Requirements

The ideal candidate combines strong hands-on offensive security capabilities with software development expertise, cloud security knowledge, and the ability to influence security practices across technical and non-technical teams.

  • 3+ years of experience in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.

  • 2+ years of hands-on software development experience with Python or Golang.

  • Deep knowledge of authentication and authorization, including OAuth, applied cryptography, and Zero Trust principles.

  • Strong practical experience securing cloud environments such as AWS, GCP, or Azure.

  • Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.

  • Proficiency with offensive security tools and techniques, including Burp Suite and OWASP frameworks.

  • Ability to develop security tests, exploits, and proof-of-concepts that identify real-world vulnerabilities.

  • Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.

  • Practical experience using LLMs and agentic tools to automate vulnerability discovery, reconnaissance, and penetration testing workflows.

  • Experience building security programs and automation from the ground up using risk-based prioritization.

  • Experience performing security reviews and developing or improving automated security review processes.

  • Excellent communication skills and the ability to explain complex security concepts to both technical and non-technical stakeholders.

  • Strong understanding of security standards and a commitment to keeping up with emerging security technologies and models.

  • Collaborative mindset with the ability to drive security improvements through cross-functional partnerships.

  • Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO are valued.

  • Published CVEs, original security research, or conference presentations are a plus.

  • Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing is advantageous.

  • Ability to work remotely and operate effectively with a high degree of autonomy.

  • This position does not offer visa sponsorship.
Benefits:
  • Fully remote, remote-first working environment.

  • EU compensation of €118,860–€169,800, plus equity.

  • Flexible scheduling designed to support autonomy and work-life balance.

  • Generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.

  • Home office support to help create a comfortable and effective workspace.

  • Technology stipend equivalent to US$100 net per month.

  • Annual learning and development stipend for conferences, courses, certifications, and professional development.

  • 16 weeks of paid parental leave after six months of employment.

  • Equity for all full-time employees.

  • Comprehensive medical, retirement, and paid holiday benefits, varying by country.

  • Opportunity to work on security challenges spanning cloud infrastructure, containers, AI/ML, and large-scale developer platforms.

  • Offices available in Seattle and Paris for connection and collaboration when relevant.

  • Company merchandise and team perks.

The market for this type of role

Similar openings
79
Engineering roles in UK
Full-time
80%
of Engineering roles in the UK
Remote possible
8%
of Engineering roles
jobgether

200 open positions · Argentina, Austria, Belgium, France, Germany +11

📊 Engineering · the UK
6,544
active jobs
11.9%
Remote
Ø 2d
avg. online
Top skills in demand
ExcelERPISOPythonAWSCI/CDSQLAzureAgileLean

Frequently asked questions

How many Engineering jobs are available in UK?
Currently 79 Engineering roles in UK on AlmostHired, across 26 different companies. Our data is updated daily.
Do Engineering roles offer remote work?
8% of Engineering roles in the UK allow remote work, either partial or full. To filter specifically for remote positions, use AlmostHired.
How do I know if I match this role?
Upload your CV — our AI compares your profile to the job requirements and gives you a precise match score, with matching and missing skills.