Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team
Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team requirement for an urgent start. The Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team will be working for a major global financial client, supporting an offensive security function focused on deep manual testing, vulnerability research and frontier-model-assisted discovery across a complex, highly regulated technology estate.
Penetration Tester - Vulnerability Research - AI Offensive Security - Exploit Development - Red Team Key Skills:
- Strong hands-on offensive security background, with proven senior-level experience delivering manual penetration tests across web applications, APIs, infrastructure, cloud and internal networks
- Demonstrable vulnerability research capability, including source code review, reverse engineering, fuzzing and the discovery of novel issues beyond automated scanner output
- Practical experience using frontier AI/LLM tooling to accelerate reconnaissance, code and log analysis, payload generation and hypothesis testing, with the judgement to validate and discard model output
- Proven exploit development and validation experience, safely proving impact and chaining findings to demonstrate realistic attack paths rather than reporting theoretical risk
- Risk-based triage and prioritisation skills, translating technical findings into business impact, exploitability ratings and clear, actionable remediation guidance for engineering teams
- Strong understanding of MITRE ATT&CK, OWASP Top 10/ASVS, CVSS and threat modelling techniques, with experience running structured, objective-led testing campaigns
- Experience testing cloud-native and hybrid environments (Azure, AWS, GCP), containers, CI/CD pipelines and identity layers (eg Entra ID, OAuth/OIDC, SAML, MFA)
- Excellent written and verbal communication skills, with the ability to defend findings to engineering, risk, audit and senior leadership stakeholders; industry certifications (eg OSCP, OSCE/OSEP, Crest CCT, GXPN) advantageous
Penetration on Tester - Vulnerability Research - AI-Assisted Offensive Security - Exploit Development - Red Team - Contract inside IR35 - Hybrid - Long-term Programme - Urgent Start