Cyber Security Offensive Specialist

Company: DAC Beachcroft
Apply for the Cyber Security Offensive Specialist
Location: Bristol
Job Description:

Overview

In this role, you will identify and assess security risks by thinking like a potential attacker to strengthen the firm’s cyber resilience. You will conduct penetration tests, lead adversary simulations, and collaborate with IT, cyber security, and business teams to drive remediation and improved controls. You’ll shape offensive security practices while aligning with defensive capabilities to advance the firm’s security posture. This is a chance to impact security outcomes across networks, cloud, and applications in a collaborative, innovative environment.

Pay / Benefits

  • hybrid work
  • permanent contract
  • focus on cyber security capability
  • inclusive recruitment
  • opportunity to influence security posture

Responsibilities

  • Plan and execute authorised penetration tests across internal and external networks, systems, applications, and cloud environments
  • Lead red team/adversary simulation exercises to test people, processes, and technology controls
  • Research and emulate emerging threat actor TTPs to keep testing aligned with current threats
  • Develop and customise scripts, tooling, and exploits to support offensive engagements
  • Assess security of cloud platforms, APIs, web applications, third-party integrations, and enterprise infrastructure
  • Produce high-quality technical reports and communicate findings to technical and non-technical stakeholders
  • Collaborate with IT, Cyber Security, and business teams to prioritise remediation and strengthen controls
  • Partner with defensive security teams to improve detection/response through attack simulations
  • Support development of security standards, policies, and hardening practices informed by offensive insights

Key requirements

  • Hands-on penetration testing experience across networks, infrastructure, web apps, APIs, and cloud
  • Experience planning and executing red team or adversary simulation exercises
  • Strong ability to identify and exploit vulnerabilities in AD, cloud, apps, and enterprise systems
  • Experience with Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound and related tooling
  • Ability to develop custom scripts/automation using Python, Java, C#, or C++
  • Experience producing clear technical risk-oriented reports for varied stakeholders
  • Experience in a corporate/enterprise environment with operational risk considerations
  • Strong analytical mindset
  • Excellent communication skills to explain complex concepts
  • High integrity, professionalism, and accountability
  • Burp Suite
  • Metasploit
  • Cobalt Strike

Posted: September 14th, 2026