> Markdown version of [/jobs/ext/103797-offensive-security-researcher-red-team-cloud-saas-exploitation](https://www.wearedevelopers.com/jobs/ext/103797-offensive-security-researcher-red-team-cloud-saas-exploitation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Researcher | Red Team | Cloud & SaaS Exploitation - **Company:** Responsibilitieshunt - **Location:** Warrington, UK - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Continuous Integration, Emulators, Identity and Access Management, Python (Programming Language), Cloud Services, Red Team (Cyber Security), Web Application Security, Web Applications, Google Cloud, Software Security, Vulnerability Analysis, Golang - **Published:** May 25, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/37345440/ ## About the Role Required Skills & ExperienceProven hands-on experience in Offensive Security, Red Teaming, Vulnerability Research, or Adversary SimulationStrong understanding of modern attack surfaces including cloud infrastructure, SaaS platforms, APIs, identity systems, and web applicationsDemonstrated ability to discover high-impact vulnerabilities and complex attack paths beyond known CVEsExperience exploiting cloud identities, IAM misconfigurations, CI/CD pipelines, SSO environments, or internet-exposed servicesStrong knowledge of adversary tradecraft, post-exploitation, lateral movement, privilege escalation, and modern offensive methodologiesScripting or development capability in Python, Go, or similar languages for automation, tooling, exploit development, or offensive researchAbility to operate autonomously in highly technical offensive environmentsDeep technical curiosity with a research-driven attacker mindset Desirable / Bonus ExperienceExploit development experienceCloud exploitation and cloud-native offensive security researchPublic vulnerability disclosures, bug bounty achievements, or original security researchExperience building offensive security tooling or frameworksConference presentations, technical blogs, or published researchKnowledge of detection evasion, offensive automation, or large-scale attack surface analysis Offensive Security, Red Team, Vulnerability Research, Exploit Development, Cloud Security, AWS, Azure, GCP, SaaS Security, Adversary Simulation, Offensive Engineering, Attack Path Analysis, CI/CD Security, Identity Security, Web Application Security, API Security, Python, Go, Exploit Automation, Post-Exploitation, Privilege Escalation, Lateral Movement, Threat Emulation, Security Research, Offensive Tooling, Vulnerability Discovery, Internet-Exposed Infrastructure, Offensive Tradecraft, Penetration Testing, Cloud Exploitation ## Description Join a cutting-edge Offensive Security team focused on uncovering high-impact vulnerabilities across modern attack surfaces. We're looking for an experienced Offensive Security Researcher / Red Team Operator who thrives in complex, real-world environments and enjoys discovering novel attack paths beyond known CVEs.This is a highly technical opportunity for someone passionate about vulnerability research, cloud exploitation, adversary simulation, exploit development, offensive automation, and advanced tradecraft across cloud-native and internet-facing environments. About the RoleAs an Offensive Security Researcher, you'll identify and weaponise real-world attack paths across Cloud, SaaS, CI/CD pipelines, modern web applications, identity systems, and internet-exposed infrastructure. You'll collaborate with elite offensive practitioners to conduct deep technical research, develop new offensive methodologies, and scale successful attack techniques through automation and tooling.This role is ideal for senior-level offensive security professionals who enjoy autonomy, creative problem solving, vulnerability discovery, exploit research, red teaming, and advanced offensive engineering. Key ResponsibilitiesHunt for high-value vulnerabilities across cloud platforms, SaaS environments, internet-facing infrastructure, APIs, identity systems, and modern applicationsDiscover and exploit complex attack chains beyond publicly known CVEs and commodity techniquesConduct advanced offensive security research into emerging attack vectors, adversary tradecraft, and exploitation methodologiesPerform red team operations and adversary emulation against modern enterprise environmentsDevelop offensive tooling, PoCs, exploit automation, and research frameworks using Python, Go, or similar languagesAutomate vulnerability discovery, exploit validation, reconnaissance, and offensive workflows at scaleCollaborate with Offensive Engineering teams to operationalise successful techniques and improve offensive capabilityResearch cloud-native attack paths across AWS, Azure, GCP, SaaS ecosystems, CI/CD pipelines, and identity providersContribute to blogs, whitepapers, technical research, or conference talks (optional but encouraged) ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)