> Markdown version of [/jobs/ext/2066974-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/2066974-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Engineer - **Company:** London Construction Jobs - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Software System Penetration Testing, Cyber Security, Open Web Application Security, Software Engineering, Mitre Att&ck, Cybercrime - **Published:** August 15, 2026 - **Apply:** https://www.totaljobs.com/job/security-engineer/london-stock-exchange-job107848618 ## About the Role * Technology related Bachelor's Degree or equivalent experience and certifications in cyber security * Background in Red Teaming / Penetration Testing / Bug Bounty advantageous! * Experience building AI agentic workflows or deploying and managing security tooling is also advantageous! * Understanding of large scale enterprise IT system environments * Knowledge of security vulnerabilities and common software engineering flaws and Network Defence analytical models (Kill Chain, ATT&CK, OWASP top 10etc.) * Strong verbal & written communication skills & presentation skills * Ability to work in a fast-paced environment as a problem solver and barrier breaker with initiative ## Description This opportunity within the Offensive Security Operations team is a crucial role for the management of vulnerability discovery, offensive testing and remediation activities across the group which protects the business from sophisticated cyber threats! The role holder will work with our 3rd party vendors to plan and facilitate our testing programmes ensuring they run efficiently. The programmes in scope for the role include: * Regulatory Threat Intelligence Led Pen Testing (TLTP) and Red teaming * Bug Bounty * Continuous External Attack Surface Management * Active Directory security posture management * Any programme launched in the future aimed at driving down cyber risk at scale The applicant will be a domain authority on vulnerability testing, impact and remediation. They will provide insight on root cause analysis and scalable risk management. This role requires working closely within a technical team and with external teams like BISOs, GSOC and regulators. The candidate will stay ahead of emerging cyber security thought leadership and share their ideas for areas of improvement and innovation that drive continuous cyber security risk improvement. In this role there are opportunities to explore and experiment with how AI and other types of automation can be used to improve our existing and future initiatives. WHAT YOU'LL BE DOING: * Collaborate with external vendors, regulators and leadership teams coordinating the timely delivery of requirements * Review vulnerability reports, validate issues reported and triage based on risk * Support teams in understanding vulnerabilities and validate fixes through retesting * Coordinate remediation efforts by detailing actions, owners, timelines and follow up when appropriate * Leverage engineering skills to automate and scale security programme objectives ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)