Senior Cyber Security Operator

Alexander Mann Solutions
London, UK
6 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Active Directory Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Continuous Integration Azure Active Directory Red Team (Cyber Security) Software Vulnerability Management Web Applications Office365 SC Clearance
+2 more
Server Operating Systems & Platforms Vulnerability Analysis

Job description

On behalf of The Ministry of Justice, we are looking for a Senior Cyber Security Operator Inside IR35 for a 12 Month Remote Contract with occasional visits to the London Office

An active SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. (Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active security clearance.)

The Role

You will conduct safe, simulated cyber-attack simulations against our technology estates, acting as a real-world adversary might, to test our defences, highlight weaknesses and contribute cyber security expertise and insight in support of the department’s strategic security decision-making functions. You will be familiar with exploitation methodologies across a wide range of technologies, from classic enterprise technology stacks to modern digital services. You will have a well-developed ability to tactically assess and to execute a diversity of attack types, including chained attacks and evasion techniques, to achieve your desired goal.

You have a keen instinct for evading detection and avoiding disruption to MoJ’s operations.

Key Responsibilities . Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the Ministry of Justice. Adopting a red team approach, discovering high-impact weaknesses across the organisation’s most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively. . Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making. . Development and implementation of tools and methodologies to augment and to automate team offensive and analytical capability. . Mentoring junior Red Team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in the department.

Requirements

Essential . Proven ability to plan and execute complex, multi-phase operations. . Scenario-driven adversary simulation . Threat intelligence analysis and assessment . Exploitation of a wide range of technologies, including infrastructure, web application and cloud platforms: Microsoft Entra, Active Directory, M365, macOS.Kubernetes, CI/CD, AWS, Azure. . Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets . Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft . Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex Legacy and modern enterprise environments. . Experience using, developing and deploying tools in support of red teaming activities, including attack infrastructure, C2 frameworks and infrastructure-as-code technologies. . Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences, including senior stakeholders, in support of vulnerability management, threat mitigation, and risk-based decision-making. . Participation in GCASE/GBEST/CBEST/TIBER engagements.

Desirable . Experience in threat and/or vulnerability research, including publication and presentation to the wider cyber security community. . Background in a related a discipline, such as protective monitoring, incident response, security engineering or security architecture. . Certifications in the field of red team: CCSAS, CRTL

Please be aware that this role can only be worked within the UK and not Overseas.

Disability Confident

As a member of the Disability Confident Scheme, MOJ guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. This scheme encourages candidates with a disability and/or neurodivergence to apply. In exceptional circumstances, we may also need to apply the desirable criteria in our shortlisting process which may include holding active security clearance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:52 min

Addressing junior hiring bottlenecks and mitigating widespread employee burnout

Hung Lee Hung Lee +3 · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all