Offensive Security and Threat Intelligence Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Step into the world where science meets robust information security. Protect the technology that powers ground-breaking discoveries and be part of the team that safeguards the future of Big Science. Here, you’ll collaborate with leading engineers, researchers, and technologists to tackle the most pressing security challenges in a fast-paced, innovative environment. Every day offers you the chance to defend vital data and systems, ensuring that the pursuit of scientific excellence continues securely and seamlessly.
Discover the difference you can make when you bring your expertise in information security to an organisation at the forefront of global research - working alongside some of the brightest minds and most advanced facilities in the world.
Security
As a minimum, due to the nature of this role, candidates must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process.Please indicate eligibility in the written submission. Candidates not meeting this level of clearance will not be considered.
The level of clearance required is security check .
About the role
The UKRI CIO Group plays a pivotal role in managing and optimising the organisations critical enterprise technical services that underpin and enable UKRI’s business capabilities. Within the group a team of Information Security Experts support the delivery of modern, secure, resilient and scalable services across a larger federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system.
Join us for this rare opportunity to apply your experience in offensive security and threat intelligence in a dynamic, fast-paced security operational and strategic role in an organisation at the heart of research and innovation in the UK. Your broad remit is to identify real-world risks to diverse technical landscapes, uncovering security vulnerabilities, actively exploiting findings, assessing additional impacts through post-exploitation, and providing proactive advice to teams on the most effective remediation strategies. The role encompasses the full scope and delivery of penetration testing, including zero-knowledge network assessments, insider threat evaluations, credentialed application exploitation, and rigorous testing of human and physical security controls across the UKRI estate. In addition to these offensive security responsibilities, the specialist manages the external penetration testing call-off contract to ensure that UKRI receives high-quality, tailored assessments both internally and externally, supporting a continuous programme of security improvement.
Your responsibilities:
- Complete targeted penetration tests and red team exercises to identify exploitable vulnerabilities.
- Develop and maintain offensive tooling to simulate adversary tactics and techniques.
- Monitor and analyse threat intelligence feeds to identify emerging threats and relevant TTPs.
- Produce technical threat reports and briefings to inform security posture and decision-making.
- Conduct proactive threat hunting based on intelligence-led hypotheses and anomaly detection.
- Support risk assessments with insights from offensive operations and threat landscape analysis.
Personal Specification
The below criteria will be scored during Shortlisting (S), Interview (I) or both (S&I).
Applicants will be able todemonstrateskills in line with thecyber securityrisk manager roles using the Government Security Profession career framework ., We’ll assess you against these behaviours during the selection process:
- Managing a quality service
- Changing and improving
- Delivering at pace
- Seeing the Big Picture
Selection Process Details
We know different organisations use different processes, so we wanted you to know what to expect from us.
Stage 0 - Pre-application
If you would like to find out more about the role we encourage prospective applicants to get in touch with us to discuss the opportunity.
Requirements
- Significant hands-on professional experience delivering penetration testing and/or red-team activity across enterprise environments (S&I).
- Deep technical capability across mixed technology environments, including operating systems, networking, identity/authentication, and cloud platforms (e.g. Azure and/or AWS) (S&I).
- Demonstrable proficiency using common offensive security tools and techniques (e.g. Nmap, Burp Suite, Metasploit) to identify and exploit real-world attack paths (S&I).
- Ability to adapt quickly to new technologies, vulnerabilities, and offensive security techniques (S&I).
- Proven ability to produce clear, high-quality penetration testing reports that articulate risk, impact, and remediation for technical and non-technical audiences (I).
- Strong analytical and problem-solving skills, with sound professional judgement when assessing security weaknesses and advising on pragmatic remediation (I).
- Evidence of continued professional development in offensive security, demonstrated through relevant certifications, structured training, or equivalent practical experience (S&I).
Benefits & conditions
We recognise and value our employees as individuals and aim to provide a favourable pay and rewards package. We are committed to supporting employees’ development and promote a culture of continuous learning.
A list of benefits below:
- An outstanding defined benefit pension scheme.
- 30 days’ annual leave in addition to 10.5 public and privilege days (full time equivalent).
- Employee discounts and offers on retail and leisure activities.
- Employee assistance programme, providing confidential help and advice.
- Flexible working options.
Plus many more benefits and wellbeing initiatives that enable our employees to have a great work life balance!
About the company
UKRI is an organisation that brings together the seven disciplinary research councils, Research England and Innovate UK. Together, we build an independent organisation with a strong voice and vision ensuring the UK maintains its world-leading position in research and innovation.
Supporting some of the world’s most exciting and challenging research projects, we develop and operate some of the most remarkable scientific facilities in the world. We are pushing the frontiers of human knowledge through fundamental research and delivering benefits for UK society and the economy through world-class research, skills and business-led innovation., UKRI seeks to ensure it creates and maintains a system of openness, fairness and inclusion - a collaborative, trusted environment, which is attractive to and accessible to everyone who is interested in developing their career with us.
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be rejected and internal candidates may be subject to disciplinary action.
As part of the pre-employment checks there is a requirement to undergo Baseline Personnel Security Screening. BPSS is a pre-condition of employment and failure to achieve it may mean that the employment offer is rescinded. UKRI reserves the right to run, or re-run, security clearance as required during the course of employment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
IT Salaries in UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?