> Markdown version of [/jobs/ext/3195959-cyber-security-offensive-specialist](https://www.wearedevelopers.com/jobs/ext/3195959-cyber-security-offensive-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Offensive Specialist - **Company:** DAC Beachcroft - **Location:** Bristol, UK - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, Application Programming Interfaces (APIs), Software System Penetration Testing, Burp Suite, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, CompTIA Security+, Cyber Security, Python (Programming Language), Nmap, Red Team (Cyber Security), Web Applications, Scripting, Enterprise Software Applications, Cloud Platform System, Information Technology, Metasploit, Integration Frameworks - **Published:** September 3, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=345d575a25d2b165 ## About the Role * Hands-on penetration testing experience across networks, infrastructure, web applications, APIs, and cloud platforms. * Experience planning and executing red team or adversary simulation exercises. * Strong understanding of identifying and exploiting vulnerabilities across Active Directory, cloud environments, applications, and enterprise systems. * Experience using industry-standard offensive security tools such as Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, and related tooling. * The ability to develop custom scripts and automation using languages such as Python, Java, C#, or C++. * Experience producing clear technical reports and communicating risk effectively to varied stakeholder groups. * Experience working within a corporate or enterprise environment where operational impact and risk management are critical considerations. One or more of the following certifications would be advantageous: * Offensive Security Certified Professional (OSCP) * Certified Red Team Operator (CRTO) * Certified Web Exploitation Expert (CWEE) * Certified Ethical Hacker (CEH) * CompTIA Security+ * CISSP * CISM A degree in Cyber Security, Computer Science, Information Technology, or a related discipline would also be beneficial. Alongside your technical expertise, you'll bring: * A strong analytical mindset and a passion for uncovering vulnerabilities before attackers do. * Excellent communication skills with the ability to explain complex technical concepts clearly and effectively. * High levels of integrity, professionalism, and accountability when working with sensitive information and systems. * A proactive approach to learning, staying current with emerging threats and security research. * The ability to work independently while building strong collaborative relationships across teams. ## Description At DAC Beachcroft, technology plays a critical role in helping our people, business, and clients reach their full potential. As we continue to enhance our cyber security capability, we're looking for an experienced Cyber Security Offensive Specialist to join our growing Technology team in Bristol. Reporting to the Head of Cyber Security, you will play a key role in identifying and assessing security risks before they can be exploited, helping to strengthen the firm's cyber resilience and security posture. This is an exciting opportunity for a cyber security professional who enjoys thinking like an attacker, uncovering vulnerabilities, and working collaboratively with technical and business stakeholders to improve security outcomes. You'll have the opportunity to conduct penetration testing, lead adversary simulation exercises, influence remediation strategies, and contribute to the ongoing development of DAC Beachcroft's cyber defences. DAC Beachcroft is an international law firm with a broad-based commercial and insurance practice. We combine sector expertise with a forward-thinking approach, delivering exceptional outcomes for clients while investing heavily in our people, processes, and technology. As part of our Cyber Security function, you'll be joining a team that is committed to innovation, continuous improvement, and staying ahead of an evolving threat landscape., * Plan and execute authorised penetration tests across internal and external networks, systems, applications, and cloud environments. * Conduct red team exercises that simulate real-world attack scenarios to evaluate people, processes, and technology controls. * Research and emulate emerging threat actor tactics, techniques, and procedures (TTPs) to ensure testing remains aligned to current threats. * Develop and customise scripts, tooling, and exploits to support offensive security engagements. * Assess the security of cloud platforms, APIs, web applications, third-party integrations, and enterprise infrastructure. * Produce high-quality technical reports and present findings to both technical and non-technical stakeholders. * Work closely with IT, Cyber Security, and business teams to prioritise remediation efforts and enhance security controls. * Partner with defensive security teams to strengthen detection and response capabilities through shared knowledge and attack simulation activities. * Support the development of security standards, policies, and hardening practices informed by offensive security insights. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Introduction to sCrypt - a smart contract language for Bitcoin SV](https://www.wearedevelopers.com/videos/24-introduction-to-scrypt-a-smart-contract-language-for-bitcoin-sv) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)