Offensive Security Manager

barlowe llp

📍 london uk united kingdom🕐 7d ago🔗 workday

Job Description

We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world-class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve.  Together we’re building a world-class platform to amplify our teams’ most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. ### The role We are looking for an Offensive Security Manager (Penetration Testing) to establish and grow our offensive security capability. You will lead a team responsible for testing the firm's highest-priority systems, using hands-on offensive techniques to demonstrate whether our security controls can withstand a capable attacker. The team is being established and expanded with a focus on hands-on penetration testing and offensive engineering. AI and automation will play a central role in closing the gaps left by point-in-time testing. This is a build-it, own-it, prove-it role. Rather than inheriting an established programme, you will define what a mature offensive security function looks like, setting direction, raising the bar for methodology and evolving the team beyond request-driven testing toward continuous, evidence-based assurance. **Key responsibilities** Key responsibilities of the role include: * Leading, developing and growing a team of offensive security engineers and penetration testers * Owning and delivering the offensive security testing programme across the firm’s highest-priority systems, balancing recurring assessments with testing new and changing services * Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required * Driving offensive testing methodologies, from scope definition through to safe validation of real-world attack paths and control effectiveness * Establish attack-chain validation and continuous purple teaming with detection and response teams * Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling * Overseeing physical and social engineering assessment where appropriate * Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement * Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility ### Who are we looking for? **Technical experience** * Strong hands-on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure * Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems * Experience defining testing scope, rules of engagement and threat-led, attack chain-based assessments * Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing **Leadership and delivery** * Experience leading or developing technical teams, including performance management and coaching * Strong judgement in prioritising work, balancing risk, impact and competing demands * Experience building teams and evolving ways of working as the function matures **Communication and influence** * Strong communication skills, with the ability to explain offensive findings and drive remediation * Ability to influence technical decisions through credibility, evidence and collaboration ### Why join us? * Highly competitive compensation plus annual discretionary bonus * Lunch provided via Just Eat for Business and dedicated barista bar * 35 days’ annual leave * 9% company pension contributions * Informal dress code and excellent work-life balance * Comprehensive healthcare and life assurance * Cycle-to-work scheme * Monthly company events _G-Research is committed to cultivating and preserving an inclusive work environment. We are an ideas-driven business and we place great value on diversity of experience and opinions._ _We want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation please let us know in the relevant section_
Offensive Security Manager at barlowe llp | MergeJobs | MergeJobs