Offensive Security Manager
barlowe llp
📍 london uk united kingdom🕐 7d ago🔗 workday
Job Description
We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity.
From our London HQ, we unite world-class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we’re building a world-class platform to amplify our teams’ most powerful ideas.
Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale.
Take the next step in your career.
### The role
We are looking for an Offensive Security Manager (Penetration Testing) to establish and grow our offensive security capability.
You will lead a team responsible for testing the firm's highest-priority systems, using hands-on offensive techniques to demonstrate whether our security controls can withstand a capable attacker.
The team is being established and expanded with a focus on hands-on penetration testing and offensive engineering. AI and automation will play a central role in closing the gaps left by point-in-time testing.
This is a build-it, own-it, prove-it role. Rather than inheriting an established programme, you will define what a mature offensive security function looks like, setting direction, raising the bar for methodology and evolving the team beyond request-driven testing toward continuous, evidence-based assurance.
**Key responsibilities**
Key responsibilities of the role include:
* Leading, developing and growing a team of offensive security engineers and penetration testers
* Owning and delivering the offensive security testing programme across the firm’s highest-priority systems, balancing recurring assessments with testing new and changing services
* Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required
* Driving offensive testing methodologies, from scope definition through to safe validation of real-world attack paths and control effectiveness
* Establish attack-chain validation and continuous purple teaming with detection and response teams
* Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling
* Overseeing physical and social engineering assessment where appropriate
* Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement
* Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility
### Who are we looking for?
**Technical experience**
* Strong hands-on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure
* Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems
* Experience defining testing scope, rules of engagement and threat-led, attack chain-based assessments
* Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing
**Leadership and delivery**
* Experience leading or developing technical teams, including performance management and coaching
* Strong judgement in prioritising work, balancing risk, impact and competing demands
* Experience building teams and evolving ways of working as the function matures
**Communication and influence**
* Strong communication skills, with the ability to explain offensive findings and drive remediation
* Ability to influence technical decisions through credibility, evidence and collaboration
### Why join us?
* Highly competitive compensation plus annual discretionary bonus
* Lunch provided via Just Eat for Business and dedicated barista bar
* 35 days’ annual leave
* 9% company pension contributions
* Informal dress code and excellent work-life balance
* Comprehensive healthcare and life assurance
* Cycle-to-work scheme
* Monthly company events
_G-Research is committed to cultivating and preserving an inclusive work environment. We are an ideas-driven business and we place great value on diversity of experience and opinions._
_We want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation please let us know in the relevant section_