Senior Cyber Security Engineer - Red Team
This role creates and tests red-team labs, ranges, and learning content that simulate real-world attacks and teach offensive-security concepts. It requires several years of penetration-testing or offensive-security experience, strong MITRE ATT&CK knowledge, and broad technical cybersecurity skills.
About the job
Responsibilities
- Plan, write, and improve offensive-security labs, challenges, and online learning content for the Immersive One platform.
- Produce practical exercises, questions, and gamified learning content in multiple formats.
- Test red-team labs and ranges to ensure they function as expected.
- Research vulnerabilities, tools, and offensive tactics, then turn findings into practical and theory-based labs.
- Translate technical research into concise, understandable content for technical and non-technical audiences.
- Collaborate with the wider Product team on projects, product innovations, and deployment approaches.
Requirements
- Several years of experience in offensive security as a penetration tester or offensive security consultant.
- In-depth knowledge of the MITRE ATT&CK framework and its use in enterprise threat defense.
- Strong understanding of networking, computing, and cybersecurity concepts.
- Ability to use examples and analogies to simplify complex subjects and create realistic simulations.
- Strong problem-solving skills and an inclination toward prototyping, iteration, and experimentation.
Nice-to-haves
- Familiarity with Linux, Docker, and Python.
Compensation and benefits
- Remote and flexible working.
- 25 days of annual leave, plus 2 volunteering days and a birthday day off.
- Holiday allowance increasing to 30 days after five years.
- Enhanced parental leave, mindfulness groups, critical illness cover, 7% matched pension, and private healthcare.
- Career and learning development support, including a professional development fund and a “Learn Anything” fund.
- Recognition and rewards programs.
- Flexible start and finish times and reduced-hours options.
- Team events, railcard loan, and cycle scheme.
Skills
Red Teaming, Penetration Testing, Mitre Att&Ck, Networking, Linux, Docker, Python, Cybersecurity, Vulnerability Research, Offensive Security, Threat Modeling
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.