Bachelor's degree or equivalent practical experience.
5 years of experience in cybersecurity, with an offensive security (e.g., Red Teaming, Penetration Testing, or Adversary Simulation) or threat modeling.
Experience in a Security Operations Centre (SOC) or similar environment, with modern threat landscapes and attack techniques.
Experience in technical troubleshooting and writing code in one or more programming languages.
Experience in threat modeling methodologies (e.g., STRIDE, PASTA, or attack trees) and secure system design principles.
United Kingdom Security Vetting Developed Vetting (DV) clearance.
Preferred qualifications:
Certifications in OSCE3, CRTP/CRTE, GIAC GCSA/Kubernetes-related, OSCP, OSCE, CRTO, CISSP, or GIAC (e.g., GPEN, GCTI, GWAPT).
Experience designing or executing Purple Team exercises, combining offensive tactics with defensive feedback to drive continuous improvement.
Experience with Kubernetes security, including secure cluster configuration, workload hardening, and threat detection in containerised environments.
Experience in building or maturing security culture initiatives, including awareness programs, gamified training, or executive engagement.
Experience with security testing tools and frameworks (e.g., MITRE ATT&CK, Cobalt Strike, Metasploit, Burp Suite, or similar).