Cyber Security Offensive Specialist
Summary
In-house offensive security role at DAC Beachcroft's Bristol Technology team: plan and run penetration tests and red team/adversary simulation exercises across networks, cloud, applications, and APIs, then report findings and guide remediation with IT and business stakeholders. Key tools include Burp Suite, Metasploit, Cobalt Strike, Nmap, and BloodHound, with scripting in Python, Java, C#, or C++
Join DAC Beachcroft's Cyber Security Team
About DAC Beachcroft
- Plan and execute authorised penetration tests across internal and external networks, systems, applications, and cloud environments.
- Conduct red team exercises that simulate real-world attack scenarios to evaluate people, processes, and technology controls.
- Research and emulate emerging threat actor tactics, techniques, and procedures (TTPs) to ensure testing remains aligned to current threats.
- Develop and customise scripts, tooling, and exploits to support offensive security engagements.
- Assess the security of cloud platforms, APIs, web applications, third-party integrations, and enterprise infrastructure.
- Produce high-quality technical reports and present findings to both technical and non-technical stakeholders.
- Work closely with IT, Cyber Security, and business teams to prioritise remediation efforts and enhance security controls.
- Partner with defensive security teams to strengthen detection and response capabilities through shared knowledge and attack simulation activities.
- Support the development of security standards, policies, and hardening practices informed by offensive security insights.
Essential Experience
- Hands-on penetration testing experience across networks, infrastructure, web applications, APIs, and cloud platforms.
- Experience planning and executing red team or adversary simulation exercises.
- Strong understanding of identifying and exploiting vulnerabilities across Active Directory, cloud environments, applications, and enterprise systems.
- Experience using industry-standard offensive security tools such as Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, and related tooling.
- The ability to develop custom scripts and automation using languages such as Python, Java, C#, or C++.
- Experience producing clear technical reports and communicating risk effectively to varied stakeholder groups.
- Experience working within a corporate or enterprise environment where operational impact and risk management are critical considerations.
Desirable Qualifications
- Offensive Security Certified Professional (OSCP)
- Certified Red Team Operator (CRTO)
- Certified Web Exploitation Expert (CWEE)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- CISSP
- CISM
What We're Looking For
- A strong analytical mindset and a passion for uncovering vulnerabilities before attackers do.
- Excellent communication skills with the ability to explain complex technical concepts clearly and effectively.
- High levels of integrity, professionalism, and accountability when working with sensitive information and systems.
- A proactive approach to learning, staying current with emerging threats and security research.
- The ability to work independently while building strong collaborative relationships across teams.