Cyber Security Analyst

Lancesoft Europe·United Kingdom·Posted 4d ago·via Talent.com

RegionUK
Apply Now

Job description

Description:

Principal Offensive Security Operator

Enable Skills-Based Hiring No MOJ Managing Business Unit try { var fgTooltip = new FG.Tooltip({ element: $('#cf_descz18112611030889983998905'), text: "Please enter the name of the business unit that is managing the worker in this role as it may differ from the business unit where the cost is associated to" }).initialize(); } catch(err) {} Additional Details

  • Senior Interim Hire : No
  • MOJ Managing Business Unit : MOJ | Chief Financial Officer Group | Digital and Technology
  • Region : Outer London
  • Requisition Type : 1. New Requirement
  • Name of Nominated Worker : (No Value)
  • Please provide any additional information specific to this role : The Role You will conduct safe, simulated cyber-attack simulations against our technology estates, acting as a real-world adversary might, to test our defences, highlight weaknesses and contribute cyber security expertise and insight in support of the department s strategic security decision-making functions. You will be familiar with exploitation methodologies across a wide range of technologies, from classic enterprise technology stacks to modern digital services. You will have a well-developed ability to tactically assess and to execute a diversity of attack types, including chained attacks and evasion techniques, to achieve your desired goal. You have a keen instinct for evading detection and avoiding disruption to MoJ s operations. Key Responsibilities Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the Ministry of Justice. Adopting a red team approach, discovering high-impact weaknesses across the organisation s most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively. Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making. Development and implementation of tools and methodologies to augment and to automate team offensive and analytical capability. Mentoring junior Red Team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in the department. Person Specification Essential Proven ability to plan and execute complex, multi-phase operations. Scenario-driven adversary simulation Threat intelligence analysis and assessment Exploitation of a wide range of technologies, including infrastructure, web application and cloud platforms: Microsoft Entra, Active Directory, M365, macOS. Kubernetes, CI/CD, AWS, Azure. Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex legacy and modern enterprise environments. Experience using, developing and deploying tools in support of red teaming activities, including attack infrastructure, C2 frameworks and infrastructure-as-code technologies. Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences, including senior stakeholders, in support of vulnerability management, threat mitigation, and risk-based decision-making. Participation in GCASE / GBEST / CBEST / TIBER engagements. Desirable: Experience in threat and/or vulnerability research, including publication and presentation to the wider cyber security community. Background in a related a discipline, such as protective monitoring, incident response, security engineering or security architecture. Certifications in the field of red team: CCSAS, CRTL
  • If any professional qualifications are required for the role, please list certificates here: : Experience in threat and/or vulnerability research, including publication and presentation to the wider cyber security community. Background in a related a discipline, such as protective monitoring, incident response, security engineering or security architecture. Certifications in the field of red team: CCSAS, CRTL
  • Desired Skill 1 : TECH & DIGITAL|Cyber / Information Security
  • Desired Skill 2 : (No Value)
  • Desired Skill 3 : (No Value)
  • Desired Skill 4 : (No Value)
  • Desired Skill 5 : (No Value)
  • Are there any Health and Safety requirements or hazards associated to this role? : No
  • If yes, please specify the Health and Safety Considerations : (No Value)
  • Is the role in or out of scope of IR35? : In Scope
  • Level of screening : SC (Security Clearance)
  • Internal Job Title : Principal Offensive Security Operator
  • Grade : 6
  • AMS Job Category : Technology|Cyber Security Manager
  • Equivalent Permanent Grade : Ministry Of Justice (MOJ MOJ)|Grade 6 / G6
  • Armed Forces Covenant Signatory : Yes
  • Disability Confident Level : Yes - Leader (L3)
  • Business Unit Name Hierarchy : Ministry of Justice|Ministry of Justice|Chief Financial Officer Group|Digital and Technology
  • Business Unit Code Hierarchy : MOJ|MOJ MOJ|MOJ MOJ CFO|MOJ MOJ CFO DaT

first seen 2026-08-21 04:00:01 · last verified 2026-08-25 04:00:01


pentestcareers.com // breach the job market

Cyber Security Analyst at Lancesoft Europe | Pentest Careers