Location
Canary Wharf, London
Hours
Hybrid working with the expectation to attend the office as business needs require
Salary
Negotiable
About the Role
This role reports to the Head of Information Security and requires a fast-learning, self-motivated individual to enhance capability and capacity within a small but highly effective team. You will play a key part in implementing and improving structured, systematic, and audited approaches to Information Security across the firm. The role involves conducting thorough Red Team offensive penetration testing on both on-premises and cloud IT infrastructure to identify vulnerabilities and recommend remediation. You will perform security assessments on cloud-based applications, IoT devices, SmartBuilding digital landscapes, data lakes, web-based APIs, and applications. Additionally, you will execute red team exercises simulating real-world attack scenarios to test detection and response capabilities.
You will collaborate with cross-functional teams and wider stakeholders to develop testing models, including for Generative A.I security, and help reduce vulnerabilities to minimize security incidents. Preparing detailed reports and presentations for both technical and non-technical stakeholders is a key responsibility. You will assist in developing and maintaining security policies, procedures, and guidelines, support certification activities such as ISO27001, SOC2, and Cyber Essentials Plus, and engage with external industry partners to stay aligned with best practices.
This pivotal role requires you to be an integral part of an innovative, diverse, and ambitious team, supporting colleagues to become informed security contacts and helping resolve security issues. You will also research and analyse existing security policies to identify training needs and participate in the evaluation and implementation of security testing technologies.
Experience
Comprehensive experience and knowledge in security testing and red teaming, with the ability to communicate concepts effectively within the firm. Proven background in conducting a wide range of security testing and red team activities, providing advice and guidance to the business. Experience coordinating external security requirements and driving continuous improvement in security services. Skilled in assessing and documenting risks, engaging with stakeholders at various seniority levels, and aligning Information Security with business objectives. Experience in developing and using structured documentation including process, format, logical content, and version control.
About you
Organised and able to manage and prioritise multiple concurrent assignments. Fast learner, self-motivated, and able to work collaboratively within a small team. Strong interpersonal skills to maintain good working relations and build bridges even in challenging circumstances. Proactive in staying informed about emerging threats and trends, integrating this knowledge into security testing processes. Committed to supporting an inclusive and team-based approach to work.
Qualifications
A degree-level education is likely but not essential. Professional certifications such as CREST, CHECK, OSCP, OSWE, OSWA, or full membership status with the IISP are highly advantageous. The role may require security clearance in the future. Experience supporting certification activities such as ISO27001, SOC2, and Cyber Essentials Plus is beneficial.
Clifford Chance











