 
        
        Offensive Security Specialist
Locations: Salford Quays / Staines / Central London (Hybrid)
Employment type: Full time – 37.5 hours per week.
Salary: £51,200 - £64,000 (depending on experience & location).
Status: Permanent.
Working model: Flexible / Hybrid working options.
Role Overview
As an Offensive Security Specialist, you will be part of a team responsible for testing, measuring, and reporting on the effectiveness of security controls used across the Bupa IT estate against known adversarial tactics and techniques. You will do this by designing, running and analysing the output of assessments utilising our chosen Breach and Attack Simulation platform and by consuming additional data from multiple sources such as Red Team and Penetration Testing reports, Vulnerability Scanning platforms, and other tools that will identify misconfigurations within the Bupa infrastructure that represent a potential security risk. You will also perform a leading role in designing test strategies based on the MITRE ATT&CK framework, using internal and external Threat Intelligence and your own knowledge and experience of corporate network environments.
What You’ll Do
 * Reviewing and analysing findings from multiple data sources to assess their impact and determine remediation priorities.
 * Developing remediation plans for high-priority vulnerabilities, using your offensive security expertise to identify potential attack paths.
 * Collaborating across teams to disrupt those paths effectively, leveraging both your technical knowledge and that of others.
 * Influencing stakeholders including technology owners and remediation teams to commit to and implement remediation strategies.
 * Perform risk analysis on test data to ensure the most critical issues are addressed first, aligning with frameworks like MITRE ATT&CK and the Unified Kill Chain.
 * Use threat intelligence to guide future assessments, ensuring testing is relevant to current controls and risks.
 * Utilise BAS platforms and engage in continuous self-learning through provided resources to maintain your credibility and expertise.
 * Partner with internal and external SMEs across Security Operations, Engineering, Threat Intelligence, and Vulnerability Management to design effective solutions.
 * Mentor and guide colleagues, sharing knowledge and influencing others to resolve identified weaknesses.
 * Lead small projects, ensuring timely and accurate implementation of solutions, and design unbiased methods to validate their effectiveness.
 * Challenge and improve existing processes, contributing to documentation and reporting using tools like Kibana, Lucene, and Python.
 * Communicate technical findings clearly to Risk teams and other stakeholders, ensuring risks are well understood and documented.
What You’ll Bring
 * Experience within any of the following IT Security disciplines: Security Operations, Red teaming, Penetration Testing, Security Engineering, along with expert knowledge of various enterprise technologies/infrastructure including network architectures, operating systems and security controls.
 * Confident in their technical expertise and can present themselves as a technically competent SME.
 * Exposure to Security Monitoring and Security Control technologies.
 * Exposure to Threat Intelligence sources.
 * Good experience of typical enterprise security services including but not limited to:
 o Threat Intelligence
 o Penetration testing
 o Anti‑malware
 o Email/SPAM management
 o Authentication mechanisms
 o SIEM
 o WAF
 o Firewalls
 o Proxy technologies
 o IDS/IPS
 o DLP
 * Has a track record of technical delivery within a fast paced & pressured environment.
 * Engages key stakeholders well.
 * Effective communicator.
 * ‘not afraid to ask’ mentality.
Benefits
Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health – from mental and physical, to financial, social and environmental wellbeing.
 * 25 days holiday, increasing through length of service, with option to buy or sell.
 * Bupa health insurance as a benefit in kind.
 * An enhanced pension plan and life insurance.
 * Onsite gyms or local discounts where no onsite gym available.
 * Various other benefits and online discounts.
Equal Opportunity and Diversity
We encourage all of our people to “Be you at Bupa”, we champion diversity, and we understand the importance of our people representing the communities and customers we serve. That’s why we especially encourage applications from people with diverse backgrounds and experiences. Bupa is a Level 2 Disability Confident Employer and will aim to offer an interview/assessment to disabled applicants who best meet the minimum criteria for the role. We’re committed to ensuring you’re treated fairly during the recruitment process and offer reasonable adjustments to anyone who may benefit from accommodations.
#J-18808-Ljbffr