×
Register Here to Apply for Jobs or Post Jobs. X

Executive Principal Consultant - Red Team

Job in Cheltenham, Gloucestershire, GL50, England, UK
Listing for: NCC Group
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant
Salary/Wage Range or Industry Benchmark: 110000 - 150000 GBP Yearly GBP 110000.00 150000.00 YEAR
Job Description & How to Apply Below
Executive Principal Consultant - Red Team

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: G  Cheltenham Jessop House

Reporting To: Lloyd Bruce

Description

As an Executive Principal Consultant within the Red Teaming practice
, you’ll take a leading role in delivering high-end adversary simulation engagements for clients with mature security postures and critical risk profiles. You'll operate across the entire attack lifecycle—from initial access and evasion of EDR, through lateral movement and objective completion—while ensuring the safety, confidentiality, and operational integrity of every engagement.

You’ll also contribute to our capability development, tooling, and methodologies, while mentoring the next generation of Red Teamers and representing NCC Group in client-facing engagements, including with C-level stakeholders.

Key Responsibilities

Engagement Delivery

  • Design, plan, and execute advanced adversary simulation and Red Team engagements aligned with industry standards and regulatory frameworks (e.g., CBEST, TIBER, CORIE, AASE, iCAST, FEER).
  • Maintain a strong focus on operational security and risk mitigation throughout delivery.
  • Communicate risks and safety concerns to clients clearly and proactively before and during operations.
  • Use both off-the-shelf and custom-built tools to achieve objectives and evade detection.
  • Create and maintain custom scripts or tools to automate Red Team activities or exploit environment-specific weaknesses.

Reporting and Communication

  • Produce high-quality, narrative-driven reports that convey technical detail, context, and actionable insight to both technical and non-technical audiences.
  • Deliver detailed debriefs and presentations to security teams and C-level stakeholders.
  • Translate complex attack chains into engaging, informative documentation.
  • Collaboration and Stakeholder Management
  • Work autonomously on smaller engagements and collaboratively on large-scale, multi-phase assessments.
  • Build strong, lasting relationships with clients and internal teams.
  • Support sales and scoping activity where required, contributing to technical pre-sales conversations.

Capability Development

  • Share knowledge and develop internal Red Team capabilities through collaboration, tooling contributions, and process improvements.
  • Keep abreast of emerging TTPs, threat actors, and detection technologies, evaluating and integrating relevant techniques.

Mentorship and Thought Leadership

  • Act as a mentor and knowledge resource for junior consultants and cross-functional teams.
  • Promote a culture of learning, safety, and excellence within the Red Team practice.
Skills, Knowledge and Expertise

Essential:

  • Demonstrable experience delivering high-complexity Red Team engagements end-to-end.
  • Deep understanding of the adversary lifecycle and common tactics, techniques, and procedures (TTPs).
  • Familiarity with evasion techniques and bypassing controls such as EDR/EPP, email/web gateways, proxies, etc.
  • Experience in stakeholder engagement, with the ability to brief both security professionals and executive stakeholders.
  • Excellent written English and ability to create structured, compelling reporting documents.

Proficiency across multiple relevant technical domains:

  • Microsoft Active Directory
  • Office 365 security mechanisms
  • Cloud security (AWS, Azure, GCP)
  • MacOS and mixed environments

Desirable:

  • Experience working under regulatory testing frameworks such as:
  • CBEST, TIBER-EU, CORIE, AASE, iCAST, or FEER
  • Experience in the design or development of Red Team tooling or automation.
  • Familiarity with UK and international cybersecurity frameworks, regulations, and best practices.

Preferred Qualifications:

  • CREST CCSAS / CCRTS (Simulated Attack Specialist)
  • CREST CCSAM / CCRTM (Simulated Attack Manager)
Benefits

We…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary