Senior Consultant, Red Team, Offensive Security
Listed on 2026-06-10
-
IT/Tech
Cybersecurity, Security Manager
Senior Consultant, Red Team, Offensive Security – UK
Cybersecurity | London, United Kingdom |
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.
Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We help our clients discover, understand, and remediate security risks across their networks, systems, applications, cloud environments, and identity platforms. Our clients trust us to use advanced offensive security tools, creativity, imagination, and expert knowledge to identify realistic attack paths and improve cyber resilience.
We are looking to grow our UK Red Team capability with a Senior Consultant / L3 Red Team Operator. Our expertise in red team operations, purple team engagements, assumed‑breach testing, adversary emulation, and threat‑intelligence‑led penetration testing is in high demand. Our collaborative ties to our forensic and incident response team, detection engineering team, threat intelligence team, and wider Cyber Risk practice enable us to deliver high‑impact offensive security engagements for clients across a range of sectors.
This role will be based in the UK, with a hybrid working model requiring two days per week in one of our UK offices:
London, Leeds, or Birmingham.
In order to be considered for a position, you must formally apply via
What you’ll do- Deliver red team, purple team, assumed‑breach, and adversary emulation engagements for clients across multiple sectors
- Support engagement planning, including threat‑informed scenarios, attack objectives, rules of engagement, operational security considerations, and success criteria
- Execute hands‑on offensive activity across enterprise environments, including Active Directory exploitation, credential access, privilege escalation, lateral movement, and objective‑based testing
- Assess and exploit attack paths across Microsoft Entra , Microsoft 365, hybrid identity environments, AWS, Azure, GCP, and other cloud platforms where in scope
- Build, adapt, and operate red team infrastructure, command‑and‑control tooling, payloads, and scripts during authorised client engagements
- Apply detection‑aware tradecraft and understand how EDR, SIEM, identity protection, conditional access, email security, and network monitoring can affect red team operations
- Support purple team engagements by executing agreed TTPs, working with client security teams, validating detection logic, and helping clients improve response capability
- Conduct authorised social engineering activity, including reconnaissance, phishing, vishing, pretext development, and controlled initial access scenarios
- Conduct research and development to improve Kroll’s red team tooling, tradecraft, methodology, and reporting
- Produce clear, evidence‑based reporting that explains attack paths, business impact, detection and response observations, and prioritised remediation actions
- Present technical findings to security teams and communicate business risk to senior stakeholders
- Mentor junior consultants, support technical delivery, and contribute to peer review and quality assurance
- Work collaboratively with Kroll’s wider Cyber Risk teams, including incident response, threat intelligence, cloud security, and detection engineering
- 5+ years in offensive cybersecurity, including experience delivering red team, purple team, adversary emulation, or assumed‑breach engagements
- Existing SC clearance, or the ability and willingness to obtain SC clearance
- A relevant CREST red team certification aligned to CBEST‑style delivery, such as CREST Certified Red Team Specialist, formerly CCSAS, or the ability to obtain this within the probation period
- Strong…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: