
Offensive Security Senior Manager
- Kingston upon Thames
- Permanent
- Full-time
- Identify and exploit vulnerabilities to simulate real-world attack scenarios, validate detection and response capabilities, and uncover control gaps.
- Develop and maintain a Purple Team playbook tailored to business-specific technologies and threat models.
- Integrate offensive findings into SOC tuning, detection engineering, and control validation workflows.Program Ownership- Own and evolve the offensive security roadmap, including internal testing services, external bug bounty operations, and attack surface management.
- Establish and lead a Purple Team Steering Committee with cross-functional stakeholders from Cyber, OT, R&D, and Business Units.
- Drive quarterly purple team exercises and ensure findings are embedded into the broader Cyber Transformation roadmap.Team Building & Transformation- Build and mentor a high-performing global team of offensive security engineers and red teamers.
- Lead the transformation from traditional pentesting to intelligence-driven, continuous offensive security.
- Foster a culture of innovation, experimentation, and continuous learning.Collaboration & Influence- Partner with Threat Intelligence, SOC, and Engineering teams to contextualize findings and drive remediation.
- Communicate technical findings clearly to both technical and executive audiences.
- Influence security architecture and product design through early engagement and threat modeling.Requirements
- Advanced Penetration Testing: Deep experience conducting and leading penetration tests across web applications, APIs, cloud environments (Azure, AWS, GCP), and enterprise infrastructure.
- Red and Purple Teaming: Expertise in adversary emulation, threat-informed defense, and purple team exercises that validate detection and response capabilities.
- Attack Surface Management: Familiarity with ASM platforms and methodologies to continuously identify, assess, and reduce external exposure.
- Bug Bounty Program Management: Experience managing or collaborating with external bug bounty platforms (e.g., HackerOne, Bugcrowd), including triage and remediation workflows.
- Exploit Development & Vulnerability Research: Ability to identify and exploit zero-day and known vulnerabilities, and develop custom proof-of-concept exploits.
- Tool Proficiency:
- Offensive tools: Cobalt Strike, Metasploit, Burp Suite, Nmap, BloodHound, Covenant, Sliver
- Scripting: Python, PowerShell, Bash
- Automation: CI/CD integration for security testing, custom tooling for red team automation
- Detection Engineering Collaboration: Ability to translate offensive findings into detection logic and partner with SOC teams to improve alerting and response.
- Threat Modelling & MITRE ATT&CK: Strong understanding of attacker TTPs and ability to map findings to frameworks like MITRE ATT&CK and the Cyber Kill Chain.
- Cloud Security Testing: Hands-on experience with offensive techniques in cloud-native environments, including IAM misconfigurations, container escape, and serverless exploitation.
- Security Control Validation: Experience assessing the effectiveness of EDR, WAF, IAM, and other security controls through offensive testing.
- Deep hands-on experience with red/purple teaming, adversary emulation, and vulnerability exploitation.
- Proficiency with tools such as Cobalt Strike, Metasploit, Burp Suite, BloodHound, and custom scripting.
- Strong understanding of MITRE ATT&CK, cyber kill chain, and threat-informed defense.
- Experience integrating offensive security into CI/CD pipelines and cloud-native environments.
- Relevant certifications (e.g., OSCP, OSCE, CRTO, GXPN) strongly preferred.BehavioursCandidates would be required to demonstrate the Unilever Standards of Leadership & live the Values through showing the following behaviors:
- Agility – Flexes leadership style and plans to meet changing situations with urgency. Learns from the past, envisions the future, has a healthy dissatisfaction with the status quo.
- Personal Mastery – Actively builds wellbeing and resilience in themselves and their team. Has emotional intelligence to take feedback, manage mood and motivations, and build empathy for others. Sets high standards for themselves and always brings their best self.
- Passion for High Performance – Inspires the energy needed to win, generating intensity and focus to motivate people to deliver results at speed.