Cyber Security Offensive Specialist

DAC Beachcroft

West of England

On-site

GBP 70,000 - 95,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

DAC Beachcroft in Bristol is seeking an experienced Cyber Security Offensive Specialist to join the Technology team. You will identify and assess security risks before exploitation, perform penetration testing, and lead adversary simulations to strengthen the firm's cyber resilience.

Reporting to the Head of Cyber Security, you will develop offensive security capabilities, create scripts and tooling, and work with IT and business units to prioritise remediation and improve security controls

Qualifications

  • Hands-on penetration testing across networks, infrastructure, web apps, APIs, and cloud.

Responsibilities

  • Plan and execute authorised penetration tests across internal and external networks, systems, applications, and cloud environments.
  • Conduct red team exercises that simulate real-world attack scenarios to evaluate people, processes, and technology controls.
  • Research and emulate emerging threat actor tactics, techniques, and procedures (TTPs) to ensure testing remains aligned to current threats.
  • Develop and customise scripts, tooling, and exploits to support offensive security engagements.
  • Assess the security of cloud platforms, APIs, web applications, third-party integrations, and enterprise infrastructure.
  • Produce high-quality technical reports and present findings to both technical and non-technical stakeholders.
  • Work closely with IT, Cyber Security, and business teams to prioritise remediation efforts and enhance security controls.
  • Partner with defensive security teams to strengthen detection and response capabilities through shared knowledge and attack simulation activities.
  • Support the development of security standards, policies, and hardening practices informed by offensive security insights.

Skills

Penetration testing
Red team exercises
Threat emulation
Scripting
Python
Java
C#
C++
Reports writing
Stakeholder communication

Education

OSCP
CRTO
CWEE
CEH
Security+
CISSP
CISM

Tools

Burp Suite
Metasploit
Cobalt Strike
Nmap
BloodHound

Job description

Department: Business Services - Technology

Location: Bristol

Join DAC Beachcroft's Cyber Security Team

At DAC Beachcroft, technology plays a critical role in helping our people, business, and clients reach their full potential. As we continue to enhance our cyber security capability, we're looking for an experienced Cyber Security Offensive Specialist to join our growing Technology team in Bristol. Reporting to the Head of Cyber Security, you will play a key role in identifying and assessing security risks before they can be exploited, helping to strengthen the firm's cyber resilience and security posture.

This is an exciting opportunity for a cyber security professional who enjoys thinking like an attacker, uncovering vulnerabilities, and working collaboratively with technical and business stakeholders to improve security outcomes. You'll have the opportunity to conduct penetration testing, lead adversary simulation exercises, influence remediation strategies, and contribute to the ongoing development of DAC Beachcroft's cyber defences.

About DAC Beachcroft

DAC Beachcroft is an international law firm with a broad-based commercial and insurance practice. We combine sector expertise with a forward-thinking approach, delivering exceptional outcomes for clients while investing heavily in our people, processes, and technology.

As part of our Cyber Security function, you'll be joining a team that is committed to innovation, continuous improvement, and staying ahead of an evolving threat landscape.

Key Responsibilities
  • Plan and execute authorised penetration tests across internal and external networks, systems, applications, and cloud environments.
  • Conduct red team exercises that simulate real-world attack scenarios to evaluate people, processes, and technology controls.
  • Research and emulate emerging threat actor tactics, techniques, and procedures (TTPs) to ensure testing remains aligned to current threats.
  • Develop and customise scripts, tooling, and exploits to support offensive security engagements.
  • Assess the security of cloud platforms, APIs, web applications, third-party integrations, and enterprise infrastructure.
  • Produce high-quality technical reports and present findings to both technical and non-technical stakeholders.
  • Work closely with IT, Cyber Security, and business teams to prioritise remediation efforts and enhance security controls.
  • Partner with defensive security teams to strengthen detection and response capabilities through shared knowledge and attack simulation activities.
  • Support the development of security standards, policies, and hardening practices informed by offensive security insights.
Skills, Knowledge and Expertise

We're interested in hearing from professionals who can demonstrate:

Essential Experience
  • Hands-on penetration testing experience across networks, infrastructure, web applications, APIs, and cloud platforms.
  • Experience planning and executing red team or adversary simulation exercises.
  • Strong understanding of identifying and exploiting vulnerabilities across Active Directory, cloud environments, applications, and enterprise systems.
  • Experience using industry-standard offensive security tools such as Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, and related tooling.
  • The ability to develop custom scripts and automation using languages such as Python, Java, C#, or C++.
  • Experience producing clear technical reports and communicating risk effectively to varied stakeholder groups.
  • Experience working within a corporate or enterprise environment where operational impact and risk management are critical considerations.
Desirable Qualifications
  • Offensive Security Certified Professional (OSCP)
  • Certified Red Team Operator (CRTO)
  • Certified Web Exploitation Expert (CWEE)
  • Certified Ethical Hacker (CEH)
  • CompTIA Security+
  • CISSP
  • CISM

A degree in Cyber Security, Computer Science, Information Technology, or a related discipline would also be beneficial.

What We're Looking For
  • A strong analytical mindset and a passion for uncovering vulnerabilities before attackers do.
  • Excellent communication skills with the ability to explain complex technical concepts clearly and effectively.
  • High levels of integrity, professionalism, and accountability when working with sensitive information and systems.
  • A proactive approach to learning, staying current with emerging threats and security research.
  • The ability to work independently while building strong collaborative relationships across teams.
Additional Information

As a Disability Confident Scheme employer, we’re committed to providing an inclusive and accessible recruitment process. If you need any reasonable adjustments at any stage (including the application, assessment or interview process), please contact recruitment@dacbeachcroft.com in confidence with the vacancy reference in the subject line, and we’ll be happy to help.

We are happy to talk flexible working with our Flex Forward scheme. We would encourage you to talk to us about our approach to flexible working during the hiring process if you would like to explore this further.

Note for Recruitment Agencies

DAC Beachcroft manages all vacancies via our in-house recruitment teams, prioritising direct sourcing and referrals. When external support is required, roles are released to selected agencies on our Preferred Supplier List (PSL).

Speculative CVs sent to any DAC Beachcroft employee without prior instruction from our recruitment teams (LLP and CSG) will not be accepted, and no fees will be payable.

For PSL queries, please contact: recruitment@dacbeachcroft.com or csgrecruitment@dacbeachcroft.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Offensive Specialist
Cyber Security Offensive Specialist

DAC Beachcroft LLP • West of England

On-site
GBP 60,000 - 90,000
Client Development Executive
Client Development Executive

DAC Beachcroft • Leeds

Hybrid
GBP 45,000 - 60,000
Flexible working
Client Development Executive
Client Development Executive

DAC Beachcroft • Manchester

Hybrid
GBP 40,000 - 60,000
Disability Confident Scheme
Offensive Security Engineer: Red Team & Pen Testing
Offensive Security Engineer: Red Team & Pen Testing

DAC Beachcroft • West of England

On-site
GBP 70,000 - 95,000
Client Development Executive
Client Development Executive

DAC Beachcroft • West of England

Hybrid
GBP 35,000 - 55,000
Solicitor - Healthcare Regulatory
Solicitor - Healthcare Regulatory

DAC Beachcroft • Newcastle upon Tyne

On-site
GBP 65,000 - 90,000
Directories Manager
Directories Manager

DAC Beachcroft • West of England

On-site
GBP 55,000 - 75,000
Experience and Content Management Executive
Experience and Content Management Executive

DAC Beachcroft • West of England

On-site
GBP 32,000 - 46,000
Client Development Executive
Client Development Executive

DAC Beachcroft • Newcastle upon Tyne

On-site
GBP 30,000 - 45,000
Flex Forward scheme
Flexible working
Solicitor/ Associate - Data, Cyber & Technology Risk
Solicitor/ Associate - Data, Cyber & Technology Risk

DAC Beachcroft • West of England

On-site
GBP 32,000 - 52,000