Job Search and Career Advice Platform

Enable job alerts via email!

Offensive Security Engineer

CHAMP Cargosystems

England

On-site

GBP 60,000 - 80,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A global IT solutions provider is seeking an Offensive Security Engineer to establish a Product Security Team. The ideal candidate, with over 8 years of experience in software development and application security, will drive penetration testing and oversee secure software development practices. You will integrate security into CI/CD and mentor team members in an agile environment. Proficiency in Java and relevant security certifications are required. Join us to help shape the security posture of our software products.

Qualifications

  • 8+ years in software development and application security.
  • Hands-on experience with Java web applications.
  • Certifications such as OSCP or CISSP, CISM.

Responsibilities

  • Drive penetration testing capability and secure software development practices.
  • Oversee vulnerability remediation integrated into CI/CD.
  • Mentor team members, ensuring security is embedded in every sprint.

Skills

Secure development practices
Threat modeling
Vulnerability management
SAST/DAST tools
Excellent communication
Agile/SCRUM leadership

Education

Bachelor's or Master's in Software Engineering, Cybersecurity

Tools

Java
CI/CD
Job description
Overview

CHAMP Cargosystems provides the most comprehensive range of integrated IT solutions and distribution services for the air cargo transport chain. Our portfolio spans core management systems, messaging services, and eCargo solutions. These include applications designed to meet customs and security requirements, quality optimization, as well as e‑freight and mobility needs. Our products and services are recognized globally under the Cargospot and Traxon brands.

We serve over 200 airlines and GSAs, connecting them with approximately 3,000 forwarders and GHAs worldwide. Our solutions help customers, and their clients, adapt to the critical and ongoing changes in air transport logistics and meet the demands of global trade.

Headquartered in Luxembourg, CHAMP Cargosystems operates offices in Reading, Zurich, Frankfurt, Manila, Singapore, and Atlanta.

We are looking for an Offensive Security Engineer to join our Security & GRC team.

The role will be reporting to the Security Architect.

Responsibilities

We are seeking an Offensive Security Engineer to establish and guide our Product Security Team. The successful candidate will drive our penetration testing capability, our secure software development practices, oversee vulnerability remediation, and build automated offensive security capabilities integrated into our agile CI/CD environment. Working within the SCRUM methodology, the Offensive Security Engineer will ensure that security is embedded into every sprint, release, and product lifecycle stage. As our SaaS products are primarily developed in Java‑based web applications, the ideal candidate will bring hands‑on experience in software development and a strong understanding of secure coding practices in Java and modern web technologies.

Security governance & development enablement
  • Establish secure coding standards, reusable libraries, and best practices for Java web application development.
  • Collaborate with product owners and developers to integrate security requirements into user stories.
  • Provide guidance on threat modeling and secure design during sprint planning.
  • Ensure security tasks are prioritized alongside functional requirements in the agile backlog.
Offensive security & testing
  • Build and oversee internal penetration testing capabilities for web applications and APIs.
  • Ensure each release in the CI/CD chain undergoes automated and manual security testing.
  • Expand testing scope to infrastructure and cloud environments as maturity grows.
  • Continuously simulate attacker techniques to validate product resilience.
Tooling & automation
  • Drive adoption of SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) solutions, with emphasis on Java and web application frameworks.
  • Integrate automated security testing into CI/CD pipelines.
  • Oversee development of unit test frameworks with embedded security checks.
Compliance & reporting
  • Align product security practices with compliance frameworks (ISO27001, SOC2, NIS2, EU AI Act, etc.).
  • Collaborate with Compliance and IT Security teams to maintain certifications and audit readiness.
  • Provide leadership with clear reporting on product security posture, vulnerabilities, and remediation progress.
Agile management
  • Define backlog items related to security improvements, vulnerability remediation, and testing initiatives.
  • Facilitate sprint planning, daily stand‑ups, retrospectives, and ensure delivery of security objectives.
  • Mentor and coach team members, fostering a culture of collaboration and continuous improvement.
Knowledge, skills, and abilities
  • Strong knowledge of secure development practices, threat modeling, and vulnerability management.
  • Hands‑on experience with SAST/DAST tools and CI/CD integration.
  • Excellent communication skills to engage developers, auditors, and executives.
  • Proven experience leading teams in agile/SCRUM environments.
Education and Experience
  • Bachelor's or Master's degree in Software Engineering, Cybersecurity, or related field.
  • 8+ years of experience in software development and application security, with hands‑on exposure to Java web applications.
  • Certifications such as OSCP or CISSP, CISM.
  • Experience in SaaS environments and cloud‑native security.
  • Familiarity with compliance frameworks (ISO27001, SOC2, NIS2, EU AI Act).
  • Ability to balance strategic vision with hands‑on technical leadership.

The selected candidate may be subject to the provision of an up‑to‑date (not older than 3 months) criminal record certificate.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.