Senior Offensive Security Engineer

DRW

City Of London

On-site

GBP 90,000 - 130,000

Full time

16 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DRW is seeking a Senior Offensive Security Engineer to lead red team engagements, penetration tests, and adversary simulations across trading systems, IT, and cloud platforms. You will design tooling, translate findings into actionable improvements, and work closely with security, infrastructure, and trading teams to strengthen defenses.

You will help shape DRW’s offensive security approach, stay ahead of evolving threats, and mentor other engineers while advancing the firm’s security maturity.

Qualifications

  • 5+ years of hands-on offensive security experience including full engagement lifecycle: reconnaissance, initial access, privilege escalation, lateral movement, persistence, exfiltration.
  • Strong scripting or programming ability for building/adapting offensive tooling.
  • Solid understanding of networking fundamentals and OS internals (Windows, macOS, Linux); cloud platforms.
  • Practical experience with common offensive security tools and a track record of building custom tooling when needed.
  • Working knowledge of MITRE ATT&CK, adversary emulation, and detection evasion; ability to translate findings into risk for engineers and executives.
  • Experience with smart contract auditing and blockchain security.
  • Familiarity with AI/ML security risks including prompt injection and model manipulation.

Responsibilities

  • Plan and execute red team engagements and adversary simulations against trading systems, IT, and cloud environments, aligning with MITRE ATT&CK.
  • Conduct comprehensive penetration tests across networks, web and internal apps, APIs, and cloud infrastructure, delivering clear remediation guidance.
  • Design and build custom tooling and exploits to simulate attacker behavior and validate detections.
  • Collaborate with Security Engineering and SOC teams in purple-team exercises to close gaps.
  • Run social engineering and phishing simulations to improve security awareness.
  • Identify, validate, and track vulnerabilities through remediation with stakeholders.
  • Present results and risk narratives to technical teams and senior leadership.
  • Stay current on threat landscape and offensive tooling; contribute to DRW's security roadmap.
  • Assess AI/LLM-integrated systems security and harden them alongside product teams.
  • Leverage AI-assisted tooling to accelerate reconnaissance and exploit development.
  • Help mature DRW’s offensive security methodology, standards, and tooling; mentor others.

Skills

5+ years of offensive security
Scripting & programming
Networking fundamentals
Windows/macOS/Linux internals
MITRE ATT&CK familiarity
Clear reporting
AI/ML security awareness
Collaborative mindset
Blockchain security experience

Tools

Cobalt Strike
Metasploit
BloodHound
Burp Suite
Nmap

Job description

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

About the Role

DRW is building out its offensive security capability, and we’re looking for a Senior Offensive Security Engineer to lead the charge. In this role, you’ll plan and execute red team engagements, penetration tests, and adversary simulations against our trading infrastructure, corporate environment, and cloud platforms, acting as a trusted adversary who helps us find and fix weaknesses before anyone else does.

You’ll work closely with our security, infrastructure, and trading teams to translate what you find into real improvements, and you’ll help shape the methodology, tooling, and roadmap for offensive security at DRW as the function matures. This is a hands-on, high-trust role for someone who thinks like an attacker, communicates like a partner, and cares about making the firm measurably harder to compromise.

What You'll Do

  • Plan and execute red team engagements and adversary simulations against trading systems, corporate IT, and cloud environments, modeling realistic attacker tactics, techniques, and procedures (TTPs) mapped to frameworks such as MITRE ATT&CK
  • Conduct penetration tests across networks, web and internal applications, APIs, and cloud infrastructure, and report findings with clear, actionable remediation guidance
  • Design and build custom tooling, scripts, and exploits to emulate adversary behavior, test control effectiveness, and validate detection coverage
  • Partner with the Security Engineering and SOC teams in purple-team exercises to close gaps between what attackers can do and what defenders can see
  • Run social engineering and phishing simulations to assess and improve organizational security awareness
  • Identify, validate, prioritize, and track vulnerabilities and control weaknesses through to remediation in collaboration with infrastructure, platform, and application owners
  • Present engagement results and risk narratives to both technical teams and senior leadership in a way that drives action
  • Stay current on the threat landscape, emerging TTPs, and offensive tooling, and bring that knowledge back into DRW’s defenses
  • Assess the security of AI and LLM-integrated systems, including prompt injection, model manipulation, data poisoning, and abuse of agentic workflows, and work with teams building these systems to harden them
  • Leverage AI-assisted tooling to accelerate reconnaissance, vulnerability discovery, and exploit development, and evaluate new AI-powered offensive techniques as they emerge
  • Help define and mature DRW’s offensive security methodology, standards, and tooling, and mentor other engineers on the security team

What We're Looking For

  • 5+ years of hands-on experience in offensive security, penetration testing, or red teaming, including full engagement lifecycle work: reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
  • Strong scripting or programming ability for building and adapting offensive tooling
  • Solid understanding of networking fundamentals, Windows, macOS, and Linux internals, identity providers, and cloud platforms
  • Practical experience with common offensive security tools (e.g., Cobalt Strike, Metasploit, BloodHound, Burp Suite, Nmap) and a track record of building your own when the situation calls for it
  • Working knowledge of the MITRE ATT&CK framework, adversary emulation, and detection evasion techniques, along with enough understanding of defensive controls and tooling to help defenders improve
  • A track record of clear, precise reporting and communication and you can translate technical findings into risk that both engineers and executives understand
  • Experience with smart contract auditing and blockchain security
  • Familiarity with AI/ML security risks, including adversarial attacks on models, prompt injection, and the offensive and defensive implications of LLM-powered tooling
  • A collaborative mindset: you see red teaming as a way to make the whole organization more secure, not just to find flaws

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice .

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in DRW ’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability.

A "recently separated veteran" means any veteran during the three‑year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer
Senior Offensive Security Engineer

DRW • Greater London

On-site
GBP 120,000 - 190,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

DRW Holdings, LLC • Greater London

Hybrid
GBP 120,000 - 180,000
Risk Product Analyst
Risk Product Analyst

DRW • Greater London

On-site
GBP 85,000 - 110,000
Trade Support Specialist - Cumberland Options
Trade Support Specialist - Cumberland Options

DRW • Greater London

On-site
GBP 60,000 - 90,000
Senior Database Engineer - Postgres
Senior Database Engineer - Postgres

DRW • Greater London

On-site
GBP 90,000 - 140,000
Threat Specialist
Threat Specialist

DRW • Greater London

On-site
GBP 55,000 - 90,000
Threat Specialist
Threat Specialist

Drweng • Greater London

On-site
GBP 60,000 - 85,000
Threat Specialist
Threat Specialist

DRW • City Of London

On-site
GBP 60,000 - 90,000
Senior Offensive Security Engineer - Red Team Lead
Senior Offensive Security Engineer - Red Team Lead

DRW • City Of London

On-site
GBP 90,000 - 130,000
Senior Red Team Engineer - Offensive Security
Senior Red Team Engineer - Offensive Security

DRW Holdings, LLC • Greater London

Hybrid
GBP 120,000 - 180,000