- Company Name
- BDO UK
- Job Title
- BDO Digital Offensive Security Consultant
- Job Description
-
**Job Title:**
BDO Digital Offensive Security Consultant
**Role Summary:**
Lead penetration testing and red‑team engagements for BDO clients, identifying vulnerabilities and strengthening security posture. Develop and refine advanced testing methodologies, tools, and automation solutions to meet evolving threat landscapes and regulatory requirements. Collaborate with cross‑functional teams and senior leadership to advise on risk mitigation and improvement strategies.
**Expectations:**
- Conduct comprehensive vulnerability assessments, penetration tests, and red‑team exercises across diverse client environments.
- Deliver actionable findings, technical recommendations, and executive‑level summaries.
- Drive continuous improvement of testing processes, tooling, and automation.
- Stay current on emerging attack techniques, threat intelligence, and cybersecurity regulations.
- Engage with clients and internal stakeholders to shape security strategy and product offerings.
**Key Responsibilities:**
1. Plan, execute, and report on penetration testing and red‑team engagements.
2. Identify, analyze, and prioritize security weaknesses in applications, networks, and infrastructure.
3. Create and maintain custom exploitation tools, scripts, and automation pipelines.
4. Develop and document advanced testing methodologies, frameworks, and playbooks.
5. Collaborate with internal auditors, risk, and technology teams to integrate findings into broader risk management.
6. Communicate technical results to technical and non‑technical audiences, including senior managers and partners.
7. Mentor junior security analysts and contribute to knowledge sharing initiatives.
8. Monitor industry developments, regulatory changes, and emerging threats to inform testing strategies.
**Required Skills:**
- Proficient in penetration testing, vulnerability scanning, and red‑team operations.
- Strong knowledge of contemporary attack techniques, exploitation frameworks, and defensive countermeasures.
- Experience with scripting/automation (Python, Bash, PowerShell, etc.).
- Familiarity with security tools (Metasploit, Burp Suite, Nmap, Nessus, etc.) and CI/CD security integrations.
- Analytical mindset with the ability to translate technical findings into business‑impact recommendations.
- Excellent written and verbal communication skills.
- Self‑motivated, proactive, and collaborative, with capacity to manage independent work and team projects.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional certifications preferred: CEH, OSCP, CREST (or equivalent).
- Continuous learning in offensive security and cybersecurity certifications encouraged.