Offensive Security Engineer
OUR PEOPLE:
People are at the heart of what we do and drive the success of our business. Our culture of connecting, creating opportunity and delivering excellence shape how we think, how we do things and how we help our people fulfil their potential. We embrace diversity and actively seek to attract individuals with unique backgrounds and perspectives. We break down barriers and encourage teamwork, enabling innovation and rapid development of solutions that make a difference. Our workplace generates an enriching and rewarding experience for our people and customers alike. Our vision is to build an inclusive culture in which everyone feels encouraged to fulfil their potential.
We know that real personal growth cannot be achieved by simply climbing a career ladder โ which is why we encourage and enable a wealth of avenues and interesting opportunities for everyone to broaden and deepen their skills and expertise. As a global organisation spanning 70 countries and one rooted in a culture of growth, opportunity, diversity and innovation, LSEG is a place where everyone can grow, develop and fulfil your potential with meaningful careers.
ROLE SUMMARY:
This opportunity within the Offensive Security Operations team is a crucial role for the management of vulnerability discovery, offensive testing and remediation activities across the group which protects the business from sophisticated cyber threats!
The role holder will work with our 3rd party vendors to plan and facilitate our testing programmes ensuring they run efficiently. The programmes in scope for the role include:
-
Regulatory Threat Intelligence Led Pen Testing (TLTP) and Red teaming
- Bug Bounty
-
Continuous External Attack Surface Management
-
Active Directory security posture management
-
Any programme launched in the future aimed at driving down cyber risk at scale
The applicant will be a domain authority on vulnerability testing, impact and remediation. They will provide insight on root cause analysis and scalable risk management. This role requires working closely within a technical team and with external teams like BISOs, GSOC and regulators. The candidate will stay ahead of emerging cyber security thought leadership and share their ideas for areas of improvement and innovation that drive continuous cyber security risk improvement. In this role there are opportunities to explore and experiment with how AI and other types of automation can be used to improve our existing and future initiatives.
WHAT YOU'LL BE DOING:
-
Collaborate with external vendors, regulators and leadership teams coordinating the timely delivery of requirements
-
Review vulnerability reports, validate issues reported and triage based on risk
-
Support teams in understanding vulnerabilities and validate fixes through retesting
-
Coordinate remediation efforts by detailing actions, owners, timelines and follow up when appropriate
-
Leverage engineering skills to automate and scale security programme objectives
WHAT YOU'LL BRING:
- Technology related Bachelor's Degree or equivalent experience and certifications in cyber security
- Background in Red Teaming / Penetration Testing / Bug Bounty advantageous!
- Experience building AI agentic workflows or deploying and managing security tooling is also advantageous!
- Understanding of large scale enterprise IT system environments
- Knowledge of security vulnerabilities and common software engineering flaws and Network Defence analytical models (Kill Chain, ATT&CK, OWASP top 10etc.)
- Strong verbal & written communication skills & presentation skills
- Ability to work in a fast-paced environment as a problem solver and barrier breaker with initiative
Career Stage:
Senior Associate
London Stock Exchange Group (LSEG) Information:
Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear