Red Team Lead

Oscar Technology
London, United Kingdom
Today
£70,000 – £90,000 pa

Salary

£70,000 – £90,000 pa

Job Type
Permanent
Work Pattern
Full-time
Work Location
Remote
Seniority
Lead
Education
Degree
Posted
1 Jun 2026 (Today)

Red Team Lead | Remote (UK Only)

This is a senior technical position for someone who thrives at the intersection of offensive security, threat research, and client advisory. You'll work closely with senior leadership to shape engagements, influence testing methodology, and deliver realistic, intelligence-driven adversary emulation across complex enterprise environments.

This opportunity goes far beyond traditional penetration testing. The successful candidate will play a key role in designing sophisticated attack scenarios, researching emerging threats, and translating real-world attacker behaviour into impactful red team operations

The Opportunity:

As a Red Team Lead, you'll take ownership of advanced adversary simulation engagements from initial planning through to execution and reporting. You'll help define attack hypotheses, model realistic threat actor behaviour, and challenge client assumptions through carefully crafted offensive operations.

You'll be trusted to operate autonomously while collaborating closely with senior technical stakeholders, helping to maintain exceptionally high delivery standards across all engagements.

Key Responsibilities:

  • Lead and deliver complex red team and adversary emulation engagements
  • Design realistic attack scenarios based on current threat intelligence and adversary tradecraft
  • Support engagement planning, attack path development, and operational execution
  • Research emerging threat actors, attack techniques, and offensive tooling
  • Develop and refine bespoke tactics, techniques, and procedures (TTPs) for client engagements
  • Conduct phishing, social engineering, and human-layer attack simulations
  • Execute attacks across enterprise and hybrid environments including:
    • Active Directory
    • Microsoft 365
    • Azure
    • AWS
    • Google Cloud
    • Identity platforms and SaaS ecosystems
  • Assess and bypass modern security controls using stealth-focused methodologies
  • Develop, modify, or enhance offensive tooling and command-and-control infrastructure
  • Support purple team exercises and collaborative defensive improvement initiatives
  • Produce clear, technically accurate reports that provide meaningful attacker insight and business value

About You:

We're interested in individuals who combine deep technical capability with strong research instincts and client-facing credibility.

You'll likely have:

  • Extensive experience delivering or leading red team engagements within large enterprise, government, financial services, or other regulated environments
  • Strong understanding of adversary emulation and threat intelligence-led testing
  • Experience researching vulnerabilities, attack paths, and exploitation opportunities
  • Deep knowledge of Active Directory, hybrid identity, cloud security, and modern enterprise attack surfaces
  • The ability to develop or adapt offensive techniques beyond standard frameworks and playbooks
  • Experience communicating complex attack scenarios to both technical and executive audiences
  • Strong stakeholder management and consulting skills

As a senior member of the team, you'll be expected to:

  • Maintain and promote high technical and ethical standards
  • Mentor and support the development of less experienced consultants
  • Demonstrate sound judgement during complex engagements
  • Build trusted relationships with colleagues and clients
  • Take ownership of outcomes and drive work to completion
  • Contribute to internal research, capability development, and knowledge sharing initiatives

Desirable Experience:

Any of the following would be advantageous:

  • Experience emulating named threat actors or advanced persistent threats
  • Vulnerability research or proof-of-concept development
  • Contributions to open-source security projects
  • Conference speaking, technical blogging, or published research
  • Experience working within frameworks such as CBEST, GBEST, TIBER-EU, or equivalent threat-led testing methodologies
  • Industry-recognised offensive security certifications

If you're passionate about realistic adversary simulation, enjoy pushing beyond conventional testing approaches, and want to influence how offensive security engagements are designed and delivered, we'd be keen to hear from you.

Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Related Jobs

View all jobs

Cyber Security Engineer - Red Team within UK

Immersive United Kingdom
Remote

Manager, Red Team Services , GBR)

CrowdStrike London, SE10 0TW, United Kingdom
Remote Clearance Required

Manager, Red Team Services , GBR)

CrowdStrike Dunscore, Alba / Scotland, DG2 0SR, United Kingdom
Remote

Manager, Red Team Services , GBR)

CrowdStrike Bigton, Alba / Scotland, ZE2 9GA, United Kingdom
Remote Clearance Required

Manager, Red Team Services , GBR)

CrowdStrike Windsor, SL4 4BQ, United Kingdom
Remote

Manager, Red Team Services , GBR)

CrowdStrike United Kingdom
Remote

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.