# Senior Offensive Security Engineer

[Drweng](https://gurify.com/jobs?q=Drweng) · London · Posted 2 days ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/drweng/jobs/8237371)

## Job description

DRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.

Headquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.

We operate with respect, curiosity and open minds. The people who thrive here share our belief that it’s not just what we do that matters–it's how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.

### About the Role

DRW is building out its offensive security capability, and we’re looking for a Senior Offensive Security Engineer to lead the charge. In this role, you’ll plan and execute red team engagements, penetration tests, and adversary simulations against our trading infrastructure, corporate environment, and cloud platforms, acting as a trusted adversary who helps us find and fix weaknesses before anyone else does.

You’ll work closely with our security, infrastructure, and trading teams to translate what you find into real improvements, and you’ll help shape the methodology, tooling, and roadmap for offensive security at DRW as the function matures. This is a hands-on, high-trust role for someone who thinks like an attacker, communicates like a partner, and cares about making the firm measurably harder to compromise.

### What You'll Do

- Plan and execute red team engagements and adversary simulations against trading systems, corporate IT, and cloud environments, modeling realistic attacker tactics, techniques, and procedures (TTPs) mapped to frameworks such as MITRE ATT&CK

- Conduct penetration tests across networks, web and internal applications, APIs, and cloud infrastructure, and report findings with clear, actionable remediation guidance

- Design and build custom tooling, scripts, and exploits to emulate adversary behavior, test control effectiveness, and validate detection coverage

- Partner with the Security Engineering and SOC teams in purple-team exercises to close gaps between what attackers can do and what defenders can see

- Run social engineering and phishing simulations to assess and improve organizational security awareness

- Identify, validate, prioritize, and track vulnerabilities and control weaknesses through to remediation in collaboration with infrastructure, platform, and application owners

- Present engagement results and risk narratives to both technical teams and senior leadership in a way that drives action

- Stay current on the threat landscape, emerging TTPs, and offensive tooling, and bring that knowledge back into DRW’s defenses

- Assess the security of AI and LLM-integrated systems, including prompt injection, model manipulation, data poisoning, and abuse of agentic workflows, and work with teams building these systems to harden them

- Leverage AI-assisted tooling to accelerate reconnaissance, vulnerability discovery, and exploit development, and evaluate new AI-powered offensive techniques as they emerge

- Help define and mature DRW’s offensive security methodology, standards, and tooling, and mentor other engineers on the security team

### What We're Looking For

- 5+ years of hands-on experience in offensive security, penetration testing, or red teaming, including full engagement lifecycle work: reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration

- Strong scripting or programming ability for building and adapting offensive tooling

- Solid understanding of networking fundamentals, Windows, macOS, and Linux internals, identity providers, and cloud platforms

- Practical experience with common offensive security tools (e.g., Cobalt Strike, Metasploit, BloodHound, Burp Suite, Nmap) and a track record of building your own when the situation calls for it

- Working knowledge of the MITRE ATT&CK framework, adversary emulation, and detection evasion techniques, along with enough understanding of defensive controls and tooling to help defenders improve

- A track record of clear, precise reporting and communication and you can translate technical findings into risk that both engineers and executives understand

- Experience with smart contract auditing and blockchain security

- Familiarity with AI/ML security risks, including adversarial attacks on models, prompt injection, and the offensive and defensive implications of LLM-powered tooling

- A collaborative mindset: you see red teaming as a way to make the whole organization more secure, not just to find flaws

For more information about DRW's processing activities and our use of job applicants' data, please view our Privacy Notice at https://drw.com/privacy-notice.

California residents, please review the California Privacy Notice for information about certain legal rights at https://drw.com/california-privacy-notice.

#LI-BL1

**Live in Drweng’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- EN [Lead Security Engineer](https://gurify.com/job/lead-security-engineer-at-encord-691754c23bc3) Encord · London · 6 days ago
- BR [Lead Application Security Engineer](https://gurify.com/job/lead-application-security-engineer-at-brunswickgroup-5849dbce754f) Brunswickgroup · London, United Kingdom · 3 days ago
- XA [Infrastructure Security Engineer](https://gurify.com/job/infrastructure-security-engineer-at-xai-5df6888fa213) Xai · Dublin, United Kingdom · last week
- OM [Platform Security Engineer](https://gurify.com/job/platform-security-engineer-at-omnea-79e993c63a72) Omnea · London · 2 days ago
- FL [Security Engineer, Incident Response](https://gurify.com/job/security-engineer-incident-response-at-fluidstack-20713d42233c) Fluidstack · London · 2 days ago
- RI [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f) Rightmove · London, United Kingdom · 6 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Offensive Security Engineer","description":"\u003Cp\u003EDRW is a diversified trading firm with over 3 decades of experience bringing sophisticated technology and exceptional people together to operate in markets around the world. We value autonomy and the ability to quickly pivot to capture opportunities, so we operate using our own capital and trading at our own risk.\u003C/p\u003E\u003Cp\u003EHeadquartered in Chicago with offices throughout the U.S., Canada, Europe, and Asia, we trade a variety of asset classes including Fixed Income, ETFs, Equities, FX, Commodities and Energy across all major global markets. We have also leveraged our expertise and technology to expand into three non-traditional strategies: real estate, venture capital and cryptoassets.\u003C/p\u003E\u003Cp\u003EWe operate with respect, curiosity and open minds. The people who thrive here share our belief that it\u2019s not just what we do that matters\u2013it\u0026#39;s how we do it. DRW is a place of high expectations, integrity, innovation and a willingness to challenge consensus.\u003C/p\u003E\u003Ch3\u003EAbout the Role\u003C/h3\u003E\u003Cp\u003EDRW is building out its offensive security capability, and we\u2019re looking for a Senior Offensive Security Engineer to lead the charge. In this role, you\u2019ll plan and execute red team engagements, penetration tests, and adversary simulations against our trading infrastructure, corporate environment, and cloud platforms, acting as a trusted adversary who helps us find and fix weaknesses before anyone else does.\u003C/p\u003E\u003Cp\u003EYou\u2019ll work closely with our security, infrastructure, and trading teams to translate what you find into real improvements, and you\u2019ll help shape the methodology, tooling, and roadmap for offensive security at DRW as the function matures. This is a hands-on, high-trust role for someone who thinks like an attacker, communicates like a partner, and cares about making the firm measurably harder to compromise.\u003C/p\u003E\u003Ch3\u003EWhat You\u0026#39;ll Do\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EPlan and execute red team engagements and adversary simulations against trading systems, corporate IT, and cloud environments, modeling realistic attacker tactics, techniques, and procedures (TTPs) mapped to frameworks such as MITRE ATT\u0026amp;CK\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct penetration tests across networks, web and internal applications, APIs, and cloud infrastructure, and report findings with clear, actionable remediation guidance\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and build custom tooling, scripts, and exploits to emulate adversary behavior, test control effectiveness, and validate detection coverage\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with the Security Engineering and SOC teams in purple-team exercises to close gaps between what attackers can do and what defenders can see\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun social engineering and phishing simulations to assess and improve organizational security awareness\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify, validate, prioritize, and track vulnerabilities and control weaknesses through to remediation in collaboration with infrastructure, platform, and application owners\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPresent engagement results and risk narratives to both technical teams and senior leadership in a way that drives action\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStay current on the threat landscape, emerging TTPs, and offensive tooling, and bring that knowledge back into DRW\u2019s defenses\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssess the security of AI and LLM-integrated systems, including prompt injection, model manipulation, data poisoning, and abuse of agentic workflows, and work with teams building these systems to harden them\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELeverage AI-assisted tooling to accelerate reconnaissance, vulnerability discovery, and exploit development, and evaluate new AI-powered offensive techniques as they emerge\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp define and mature DRW\u2019s offensive security methodology, standards, and tooling, and mentor other engineers on the security team\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat We\u0026#39;re Looking For\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years of hands-on experience in offensive security, penetration testing, or red teaming, including full engagement lifecycle work: reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong scripting or programming ability for building and adapting offensive tooling\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESolid understanding of networking fundamentals, Windows, macOS, and Linux internals, identity providers, and cloud platforms\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience with common offensive security tools (e.g., Cobalt Strike, Metasploit, BloodHound, Burp Suite, Nmap) and a track record of building your own when the situation calls for it\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking knowledge of the MITRE ATT\u0026amp;CK framework, adversary emulation, and detection evasion techniques, along with enough understanding of defensive controls and tooling to help defenders improve\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA track record of clear, precise reporting and communication and you can translate technical findings into risk that both engineers and executives understand\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with smart contract auditing and blockchain security\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with AI/ML security risks, including adversarial attacks on models, prompt injection, and the offensive and defensive implications of LLM-powered tooling\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA collaborative mindset: you see red teaming as a way to make the whole organization more secure, not just to find flaws\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EFor more information about DRW\u0026#39;s processing activities and our use of job applicants\u0026#39; data, please view our Privacy Notice at https://drw.com/privacy-notice.\u003C/p\u003E\u003Cp\u003ECalifornia residents, please review the California Privacy Notice for information about certain legal rights at https://drw.com/california-privacy-notice.\u003C/p\u003E\u003Cp\u003E#LI-BL1\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-offensive-security-engineer-at-drweng-a6288ff0c792"},"url":"https://gurify.com/job/senior-offensive-security-engineer-at-drweng-a6288ff0c792","datePosted":"2026-10-06","validThrough":"2026-11-22T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Drweng","sameAs":"https://job-boards.greenhouse.io/drweng"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Offensive Security Engineer","item":"https://gurify.com/job/senior-offensive-security-engineer-at-drweng-a6288ff0c792"}]}
```
