Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Assurance Engineer (Internal Penetration Testing)

£37.6 - £44.1 per hourEstimated
Full-time

Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high quality returns for our investors.

The Security Assurance team is responsible for identifying, assessing, and validating security risks across QRT’s technology environment. The team works closely with Security Engineers, Software Engineers, Infrastructure Engineers, Cloud Engineers, and Technology stakeholders to evaluate the effectiveness of security controls and strengthen the firm's overall security posture through adversarial testing and assurance activities.

Your Future Role within QRT

You will:

  • Conduct internal penetration testing across a wide range of systems, including trading infrastructure, cloud platforms, APIs, and business applications in both Windows and Linux environments.
  • Perform red team-style assessments and adversarial simulations to identify weaknesses in detection, response, and resilience capabilities.
  • Design and execute security assurance strategies to validate the effectiveness of security controls across applications, infrastructure, and cloud environments.
  • Coordinate external penetration testing engagements with third-party security vendors, including scoping, execution oversight, validation of findings, and remediation tracking across cloud, infrastructure, and application environments.
  • Identify, exploit, and clearly document vulnerabilities, providing actionable remediation guidance tailored to engineering teams.
  • Collaborate with product security and development teams to ensure vulnerabilities are properly remediated.
  • Support threat modelling exercises by providing an attacker’s perspective on system design and architecture.
  • Develop and maintain tooling, scripts, and frameworks to automate testing and improve coverage of security assessments.
  • Contribute to continuous security testing within CI/CD pipelines, including validation of SAST/DAST findings and runtime security controls.
  • Conduct security reviews of internal and third-party systems, validating real-world exploitability of identified risks.
  • Provide mentorship and training to engineers on common attack vectors, exploitation techniques, and secure design principles.
  • Stay current with emerging threats, vulnerabilities, and offensive security techniques relevant to financial systems and low-latency environments.

Your present skillset:

  • 5+ years of experience in penetration testing, red teaming, or security assurance roles, with hands-on experience testing complex, large-scale systems.
  • Strong practical knowledge of offensive security techniques, including web application, API, network, and cloud exploitation.
  • Solid understanding of system internals, networking, and common vulnerability classes, including OWASP Top 10, logic flaws, authentication and authorisation issues, and race conditions.
  • Familiarity with both Windows and Linux environments from an attacker’s perspective.
  • Experience using standard penetration testing tools such as Burp Suite, Metasploit, Nmap, BloodHound, and similar offensive security tooling.
  • Ability to assess the real-world impact of vulnerabilities and prioritise risks in a high-stakes environment.
  • Ability to clearly document findings, explain exploitability, and provide practical remediation guidance to engineering and infrastructure teams.
  • Strong communication skills, with the ability to clearly articulate technical risks and remediation strategies to engineering stakeholders.
  • Ability to operate independently, manage multiple assessments, and provide senior-level technical judgement during security assurance activities.
  • Preferred:
    • Experience testing applications and services developed in languages such as Python, C++, Rust, Go, and Kotlin/Java.
    • Experience with cloud security testing across AWS or Azure, including IAM, network configuration, storage, managed services, and common cloud misconfigurations.
    • Experience developing custom penetration testing tools, automation, scripts, exploits, or fuzzers.
    • Experience integrating security testing into CI/CD pipelines or supporting continuous assurance practices.
    • Understanding of detection and response mechanisms, with the ability to evaluate or bypass them during controlled testing.
    • Experience conducting red team exercises, adversary simulations, or purple team engagements.
    • Experience with containerised environments, Kubernetes, infrastructure-as-code, or hybrid cloud infrastructure.
    • Knowledge of low-latency systems, financial trading environments, or high-performance distributed systems.
    • Relevant certifications such as OSCP, OSEP, OSCE, CRTO, CCT APP, CCT INF, or equivalent practical experience.

QRT is an equal opportunity employer. We value diversity as essential to our success and are committed to creating an environment where employees can work openly, respectfully, and collaboratively. In addition to supporting professional achievement, QRT offers initiatives and programmes designed to help employees maintain a healthy work-life balance.

 

Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Assurance Engineer (Internal Penetration Testing) in London vacancy
  • £79k - £105k per annumEstimated
     ...the Role As an experienced Penetration Tester at Starling, you’ll be...  ...working with talented cyber security professionals to ensure our services...  ...research, perform security testing, and report issues aligned to...  ...risk framework. Being an internal tester, you’ll gain a strong... 
    Senior
    16 hours
    Full-time
    Hybrid working
    On-site
    Flexible hours

    Starling

    London
    8 days ago
  • £550 - £600 per day

     ...Senior Penetration Tester (AI-Enabled Vulnerability Research) | London Hybrid | £600 per day PAYE...  ...Penetration Tester to join a high-profile cyber security initiative focused on AI-enabled vulnerability discovery, offensive security testing and application security assessment.... 
    Senior
    Hybrid working
    Immediate start

    Robert Half

    City of London, Greater London
    13 days ago
  • £85k - £95k per annum

    The Senior IT Security Engineer will work alongside colleagues as part of a 3-person IT Security team. You will implement and maintain robust security...  ...scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against... 
    Senior
    Permanent
    Hybrid working
    On-site
    Remote

    Prime Personnel

    City of London, Greater London
    11 days ago
  • £75k - £100k per annumEstimated
     ...Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe’s largest digital clinic. Join us at a pivotal moment...  ...and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary... 
    Senior
    Long-term contract
    Permanent
    Full-time
    Fixed-term contract
    Hybrid working
    On-site
    Shift work

    HealthHero

    London
    8 days ago
  • £41k - £53k per annumEstimated
     ...part of MGroup, a specialist cyber security consultancy founded in 2021 to...  ...passionate and technically curious Penetration Tester to join our Offensive Security Testing team. In this role, you'll help...  ...00’s of retail discounts Life assurance Enhanced maternity, paternity... 
    Suggested
    Apprenticeship
    Traineeship
    Hybrid working
    Immediate start
    London
    7 days ago
  • £54k - £72k per annumEstimated
     ...transactions. You will operate the Product Security programe for Blockchain.com’s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you’ll design and...  ...debt lifecycle for product engineering teams, and architect the automated... 
    Senior
    Full-time
    Apprenticeship
    On-site
    Remote
    Flexible hours

    Blockchain.com

    London
    a month ago
  • £52k - £69k per annumEstimated
     ...Service business, we’re looking for a talented and passionate Senior Application Security Engineer to join our security engineering team. You’ll have a...  ...SAST, DAST, and SCA are effective and efficient, and that testing programmes — including pen testing, vulnerability... 
    Senior
    Hybrid working
    On-site
    Work from home

    Loyalty Group Insurance Services, Inc.

    London
    more than 2 months ago
  • £74k - £95k per annumEstimated
     ...Summary Yelp engineering culture is driven by our values : we’re...  ...environment. Yelp’s Application Security team protects Yelp's users,...  ..., supporting both internal engineering teams and external...  ...Security research and pen testing experience are assets. Comfort... 
    Senior
    Full-time
    Remote
    Flexible hours
    London
    a month ago
  • £75k - £97k per annumEstimated
     ...vision for the role We are searching for an experienced Senior Cloud Infrastructure Security Engineer with an unquenchable thirst for automation and a...  ...Incident Response process/policy with regular evolvement, testing and adherence Required Qualifications Three years... 
    Senior
    Full-time

    Cint

    London
    12 days ago
  • £57k - £76k per annumEstimated
     ...rapid growth and the Extended Assurance team expanding across the UK,...  ...significant changes to firms’ internal processes, such as regulatory...  ...teams, under the guidance of senior leadership. ~Apply assurance...  ...risks and design of controls testing programs. ~Experience working... 
    Senior
    Flexible hours

    CK Search Global

    London
    more than 2 months ago
  • £54k - £72k per annumEstimated
     ...you to excel. Our Offensive Security professionals are on a mission...  ...in the United Kingdom. We test web and smartphone applications...  ...devices, employees via social engineering, organizations via red teaming...  ...Kroll. What you’ll do As a Senior Consultant, you will report to... 
    Senior
    Apprenticeship
    Remote
    London
    more than 2 months ago
  • £42k - £56k per annumEstimated
     ...armed forces and commercial businesses can unlock digital advantage in the most demanding environments.   Job Title: Senior Security Penetration Testing Consultant Location: London, Gloucester, Guildford, Manchester, Leeds or Frimley (Occasional office work, with 25%... 
    Senior
    Hybrid working
    On-site
    Remote

    BAE

    London
    1 day ago
  • £70k - £75k per annum

     ...Senior Internal Auditor (Permanent Role) | Energy & Infrastructure | Central London or Manchester...  ...role in the country's long-term energy security and net-zero ambitions. As the organisation...  ...a high-performing and forward-thinking assurance team. This is a hands-on role... 
    Senior
    Long-term contract
    Permanent
    Hybrid working

    Robert Half

    City of London, Greater London
    a month ago
  • £57k - £73k per annumEstimated
     ...Senior Consultant, Red Team Operator, Offensive Security, UK In a world of disruption and increasingly complex business challenges...  ...team engagements, assumed-breach testing, adversary emulation, and threat intelligence-led penetration testing is in high demand. Our collaborative... 
    Senior
    Hybrid working
    Remote
    Probationary period
    London
    a month ago
  • £58k - £77k per annumEstimated
     ...outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios...  ...as incident response runbooks, threat hunting queries, and penetration testing reports. Annotate, label, and validate data across... 
    Remote job
    Hourly pay
    Part-time
    Summer work

    Mercor

    London
    a month ago
  • £92k - £122k per annumEstimated
     ...of technology at JPMorganChase. As a Senior Security Architect - SecOps and Vulnerability Management...  ...with top cybersecurity and engineering talent, solving complex challenges and...  ...Cybersecurity & Technology Controls team for International Consumer, you will proactively partner... 
    Senior
    Long-term contract

    JPMorgan Chase & Co.

    London
    6 days ago
  • £43k - £56k per annumEstimated
     ...working world. Technology Risk - Payments Assurance Senior Manager Technology is at the heart of...  ...projects. These include, IT Payments Internal Audit, IT components of Regulatory...  ...deliver client engagements to identify risks, test controls and provide an opinion on the... 
    Senior
    Immediate start
    Flexible hours

    EY

    London
    a month ago
  • £41k - £53k per annumEstimated
    Description At Engine by Starling , we are on a mission to find and work with leading...  .... About the role: As a Product Security Engineer at Engine, you will be a technical...  ...security reviews of new features, manage our penetration testing programme, and triage complex findings.... 
    16 hours
    Full-time
    Hybrid working

    Starling Bank

    London
    5 days ago
  • £66k - £87k per annumEstimated
     ...suitable.   THE OPPORTUNITY   We're looking for a senior Security Engineer to own security at Apollo Research from end to end. You'll...  ...- Stakeholder credibility. Non-security people trust you internally, and you can credibly represent Apollo to lab partner security... 
    Senior

    apolloresearch

    London
    a month ago
  • £70k per annum

     ...We’re looking for a Senior Application Security Engineer to join our expanding Information Security team. If you are a hands‑on AppSec expert who enjoys...  ...best practices including source control, unit testing, code reviews, design documentation and strong debugging... 
    Senior
    Long-term contract
    On-site
    Remote
    Flexible hours
    Shift work

    Our Future Health

    London
    8 days ago
  • £86k - £115k per annumEstimated
     ...where your expertise in cloud security will directly influence the...  ...technology at JPMorgan Chase. As a Senior Cloud Security Architect, you...  ...with top cybersecurity and engineering talent, solving complex...  ...Technology Controls team for International Consumer, you will proactively... 
    Senior
    Long-term contract

    JPMorgan Chase & Co.

    London
    13 days ago
  • £61k - £80k per annumEstimated
     ...Member of Technical Staff - Security Engineering London or Bristol · Hybrid · Permanent About...  ...levels here! Whether you’d call yourself senior, staff, principal, or lead, what...  ...firmware/boot projects, image minimisation) Assurance and resistance (supply-chain security... 
    Permanent
    Live-in
    Hybrid working
    On-site
    Remote

    Fractile

    London
    7 days ago
  • £68k - £91k per annumEstimated
     ...getting started. The Role As a Senior Information Security Analyst within the GRC team, you will...  ...— while providing expert guidance to engineering, product, legal, and compliance teams...  ...control design, policy development, internal audit programme, and certification –... 
    Senior
    Full-time
    Hybrid working
    On-site

    checkout.com

    London
    10 hours ago
  • £79k - £101k per annumEstimated
     ...underrepresented groups. The Role Overview We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the...  ...vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised,... 
    Senior
    Hybrid working
    Flexible hours

    Financial Times

    London
    22 days ago
  • £69k - £93k per annumEstimated
     ...MPC) technology – the gold standard in secure custody. Copper’s multi-award winning custody...  ...processes. Role Purpose As a Senior Security Engineer , you will play a key role in...  ...controls against CIS, STIG, SOC2, and internal security standards, and drive remediation... 
    Senior
    Hybrid working
    1 day/week

    Copper.co

    London
    1 day ago
  • £81k - £105k per annumEstimated
     ...over 1,000 strong, across 20 markets around the world.   Senior Security Engineer We are hiring a Senior Security Engineer based in London...  ...security configuration and identity security across client and internal platforms. This role leads the design and implementation... 
    Senior
    Permanent
    Hybrid working
    On-site

    WPP Media

    London
    22 days ago
  • £50k - £67k per annumEstimated
     ...application before the opportunity passes you by.. Job title: Senior Security Engineer      Department: Information Security      Reporting to...  ...from. ~Vitality Health Care ~Unum Dental ~Life Assurance & Income Protection ~Tusker car scheme ~Cycle to Work... 
    Senior
    Odd job
    Hybrid working

    DigiOutsource

    North London
    more than 2 months ago
  • £49k - £65k per annumEstimated
     ...Senior Software Engineer in Test Our mission is to improve the performance of athletes and teams, which we do by engineering the premier technology...  ...coded API tests with PactumJS, SpecFlow, REST Assured or similar ~ Extensive experience in developing coded... 
    Senior
    Remote job
    Long-term contract

    Catapult

    London
    more than 2 months ago
  • £500 per day

     ...We're looking for a Cyber Security Engineer for a public sector organisation based in London (hybrid) on an initial 6-month contract, paying...  ...public sector ICT or security functions Experience in penetration testing or web application testing would be a bonus, as would... 
    Hybrid working
    On-site
    Remote

    Invitise

    London
    2 days ago
  • £62k - £83k per annumEstimated
     ...groups. The Role Overview We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-...  ...sources such as SAST, dependency scanning, secret scanning, penetration tests, bug bounty reports or third-party advisories. CI/CD and... 
    Hybrid working
    Flexible hours

    Financial Times

    London
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Assurance Engineer (Internal Penetration Testing). Be the first to apply!