Senior Offensive Security Engineer

100% Remote (UK/EU*)

Applications have closed

Form3

Form3 are revolutionising the way payments work from channel to payment scheme. We have developed an enterprise-grade, managed, payment technology platform that integrates across multiple payment schemes, and connects into your payment systems...

View company page

THE TEAM

The team is comprised of our Defensive and Offensive Engineering teams alongside our Information Security Officers, whilst our CISO leads the operation. Our security team interact with the product and platform engineering teams across the company to promote best practices and awareness. They’re continually baking security into our culture, utilising new technologies and open-source tools to ensure high standards of security are maintained.

THE ROLE 

Form3’s Offensive Security Engineering division is becoming rapidly more sophisticated in their approach to security testing. This team is tasked with identifying vulnerabilities and continually improving our resilience from attackers from the attacker’s perspective. With a wide range of tools and technologies available to you this is your opportunity to help Form3 protect its most important assets and services. Below are some examples of projects the team is working on: 

  • Penetration Testing the increasingly growing ecosystem of Form3.
  • Conduct code reviews and security reviews of Form3’s Infrastructure (Cloud, Kubernetes).
  • Participate in threat modelling sessions and help in vulnerability remediation.
  • Maintaining and advocating the DevSecOps mindset we have created across the business.
  • Creating new tools and methodologies to enable our team to deploy creative and effective threat assessments.
  • Researching new security vulnerabilities, threats and exploits.

THE TECH 

  • Infrastructure: AWS, GCP, Azure, Kubernetes (this will increase as we go cloudagnostic)
  • Platform: CockroachDB, EKS, GKE, PostgresDB, Vault, Consul, Linkerd, Cilium, NATS
  • Tools: Terraform, Github, Flux, Prometheus, Pact.io, TFSec, Travis CI
  • Code: Go, (a little Java), CQRS, Open-Source, Python (Security tools)
  • Ways of working: DevSecOps, GitOps, TDD/BDD, Pair Programming, 100% Remote

WHAT WE NEED FROM YOU AND WHY 

  • Confidence within a DevSecOps environment, here at Form3 DevSecOps is our chosen methodology/ mindset so experience with automatic code analysis, IaC (Terraform preferably) security and CI/CD pipeline security reviews is critical here. This extends to having the ability to not only test but offer hands-on assistance in the remediation stages.
  • In depth knowledge of Web Application penetration testing and experience with source code reviews. Manual penetration testing experience together with the ability to develop automated testing scripts.
  • Experience in Cloud-Native/ Multi-Cloud offensive security engineering. Form3 is rapidly approaching it’s goal of becoming platform-agnostic, our OffSec team is tasked with offering business leaders a clear perception of the cloud threat landscape through extensive testing and research.
  • Experience in Kubernetes and Container security reviews and exploitation. Running on a micro-service, distributed architecture, our OffSec team are challenged with finding and exploiting vulnerabilities and loopholes to ensure that our architecture is as secure and impenetrable as possible, networks and bare metal are included within this scope.

SPECIFIC DESIRABLES AND YOUR SPECIALISMS

  • Strong programming skills, we are flexible on languages, we use Go as our main language for production so a willingness or interest to learn Go is fundamental. In security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them.
  • In-depth knowledge and capabilities using Linux and Unix technologies and how these can be used in the attack matrix to allow for privileged escalation and lateral movement.
  • Active contribution to Open-Source projects and tools is highly encouraged at Form3 so prior interest in this is always welcomed.
  • Keen interest in new and emerging threats, vulnerabilities and adversary advancements coupled with the ability to present these to the wider team.
  • Qualifications: OSCP, OSWE, CCT App or Inf (or equivalent), CCSAS, CCSP, Cloud Specific Qualifications 
BENEFITS 
  • 30 days holidays plus public holidays
  • 100% remote work
  • Flexible working arrangements
  • Statutory benefits
  • Health & wellness allowance
  • Remote working equipment allowance
  • Primary caregiver leave
  • Learning days, Udemy and educational reimbursement etc.
  • Mental Health support via Spill
  • Perlego subscription
  • Full details available on our careers page
Form3 appreciates that we all lead different and often really busy lives. We work remotely 100% of the time and many of us work part time. If you’re interested in hearing what different flexible working arrangements may be available, we’d love to chat.
 
HIRING LOCATIONS

We are able to accept applications from the following countries;
 
Belgium, Czech Republic, France, Germany, Greece, Hungary, Ireland, Netherlands, Spain, Poland, Portugal, Romania & United Kingdom.
 
ABOUT US
 
We are an award-winning cloud-native payment technology provider for financially regulated institutions. Launched in 2016, we've doubled in size year on year as we continue to redefine what a truly instant payment experience means.We celebrate diversity, promote entrepreneurialism and are committed to giving everyone a say in shaping our business. Here you will grow as a person and accomplish incredible things. A career at Form3 is empowering, inspiring and fun. Join us and help shape the future of payments.

 

OUR DEI&B COMMITMENT 

We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, open-mindedness and curiosity. We’re united by our company values (we even created them together!) and we celebrate our unique differences. 

Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be. 

As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process. This includes providing job adverts in alternative, accessible formats or adjustments required at interview stage. 

If you consider yourself to be neurodiverse or physically disabled under the UN definition of disability and would like to be considered under this scheme and/or require any reasonable adjustments please let us know by sending an email to careers@form3.tech clearly stating your consent for us to process this data.

For more information please refer to our Recruitment Data Policy. 

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Automation AWS Azure CCSP CI/CD CISO Cloud Code analysis DevSecOps Exploits GCP GitHub Java Kubernetes Linux Offensive security OSCP OSWE Pentesting Prometheus Python TDD Terraform UNIX Vulnerabilities

Perks/benefits: Career development Flex hours Health care Wellness

Region: Remote/Anywhere
Job stats:  27  4  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.