Job Description
Lead Offensive Security Operator
Location: National*
Closing Date: 21/08/26
Interviews: Week commencing 25/08/26
Grade: G7
(MoJ candidates who are on a specialist grade, will be able to retain this grade on lateral transfer)
Salary**
National: £58,511 - £73,450 (which may include an allowance up to £14,939)
London: £63,343 - £78,225 (which may include an allowance up to £14,882)
Working pattern: Full-time, Part-time, Flexible working
Contract Type: Permanent
Number of vacancies: 1
Vacancy number: 20502
*We offer a hybrid working model, allowing for a balance between remote work and time spent in your local office. Office locations can be found ON THIS MAP
Please note that unless you are an existing member of staff at Justice Digital, Data and Science, the only London location being recruited to is 10 South Colonnade, E14 4PU. We are no longer recruiting to 102 Petty France, SW1H 9AJ.
The Role
Please note this role requires you to pass Security Check clearance. Please click on the link for details.
We’re recruiting for a Lead Offensive Security Operator here at Justice Digital Data and Science, to be part of our warm and collaborative Digital Infrastructure and Security Operations Team (DISO). The team are responsible for the live services, delivery, product changes and developments for all networking, security, voice, video and hosting services across the MoJ estate.
This role aligns against Penetration Testing Principal from the Government Security Profession framework.
The Justice Digital, Data and Science team is made up of around 900 digital and technology specialists, located throughout the UK. Our vision is a digitally enabled end-to-end justice system which can adapt and respond to changing needs.
Justice Digital, Data and Science is responsible for all infrastructure, end user computing, onsite support, and delivery of technology projects. It has responsibility for 95,000 devices and infrastructure across 900+ sites.
You will be part of a small team of cyber red teaming specialists who provide independent full-spectrum adversary emulation services to security stakeholders within the Ministry of Justice.
You will conduct safe, simulated cyber-attack simulations against our technology estates, acting as a real-world adversary might, to test our defences, highlight weaknesses and contribute cyber security expertise and insight in support of the department’s strategic security decision-making functions. You will be familiar with exploitation methodologies across a wide range of technologies, from classic enterprise technology stacks to modern digital services. You will have a well-developed ability to tactically assess and to execute a diversity of attack types, including chained attacks and evasion techniques, to achieve your desired goal.
You’ll receive a range of excellent benefits when you join our department, including:
- A generous employer pension contribution of 28.97% through the Civil Service Pension Scheme.
- 25 days of annual leave, (increasing to 30 days once you have reached 5 years of service), plus 8 bank holidays and a privilege day for the King’s birthday.
- Flexible working arrangements including hybrid working, working part time or compressed hours. Designed to support a positive work–life balance.
- Employees are allocated 10% of their working time for personal and professional development.
- A £1k per person learning budget is in place to support all our people, with access to best-in-class conferences and seminars, accreditation with professional bodies, fully funded vocational programmes and e-learning platforms.
- Compassionate maternity, adoption, and shared parental leave policies, with up to 26 weeks leave at full pay, 13 weeks with partial pay, and 13 weeks further leave. And maternity support/paternity leave at full pay for 2 weeks, too!
You can find more details of the Benefits we offer here. To help picture your life at MoJ Justice Digital, Data and Science please take a look at our blog.
Key Responsibilities:
- Designing and executing threat intelligence-based full-spectrum cyber-attack simulations, including long-term campaign planning, persistence, and post-exploitation operations against the Ministry of Justice.
- Adopting a red team approach, discovering high-impact weaknesses across the organisation’s most important technology estates and business areas, and validating whether the overarching cyber security apparatus is working effectively.
- Demonstrate expertise of the latest exploitation and evasion techniques in at least one area of specialism.
- Communicating technical findings in clear risk and impact-focused terms to senior stakeholders, enabling effective understanding and support for strategic decision-making.
- Development and implementation of technology platforms, tools and methodologies to augment and to automate team offensive and analytical capability.
If this feels like an exciting challenge, something you are enthusiastic about, and want to join our team please read on and apply!
Person Specification
Essential
- Proven ability to plan and execute complex, multi-phase operations, including: Scenario-driven adversary simulation and Threat intelligence analysis and assessment
- Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets
- Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft
- Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex legacy and modern enterprise environments.
- Experience using, developing and deploying tools in support of red teaming activities, including attack infrastructure, C2 frameworks and infrastructure-as-code technologies.
- Strong communication skills with the ability to clearly explain complex technical issues related to vulnerabilities and risk to diverse audiences, including senior stakeholders, in support of vulnerability management, threat mitigation, and risk-based decision-making.
Willingness to be assessed against the requirements for SC clearance
We welcome the unique contribution diverse applicants bring and do not discriminate based on culture, ethnicity, race, nationality or national origin, age, sex, gender identity or expression, religion or belief, disability status, sexual orientation, educational or social background or any other factor.
Our values are Purpose, Humanity Openness and Together. Find out more here about how we celebrate diversity and an inclusive culture in our workplace.
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy.
Salary Information**
Base salary for this role is from National: £58,511-£65,329 London: £63,343-£70,725
- New entrants to the Civil Service joining the MoJ are expected to start at the minimum of the pay band.
- Existing Civil Servants moving on a level transfer will retain their current base salary or move to the minimum of the pay band for the role, whichever is higher.
- Existing Civil Servants who are promoted will either move to the bottom of the new grade’s pay band or receive a 10% uplift, whichever provides the greater increase.
- Candidates may also be eligible for a non‑pensionable Government Digital & Data Allowance of up to £14,882 per year (London) or £14,939 (National). This is a temporary allowance, reviewed annually and may be retained, amended, or withdrawn.
The final offer will reflect the skills and experience you demonstrate during the assessment process.
How to Apply
In Justice Digital, Data and Science, we recruit using a combination of the Government Digital and Data Profession Capability and Success Profiles Frameworks. We shall assess a combination of your Experience, Technical skills and Behaviours during the assessment process.
Stage 1 - Application and sift:
To apply for this position, you must submit the following as part of your application:
- A CV detailing your career history (including any relevant qualifications). Your CV will be assessed against the essential criteria outlined within the Person Specification of this advert.
- A Personal Statement (no more than 750 words) which should outline your experience and skills, giving clear examples of work undertaken. It should specifically address the following 3 criteria listed below, using a separate paragraph for each.
- Proven ability to plan and execute complex, multi-phase operations, including Scenario-driven adversary simulation and Threat intelligence analysis and assessment
- Post-exploitation, persistence and lateral movement, including tactical analysis of attack paths leading to high-value targets
- Conducting engagement activities in line with operational security best practice and within a range of threat actor capabilities and tradecraft
A diverse sift panel will review the information in your CV and Personal Statement to assess the sift criteria specified above. We operate an anonymous shortlisting process. Please ensure your CV and Personal Statement do not include your name or any other identifying details.
Please access the following link for guidance on how to apply - Application Guidance
Stage 2 - Interviews:
Successful candidates who meet the required standard will then be invited to a panel interview held via Microsoft Teams. At interview stage, you will be assessed against the following Success Profile elements - Experience, Technical and the following Behaviours:
- Working together
- Communicating and Influencing
- Managing a Quality Service
Appointments are made strictly in merit order. In the event that two or more candidates receive identical interview scores, the following primary lead criterion will be used to determine the final merit order:
- Deep understanding of security technologies found in end-user and server operating systems and supporting infrastructure, including relevant architectural and operational patterns of at-scale deployment and administration of complex legacy and modern enterprise environments.
Should you be unsuccessful in the role that you have applied for but demonstrate the capability for a role at a lower level, we reserve the right to discuss this opportunity with you and offer you the position without needing a further application.
A reserve list may be held for up to 12 months, from which further appointments may be made.
Use of Artificial Intelligence
Artificial Intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.
Terms & Conditions
Please review our Terms and Conditions which set out how we recruit and provide further information related to the role and salary arrangements.
If you have any questions, please feel free to contact digitalanddatarecruitment@justice.gov.uk