Red Team Engineer
Central London, Greater London, England, UK
Listed on 2025-10-29
-
IT/Tech
Cybersecurity, Systems Engineer
iProov provides science-based biometric solutions that enable the world’s most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, Gov Tech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance.
This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose.
The RoleReports to: Head of Red Team
Location: UK - Hybrid
Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits
As we continue to scale and grow, we are looking for an experienced Red Team Engineer focused on web platforms to join our growing Red Team function and ensure our system continues to deliver outstanding levels of biometric security and performance globally. Our system has to provide the highest levels of biometric security to defend against the numerous and growing threats, whilst ensuring that we deliver outstanding performance for our millions of users worldwide.
This is an exceptionally challenging problem as the nature of the threats evolves rapidly and there is a constant and growing need to track new threats, develop new defences and deploy in a timely and efficient manner.
- Design and execute Red Team Operations against iProov’s biometric platform, web apps, APIs, identity flows
- Strengthen the company’s security posture through offensive security assessments including the identification and exploitation of vulnerabilities across the web platform
- Perform penetration testing and realistic security exercises to simulate various attack scenarios, to test and improve our detection and response capabilities, and to identify weaknesses in our infrastructure and products.
- Execute technical security assessments to identify risk, likelihood and impact an attacker may have on the System due to weak or missing controls
- Conduct research into real-world threat actor tactics, techniques, and procedures (TTP’s) to develop proof-of-concept tools and replicate real world attacks.
- Present findings and operational work to groups in a clear and professional manner
- Produce clear, actionable reports, risk-ranked remediation plans, and executive summaries aimed at product and engineering stakeholders.
- Collaborate with defenders, product teams, and leadership to translate findings into prioritized, actionable remediation and risk reduction.
- Bring insight into all aspects of modern security issues to our products and rapidly developing prototypes for mitigations.
- Mentor engineers in secure-by-design patterns, client-side security, and secure API design.
- Work hand-in-hand with developers to propose pragmatic mitigations, remediation plans, and detection logic for vulnerabilities discovered during engagements.
- Translate findings into engineering-friendly fix guidance (code-level suggestions, configuration changes, library upgrades, secure design alternatives) and where required create reproducible PoCs that safely demonstrate impact.
- Validate and re-test remediations and detection improvements (verify fixes, tune rules/signatures, confirm telemetry coverage).
- Integrate offensive findings into the SDLC: enable SCA (software composition analysis), SAST/DAST pipelines, pre-merge checks, and secure CI/CD practices.
- Ensure all work follows company policies, rules of engagement (ROE), and legal/regulatory requirements.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: