Skip to main content
HimalayasHimalayas logo
Rapid7RA

Senior Security Consultant, Emergent Threat & Exploit Researcher

Rapid7 is a cybersecurity company providing data security and analytics solutions, including vulnerability management, incident detection and response, application security, and cloud security. Founded in 2000, the company aims to help organizations reduce risk and eliminate threats across modern IT environments.

Rapid7

Employee count: 1001-5000

United Kingdom only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls?

As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defense strategies

About the Team

Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defense-in-depth strategy.

In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.

About the Role

Your primary responsibility is to deliver Rapid7’s Vector Command Continuous Red Teaming service. In this role, you will investigate emerging threats, uncover novel vulnerabilities across large external attack surfaces, and attempt to breach customer perimeter defenses to gain initial access. When new N-day or zero-day vulnerabilities emerge, this role rapidly analyzes them, recreates proof-of-concepts, and assesses customer environments for exposure. Between these high-priority efforts, the researcher actively hunts for novel vulnerabilities and unique attack paths across customer attack surfaces to support initial access operations. Specifically, your focus will be to:

  • Evaluate large external attack surfaces to identify vulnerabilities that enable initial access.

  • Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.

  • Analyze, develop, and exploit N-day and newly released zero-day vulnerabilities relevant to customer environments.

  • Identify novel attacks through black-box evaluation of customer web applications, leading to initial access or exposure of sensitive data.

  • Develop and maintain positive relationships with clients and understand their business and needs.

  • Participate in industry conferences and professional organizations

  • Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices

  • Translate technical concepts and convey them to non-security personnel

  • Mentor and coach junior staff to promote growth, project contributions, and knowledge sharing.

  • Meet professional practice standards and demonstrate exceptional skill in core service areas

The skills and qualities you’ll bring include:

  • 5+ years in an active technical security role & 4+ years Penetration Testing Consulting experience

  • Expert knowledge of the following:

    • Modern penetration testing tools and methods

    • Network and web-based application security concepts

    • Windows/Linux/UNIX internals

    • Exploit research and development

  • Experience using multiple interpreted languages (Ruby, Python, PHP, etc.) and compiled languages (Java, C, C++, Assembly, etc.)

  • Technical competencies, including previous technical consulting experience

  • High quality report writing and peer reviewing

  • Strong knowledge of common regulatory structures and obligations and common I.T. governance.

  • The ability to effectively lead teams of penetration testers while on engagements

  • Be comfortable explaining findings and recommendations to technical and non-technical audiences including C-Level and Board briefings

  • Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet-facing attack surfaces.

  • Certifications such as OSCP, OSCE, GXPN, OSEE, CREST

  • Experience with Red & Purple Teams

  • Excellent communication skills both with internal and external stakeholders

  • Collaborative mindset, contributing to knowledge sharing and cross training

  • Demonstrate a commitment to the "end-to-end" testing process, from the initial pre-engagement planning to providing accountable support during the final remediation phase.

  • Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.


About Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome.


Protecting 11,500+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ ve been doing for the past 20 years. If you ’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

4 years minimum

Location requirements

Hiring timezones

United Kingdom +/- 0 hours

About Rapid7

Learn more about Rapid7 and their company culture.

View company profile

Founded in 2000 by Alan Matthews, Tas Giakouminakis, and Chad Loder, Rapid7 embarked on a mission to provide innovative cybersecurity solutions. The company was established with the vision of helping organizations effectively detect and respond to security threats. Alan Matthews brought his extensive cybersecurity expertise, Tas Giakouminakis provided the technical software development knowledge, and Chad Loder contributed his entrepreneurial vision to shape the company's strategic direction. What began as a focused endeavor to address the evolving landscape of cyber threats has grown into a global leader in vulnerability management and incident detection. Over the years, Rapid7 has consistently pushed the boundaries of security technology through innovation and strategic partnerships. A key milestone in their journey was the launch of Nexpose, their flagship vulnerability management solution, in 2007. This was followed by the strategic acquisition of Metasploit, a renowned open-source penetration testing tool, in 2010, significantly expanding their product portfolio. The company's growth trajectory continued, leading to its initial public offering (IPO) on the NASDAQ stock exchange in 2012 (though another source indicates 2015). In 2015, Rapid7 further enhanced its threat detection capabilities by acquiring Logentries, a provider of cloud-based log management and analytics solutions. The introduction of InsightIDR in 2018, a cloud-based SIEM solution, marked another significant step in empowering organizations to detect and respond to security incidents in real-time.

Today, Rapid7 is a leading cybersecurity solutions provider, dedicated to making successful security tools and practices accessible to all. Their Insight Platform technology, expert services, and thought-leading research enable over 9,000 customers worldwide to improve their security programs and innovate safely. As technology continues to advance rapidly, every company has essentially become a technology company, inherently creating new security risks. The migration to the cloud and the proliferation of connected devices present security teams with an increasingly complex and unpredictable attack surface. Rapid7 believes that as cybersecurity challenges escalate, two primary factors hinder organizations from effectively managing their security exposure: the complexity of security tools and the scarcity of qualified cybersecurity professionals to manage them. These challenges are compounded for resource-constrained organizations. Rapid7 aims to bridge this 'Security Achievement Gap' by simplifying complex security problems. Their solutions empower teams to more effectively reduce vulnerabilities, monitor malicious behavior, investigate and shut down attacks, and automate routine tasks. This is all supported by a dedicated team of security researchers and consultants who bring real-world attacker behavior knowledge and emerging vulnerability insights directly to their customers. Headquartered in Boston, Massachusetts, Rapid7 operates globally, serving a diverse range of industries including technology, energy, financial services, healthcare, and government.

Claim this profileRapid7 logoRA

Rapid7

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

17 remote jobs at Rapid7

Explore the variety of open remote roles at Rapid7, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Rapid7

Remote companies like Rapid7

Find your next opportunity by exploring profiles of companies that are similar to Rapid7. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan