Hong Kong Exchanges Logo

Hong Kong Exchanges

Cyber Threat Specialist (Penetration Tester)

Posted 3 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England
Junior
In-Office
London, Greater London, England
Junior
As a Cyber Threat Specialist, you'll perform penetration testing, support security incidents, optimize detections, and assist in deploying security tools. You'll work under the Information Security team to ensure effective security measures across systems.
The summary above was generated by AI
Cyber Threat Specialist (Penetration Tester)

Shift Pattern:

Standard 40 Hour Week (United Kingdom)

Scheduled Weekly Hours:

40

Corporate Grade:

E - Associate

Reporting Line:

(UK Division) Information Technology

Location:

UK-London

Worker Type:

Permanent

Overall Purpose of Role:

This role is an entry-level position within the Information Security team at the London Metal Exchange (LME). This role will be a junior member of the penetration testing team to conduct penetration testing of LME systems and applications. Penetration testing will include scoping, performing assessments, identifying vulnerabilities, documenting technical exploitation steps, and providing recommendations and remediations. 

The successful candidate will work closely with IT Engineering, Security Operations, and Infrastructure teams to ensure that security controls are effectively implemented and maintained across LME’s platforms.

Key Responsibilities:

Penetration Testing & Security Assessments

  • Participate in offensive assessments (red team, penetration testing, breach and attack simulation, bug bounty) and defensive security operations (threat hunting, incident handling, investigation and forensics, detection engineering) for LME systems and infrastructure;
  • Support security incidents and act as stretch capacity for incident response and threat handling; Participate with on-call duties and after-hours support of incident management for incident escalations;
  • Participate in Red/Blue Team testing, identify gaps/weaknesses in monitoring capabilities and recommend/implement changes;
  • Review intelligence feeds and generate advisories as needed. Stay up-to-date with current and emerging trends that represent a threat to LME;
  • Support threat hunting based on the defined threat model and specific attack scenarios. Perform analysis of existing data to discover patterns, and build use cases to detect malicious activity;
  • Optimise detection and response rules; Support the testing and recertify SIEM rules against threat models and detection frameworks;

Security Engineering & Automation

  • Assist in the deployment and maintenance of security tools and platforms (e.g., E-Mail Security, DLP, SIEM, Endpoint Protection).
  • Develop and support the automation of security tools, configuration, and updates using scripting (e.g. Python, PowerShell, Bash, NPM).
  • Contribute to Infrastructure as Code (IaC) efforts using Terraform or Ansible.
  • Help monitor and maintain secure configurations across Windows, Linux, and Kubernetes environments.

Operational Support

  • Provide support for incident response and troubleshooting related to security tooling and access controls.
  • Provide support for Red/Blue team testing and penetration testing.
  • Help maintain documentation, standards, and procedures related to security engineering and platform protection.
  • Participate in on-call and weekend support rotations as needed

Qualifications / Skills Required:

  • Desirable: A University degree or equivalent qualifications in a STEM subject such as Computer Science, or Engineering and/or Information Systems.
  • Desirable: Entry-level certifications such as CompTIA Security+, Microsoft SC-900, or AWS Cloud Practitioner.
  • Activity on TryHackMe, HackTheBox, and OSCP-related / Red Team training (or some equivalent the named platforms).
  • Demonstrable activity on Github showing code, tools development, and/or contributing to projects and repos in the offensive security space.

Required Knowledge and Experience:

  • Up to 2 years of experience in IT, security engineering, or DevOps (internships or academic projects included).
  • Basic understanding of:
    • Ethnical Hacking & Penetration Testing
  • Networking and security protocols (TCP/IP, HTTPS, DNS, Firewalls, Proxy).
    • Operating systems (Windows, Linux/Unix, Kubernetes).
    • Scripting or programming (Python, Bash, PowerShell).
    • CI/CD tools and cloud platforms (e.g., Ansible Tower, Bitbucket, Hashicorp Vault, Pipelines, AWS, Azure)
    • Working knowledge of SDLC
    • Security Tooling (e.g. EDR, SIEM, Antivirus)

Personal Qualities:

  • Curiosity about emerging threats and technologies
  • Ability to assess and prioritize tasks/risks
  • Attention to detail
  • Enthusiastic about security engineering and automation.
  • Strong analytical and problem-solving skills.
  • Effective communicator with good documentation habits.
  • Team-oriented, proactive, and adaptable in a fast-paced environment.
  • Willingness to learn and grow within a critical infrastructure environment.
  • Commitment to continuous learning

The LME is committed to creating a diverse environment and is proud to be an equal opportunity employer. In recruiting for our teams, we welcome the unique contributions that you can bring in terms of education, ethnicity, race, sex, gender identity, expression and reassignment, nation of origin, age, languages spoken, colour, religion, disability, sexual orientation and beliefs. In doing so, we want every LME employee to feel our commitment to showing respect for all and encouraging open collaboration and communication.

Top Skills

Ansible
Antivirus
AWS
Azure
Bash
Edr
Powershell
Python
SIEM
Terraform

Similar Jobs

An Hour Ago
Hybrid
Leicester, Leicestershire, England, GBR
Mid level
Mid level
Artificial Intelligence • Hardware • Information Technology • Security • Software • Cybersecurity • Big Data Analytics
Manage client service experiences, resolve critical application issues, conduct root cause analysis, and support continuous service availability through proactive communications and mentorship.
Top Skills: Analytical SoftwareItil MethodologiesTechnical Support Tools
Yesterday
In-Office
West Bromwich, Sandwell, West Midlands, England, GBR
Senior level
Senior level
Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
Manage Aircraft Maintenance and Modification Operations, overseeing maintenance technicians, ensuring safe and efficient execution of aircraft production, and driving successful project delivery.
Top Skills: Aviation Quality AssuranceCaaEasaFaaMaa RegulationSafety Management System
Yesterday
In-Office or Remote
West Bromwich, Sandwell, West Midlands, England, GBR
Mid level
Mid level
Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
The Supplier Quality Specialist will manage a portfolio of suppliers, oversee quality processes, and ensure compliance with standards through inspections and metrics presentations.
Top Skills: 2D Manufacturing Drawings3D Manufacturing DrawingsFaa Type Certificate Process

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account