Skip to main content

Careers

Senior work, protected research time, no utilisation theatre.

We hire consultants who want to stay technical. That means engagements staffed properly, report writing inside the billed window, and one day in ten set aside for research that is yours to publish.

01Open roles

Four roles open across the practice.

All roles are permanent and remote within UK and EU time zones. If none of them fit but you think we should talk anyway, send a general application.

  • Application and cloud

    Senior Penetration Tester

    You will lead application and cloud engagements end to end: scoping calls with the client, hands-on testing, report authoring, and the walkthrough where their engineers ask hard questions. We expect you to hold an opinion about severity and defend it.

    Location
    Remote, UK or EU time zones
    Commitment
    Full time
    Apply for this role

    What you will do

    • Run web, API and cloud engagements from scoping through to retest
    • Author reports that an engineer can act on without a follow-up call
    • Peer review a colleague's report before it leaves the practice
    • Mentor consultants earlier in their career during shared engagements

    What we look for

    • Several years of hands-on testing experience across web, API and at least one major cloud platform
    • Comfortable reading source code in one or more of JavaScript, Python, Go, Java or C#
    • Able to explain a complex finding to a sceptical engineering audience
    • OSCP, OSWE, CRT or equivalent demonstrable experience
  • Adversary simulation

    Red Team Operator

    You will plan and run goal-based engagements against monitored environments, build and maintain the infrastructure that supports them, and sit with client defenders afterwards to rebuild the attack path with them.

    Location
    Remote, UK or EU time zones
    Commitment
    Full time
    Apply for this role

    What you will do

    • Plan objectives, infrastructure and tradecraft for long-running engagements
    • Develop and maintain tooling, keeping operational security intact throughout
    • Run controlled social engineering within the agreed rules of engagement
    • Lead purple team replay sessions and write detection recommendations

    What we look for

    • Demonstrable red team experience against environments with active monitoring
    • Strong Active Directory and Windows internals knowledge
    • Development ability in C, C# or Rust for tooling and payload work
    • Sound judgement about risk to the client, especially under time pressure
  • Vulnerability research

    Exploit Research Engineer

    You will take vulnerability research from initial hypothesis to reliable proof-of-concept against client software, appliances and embedded devices, then work with vendors through coordinated disclosure.

    Location
    Remote, UK or EU time zones
    Commitment
    Full time
    Apply for this role

    What you will do

    • Reverse engineer binaries, firmware and bespoke network protocols
    • Build reliable proof-of-concept exploits and document their constraints
    • Assess exploitability against mitigations already deployed in the target
    • Support coordinated disclosure and validate vendor patches

    What we look for

    • Practical experience with memory corruption or equivalent low-level vulnerability classes
    • Fluency with a disassembler and debugger of your choice
    • Comfortable in C and at least one scripting language
    • Published research, CVEs or a portfolio you can talk through under NDA
  • Education

    Security Training Lead

    You will build and deliver our hands-on training: lab environments modelled on client stacks, secure code review clinics, and threat modelling workshops. You will still test, because material written by someone who has stopped testing goes stale quickly.

    Location
    Remote, with occasional onsite delivery
    Commitment
    Full time
    Apply for this role

    What you will do

    • Design lab environments that mirror real client architectures
    • Deliver workshops remotely and onsite to mixed technical audiences
    • Turn anonymised engagement findings into teaching material
    • Spend part of your time on live engagements to keep the material current

    What we look for

    • Testing background with genuine teaching or facilitation experience
    • Able to hold a room of sceptical senior engineers for a full day
    • Comfortable building and maintaining deliberately vulnerable environments
    • Clear written English for exercises, notes and post-session summaries

02Working here

The conditions that make good testing possible.

  • Research time that is actually protected

    One day in ten is yours for research, tooling or certification study. It is scheduled into the delivery calendar, not squeezed around it.

  • Utilisation targets that leave room to think

    We staff engagements so that report writing and peer review sit inside the billed window rather than in your evenings.

  • Training and conference budget

    An annual budget for courses, certifications and conferences, with the time off to use it rather than burning annual leave.

  • Publish what you find

    Research you conduct here is yours to present and publish, subject only to client confidentiality and coordinated disclosure timelines.

  • Remote by default, together on purpose

    The team is distributed across UK and EU time zones, with the whole practice meeting in person twice a year.

  • Salary bands are agreed before the technical exercise, not after the final conversation. We will tell you the range in the first call.

03How we hire

Four conversations, one paid exercise, a decision either way.

  1. 01

    Introduction call

    Forty five minutes with the practice lead. What you have worked on, what you want to work on next, and what we actually do day to day. No whiteboard puzzles.

  2. 02

    Technical exercise

    A scoped, take-home exercise against a lab environment, timeboxed to four hours. We pay for your time on it. You keep the write-up.

  3. 03

    Technical discussion

    Two consultants walk through your exercise with you, then through a finding from your own past work that you can discuss without breaching confidentiality.

  4. 04

    Offer and references

    A decision within five working days of the final conversation, with feedback either way. References taken only after you have accepted in principle.

04Apply

Send it to the people who will read it.

Applications go straight to the practice lead. No applicant tracking system, no automated rejection, and a reply within five working days whatever the answer.

Prefer email? Write to engage@nullpath.security with the role in the subject line. Please do not send client-confidential material in either channel.

Optional. Anything public that shows how you work.

Tell us about a piece of work you are proud of and what you want to do more of. Please keep anything confidential out of this field.

Fields marked*are required. We reply to every application.