Lead Security Researcher
Fox-IT
Posted on May 29, 2026
A Lead Security Researcher within the Exploit Development Group (EDG) is responsible for conducting high‑impact vulnerability research and exploit development that advances the state of the art in cybersecurity. The role contributes directly to NCC Group’s reputation as a global authority in security research by delivering original research with deep technical expertise and representing the organisation externally through publications, presentations, and industry engagement. Through both long‑term strategic research and short‑notice tactical support, this role helps protect clients, strengthen NCC Group services and shape the wider security community.
- Department
- Cyber Services and Capabilities
- Employment Type
- Full Time
- Location
- GBR Cheltenham Jessop House
- Workplace type
- Hybrid
- Reporting To
- Alexander Plaskett
Key Responsibilities
- Conduct vulnerability research and exploit development across a range of platforms, architectures, and technologies.
- Deliver high‑quality vulnerabilities and reliable exploits as part of strategic research programmes.
- Provide short‑notice tactical support to consulting, professional, and managed services teams in areas such as reverse engineering and exploit development.
- Advance exploit development techniques and contribute to world‑leading security research.
- Participate in vulnerability research and exploit development competitions, such as Pwn2Own.
- Publish research findings and support their internal and external promotion through articles, whitepapers, presentations, and conference talks.
- Act as a subject matter expert within NCC Group, mentoring and supporting colleagues who are developing skills in vulnerability research and exploitation.
- Collaborate effectively with multi‑disciplinary teams to deliver research and client outcomes to the highest possible standard.
Skills, Knowledge and Expertise
- Strong knowledge of vulnerability research and exploitation techniques.
- Experience with major CPU architectures and operating systems or platforms.
- Ability to reverse engineer software written in both unmanaged and managed languages.
- Understanding of common programming languages, vulnerability classes and exploitation methods.
- Knowledge of modern exploitation mitigations and approaches for bypassing them.
- Ability to research and exploit unfamiliar instruction sets, programming languages and platforms.
- Clear written communication skills for documenting and presenting complex technical findings.
Benefits
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
About NCC Group
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.
With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.
We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.
Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.
We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.
Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles.
If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at: global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Notice.
We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.
Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.
If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at: global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Notice.
We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.
Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.
Not quite right? Register your interest to be notified of any roles that come along that meet your criteria.

