LRQA
Head of Offensive AI Security & Technical Excellence

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job ID: 44287
Location: Birmingham : 1 Trinity Park : Bi
Position Category: Technical
Position Type: Employee Regular
Head of Offensive AI Security & Technical Excellence
Role Purpose:
A dual-remit role leading LRQA's offensive AI security testing proposition – covering large language model, agent and AI system assessment – while owning technical excellence, methodology and people development across the whole of Offensive Services, including talent mapping and career pathways.
To establish LRQA as a credible authority in offensive AI security, and to increase the talent pool by managing our accelerator programme across the globe including talent mapping and career pathways for other offensive service disciplines.
Working Conditions:
Hybrid or remote, aligned to an LRQA office or home location within one of the delivery regions (UK&I, Greece, US, Mexico, Kuala Lumpur, APAC). Regular domestic and international travel to client sites, LRQA offices and industry events. Occasional out-of-hours and weekend working to meet client testing windows. This is a billable leadership role: the postholder carries a personal utilisation target alongside leadership accountabilities.
Performance Measures:
- Personal utilisation against the 40% target (approximately 8 days per month).
- Service line order intake, revenue and margin against plan.
- Pipeline contribution and win rate on opportunities where the postholder acts as technical sales lead.
- Delivery quality: client satisfaction, report quality, on-time delivery and no material quality escapes.
- Accreditation and scheme compliance status for the service line.
- People: retention, engagement, and completion of the 5x5x5 training model (5 days of allocated training time, £5k of funding and 5 certifications per consultant, per year).
- Contribution to the pooled operating model: consultant cross-skilling and successful redeployment across service lines.
Reporting Structure:
Reports to the Head of Offensive Services. Peer to the Heads of the other four offensive service lines. Leads the team/pod leads and will have consultants reporting to them within the service line and, through them, consultants drawn from a pooled capability of approximately 100 offensive security consultants. Consultants are allocated against demand rather than held permanently within a single service line.
Key Responsibilities:
- Build and own the offensive AI security testing methodology, testing harness, covering LLM, agentic and AI-enabled systems, aligned to OWASP LLM Top 10, NIST AI RMF and emerging regulation including the EU AI Act.
- Own technical standards, peer review, quality assurance and research and development across all offensive service lines, acting as the function's technical authority.
- Act as a technical sales lead: shape scope with clients, support bids and proposals, and present credibly to both technical and executive buyers.
- Lead, develop and retain the pod leads and consultants in the service line, setting technical direction, career pathways and certification plans under the 5x5x5 training model.
- Deliver personally on client engagements to the role's utilisation target, retaining hands-on technical credibility with clients and the team.
- Drive AI-enabled delivery: adopt and govern AI tooling that increases coverage, reduces manual effort and improves output quality, without compromising client confidentiality or testing safety.
- Work with peer Heads to keep consultants fungible across service lines, supporting the pooled resourcing model, cross-skilling and a leveraged delivery mix.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Health & Safety Responsibilities:
- Eliminate or minimise employee exposure to risks by regularly reviewing the health and safety risk register, applying appropriate controls, communicating results of risk assessments, and ensuring health and safety is considered in the planning and execution of all LRQA activities.
- Manage your own, and your team’s, compliance with health and safety rules, instructions, systems and legal requirements to ensure employees are suitably trained and adequate resources are available to work safely.
- Monitor and review health and safety performance, observe safety behaviours in the workplace, taking appropriate corrective and preventative action as necessary and suggesting and implementing improvement activities.
Number of Direct Reports:
To be confirmed – pod/team leads within the service line, plus indirect leadership of consultants allocated from the pooled capability of other consultants across Offensive Services.
Geographic Area of Impact:
Global. Delivery regions currently UK&I, Greece, US, Mexico, Kuala Lumpur and APAC, with clients and engagements worldwide.
Size of Budget:
To be confirmed – service line P&L contribution; budget scale to be confirmed with Finance.
Key Stakeholders:
- Head of Offensive Services
- Heads of the other offensive service lines
- Cyber sales and bid teams
- Delivery operations and resourcing
- Marketing and proposition development
- HR, Reward and Legal
- Clients and prospects
- LRQA AI assurance and certification teams
- Client data science and AI engineering functions
- Research and academic partners
What You'll Bring:
Essential:
- Strong offensive security background with demonstrable AI and machine learning security work, including testing of LLM-based or agentic systems.
- Understanding of model, prompt, data and supply chain attack surfaces.
- Credibility to set technical standards across a multi-discipline offensive function.
- Experience leading technical teams and mentoring/training more junior members of the team to a desired outcome.
Desirable:
- Published AI security research or tooling.
- Familiarity with AI assurance frameworks and regulation.
- Experience introducing AI into delivery workflows at scale.
- Recognised offensive certification such as OSAI, CREST CCT, OSCE3 or equivalent.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Local/Regional Requirements (in addition to those above):
- UK & Ireland: eligibility for UK security clearance (SC as a minimum) where the role supports CHECK, government or CNI-facing work. Right to work in the UK.
- United States and Mexico: eligibility to work in-region and to satisfy client-specific background screening and, where required, US federal or state contractual requirements.
- Greece, Kuala Lumpur and wider APAC: local employment eligibility; regional language capability desirable; awareness of local data protection and testing authorisation requirements.
- All regions: satisfactory background screening in line with LRQA policy and applicable scheme requirements, and the ability to travel internationally.
Who are LRQA?
LRQA is a leading global assurance partner, combining deep industry expertise with innovative solutions to help organizations manage risk, improve performance, and drive sustainable growth.
Operating in over 50 countries with a team of 2,500+ professionals, we support more than 60,000 clients worldwide through assurance, certification, cybersecurity, inspection, and training services. Our purpose is simple: to help businesses build a safer, more secure, and more sustainable future.
What We Offer:
Join a global team where your expertise is valued and your development is supported. We offer a collaborative work environment, opportunities for professional growth, flexible working arrangements where applicable, a competitive salary aligned with the market, and a comprehensive benefits package.
Pre-Employment Checks
If you are successful in securing a role with us, we may carry out pre-employment checks, as permitted by local law, including verification of identity, right to work, employment history, education, and criminal records where applicable.
These checks are conducted by our trusted screening partner, Cfirst, in compliance with applicable data protection laws. Any personal data collected will be used solely for recruitment purposes, stored securely, and retained only as required.
For questions about the screening process, contact Onboarding@lrqa.com
For queries regarding your personal data, contact dataprotection@lrqa.com
At LRQA, we believe that as a leading Global Leading Assurance and Risk Management Service provider, our talented people are our risk management advantage.
We believe the best outcomes come from diverse perspectives, shared ambition and working together with integrity. That's how we build a workplace where everyone can contribute, grow and thrive.
Guided by Vision and powered by Expertise, we're united by a shared purpose. If you're driven to make a difference, you'll belong here.
All rights reserved. Terms of use. Privacy Policy.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London