ESHAY ADVISORY
The Eshay Advisory team working through a client architecture

Home  /  Careers

Join us

We hire for judgement.

Tooling can be taught. Knowing which finding matters to this business, this quarter, cannot. If that distinction is the part of the work you enjoy, we should talk.

Why here

A small firm, deliberately.

We are structured small and senior because that is what lets one person hold a risk committee in the morning and a code review in the afternoon.

We enjoy the problems that don't have an obvious answer. If your first instinct is to understand the organisation before reaching for a framework, you'll probably enjoy working here.

Work that matters

Real environments under real pressure — critical infrastructure, regulated data, systems people depend on.

Seniority, shared

A small team where the person who scoped the engagement delivers it, and mentoring is not a side activity.

Time to go deep

Certifications, conferences and research time, because depth is the product we sell.

Flexible by default

Remote-friendly, flexible hours, and two offices to work from when proximity helps.

Find the answer, not the obvious one.

We don't expect consultants to apply playbooks. We expect them to question assumptions, adapt existing solutions and design new approaches when needed.

Straight terms

Competitive compensation, health cover and performance-based bonus. Stated plainly at the first conversation.

Open positions

Three roles, open now.

Each is a real vacancy on a live team, not a permanent advert.

Full-time · Remote · Senior

Senior Penetration Tester

You'll decide what actually matters. Some engagements need deep exploitation. Others need restraint. We're looking for someone who knows the difference.

  • 5+ years in penetration testing
  • Strong command of OWASP, NIST and MITRE ATT&CK
  • OSCP, OSCE, CEH or equivalent
  • Able to explain an exploit chain to a non-technical executive
Apply for this role
Full-time · Hybrid · Mid-Senior

Salesforce Security Consultant

Run Salesforce security assessments, design the remediation, and help clients secure the platform their business runs on.

  • We care more about the judgement behind your decisions than the number beside your CV.
  • Salesforce certification (Administrator, Advanced Administrator or Security)
  • Working knowledge of GDPR and ISO 27001
  • Comfortable in both a config screen and a governance meeting
Apply for this role
Full-time · Remote · Mid

Security Compliance Analyst

Support audits and gap analyses, and help organisations meet SOC 2, ISO 27001 and GDPR obligations without drowning in paperwork.

  • 2+ years in security compliance or audit
  • Solid grasp of the major frameworks and what they actually require
  • Documentation and communication as a genuine strength
  • Judgement about which findings matter this quarter
Apply for this role
How we hire

Four conversations, no puzzles.

We do not run whiteboard algorithm tests. We look at work you have actually done.

01 / SCREEN

A real conversation

Thirty minutes with someone who does the job, not with a recruiter reading a script.

02 / DEPTH

Something you built or broke

Walk us through real work — an engagement, a tool, a finding. We go as deep as you can.

03 / JUDGEMENT

A scenario with no clean answer

A client situation where every option costs something. We are listening for how you decide.

04 / TERMS

Straight numbers

Scope, compensation and expectations stated plainly. No exploding offers.

Don't see your role?

Write to us with what you have actually built or broken. A CV alone tells us very little — the work tells us everything.