ESHAY ADVISORY
The Eshay Advisory team working through a client architecture

Home  /  Careers

Join us

We hire for judgement.

Tooling can be taught. Knowing which finding matters to this business, this quarter, cannot. If you're driven more by solving the right problem than following the usual playbook, we should talk.

Why here

A small firm, deliberately.

We are structured small and senior because that is what lets one person hold a risk committee in the morning and a code review in the afternoon.

We enjoy the problems that don't have an obvious answer. If your first instinct is to understand the organisation before reaching for a framework, you'll probably enjoy working here.

Work that matters

Real environments under real pressure — critical infrastructure, regulated data, systems people depend on.

Seniority, shared

A small team where the person who scoped the engagement delivers it, and mentoring is not a side activity.

Time to go deep

Certifications, conferences and research time, because depth is the product we sell.

Flexible by default

Remote-friendly, flexible hours, and two offices to work from when proximity helps.

Find the answer, not the obvious one.

We don't expect consultants to apply playbooks. We expect them to question assumptions, adapt existing solutions and design new approaches when needed.

Straight terms

Competitive compensation, health cover and performance-based bonus. Stated plainly at the first conversation.

Open positions

Three roles, open now.

Each is a real vacancy on a live team, not a permanent advert.

Full-time · Remote · Senior

Senior Penetration Tester

We care less about certifications than about curiosity. Show us the lab you built, the CTFs you solved, the research you published, the tool you wrote, or the bug that kept you awake until you understood it. You'll lead complex engagements, focus on what actually matters, and help clients make better security decisions.

  • Strong practical penetration testing experience
  • Clear communication and sound judgement
  • Evidence of continuous learning beyond the day job
  • Able to translate technical findings into business decisions
Apply for this role
Full-time · Hybrid · Mid-Senior

Salesforce Security Consultant

Salesforce security isn't about finding misconfigurations. It's about understanding how an organisation actually uses the platform, then finding the right way to secure it. You'll assess environments, recommend practical improvements, and help clients implement solutions that fit their business.

  • Strong Salesforce security experience
  • Salesforce certification (Administrator, Advanced Administrator or Security)
  • Familiar with GDPR, ISO 27001 and governance practices
  • Comfortable with both technical configuration and executive discussions
Apply for this role
Full-time · Remote · Mid

Security Compliance Analyst

Frameworks are the starting point, not the objective. You'll help organisations turn compliance into practical security, focusing on the controls that reduce risk instead of creating paperwork.

  • Experience with security audits or compliance programs
  • Solid understanding of major security frameworks
  • Strong communication and documentation skills
  • Sound judgement and a pragmatic approach
Apply for this role
How we hire

Four conversations, no puzzles.

We do not run whiteboard algorithm tests. We look at work you have actually done.

01 / SCREEN

A real conversation

Thirty minutes with someone who does the job, not with a recruiter reading a script.

02 / DEPTH

Something you built or broke

Walk us through real work — an engagement, a tool, a finding. We go as deep as you can.

03 / JUDGEMENT

A scenario with no clean answer

A client situation where every option costs something. We are listening for how you decide.

04 / TERMS

Straight numbers

Scope, compensation and expectations stated plainly. No exploding offers.

Don't see your role?

Write to us with what you have actually built or broken. A CV alone tells us very little — the work tells us everything.