
Senior Penetration Tester
- United Kingdom
- Permanent
- Full-time
- Conduct comprehensive penetration tests: Execute internal and external network penetration tests, web application penetration tests, mobile application penetration tests, API penetration tests, cloud security assessments, and social engineering simulations.
- Vulnerability identification and analysis: Research, identify, and exploit security vulnerabilities in a variety of systems and applications.
- Red/Purple/Blue Teaming: participate in exercises with the goal of increasing cyber resilience for both offensive and defensive.
- Reporting and documentation: Prepare detailed and professional penetration test reports, including executive summaries, technical findings, risk ratings, and actionable recommendations for remediation.
- Collaboration and communication: Work closely with development, operations, and security teams to communicate findings, explain risks, and provide guidance on remediation strategies.
- Tooling and methodology enhancement: Continuously research and evaluate new penetration testing tools, techniques, and methodologies to improve testing efficiency and effectiveness.
- Security awareness: Contribute to the development and delivery of security awareness training for internal staff.
- Stay current: Keep abreast of the latest security threats, vulnerabilities, exploits, and industry best practices.
- Threat modelling: Participate in threat modelling exercises to identify potential attack vectors and design flaws.
- Ad-hoc security testing: Perform ad-hoc security assessments and provide expert advice on security-related matters as needed.
- OSCP, PNPT or equivalent certification
- At least three years' experience working full-time as a penetration tester on the following areas as a minimum:
- Infrastructure
- Active Directory networks
- Web Application penetration testing
- Cloud security (Entra ID/Azure)
- IoT
- mobile
- physical security / social engineering
- Ability to develop custom tools, or adapt existing tooling for the task at hand
- Demonstrable experience contributing to open-source tools
- Bachelor's degree in Cybersecurity, Information Technology, or a related field.