it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

55 jobs found

Email me jobs like this
Refine Search
Current Search
penetration tester
Penetration Tester
Darkshield City, York
About Darkshield Darkshield is an expert cybersecurity agency based in York, UK. We help organisations navigate an increasingly complex digital landscape by providing expert services in penetration testing, vulnerability assessment, managed security, and more. Our mission is to protect businesses by delivering tailored, cutting edge cybersecurity solutions that keep them resilient and ahead of cyber threats. The Role We are looking for an experienced Penetration Tester to join our team. You will conduct security assessments and ethical hacking activities to identify vulnerabilities in client systems. This role requires a deep understanding of attack techniques, security frameworks, and risk mitigation strategies. Key Responsibilities Conduct penetration testing on networks, applications, and infrastructure. Identify, analyse, and report security vulnerabilities. Simulate cyberattacks to evaluate security defences. Develop security testing methodologies and improve existing processes. Collaborate with clients to provide security recommendations and mitigation strategies. Stay up to date with the latest security threats, exploits, and hacking techniques. Assist in security awareness training and red team exercises. Provide clear and actionable reports to both technical and non technical audiences. Requirements Proven experience in penetration testing and ethical hacking. Proficiency in tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Kali Linux. Strong knowledge of web application, network, and infrastructure security. Experience with scripting and automation using Python, Bash, or PowerShell. Certifications such as OSCP, OSCE, CEH, or similar are highly desirable. Understanding of regulatory compliance standards (ISO 27001, GDPR, NIST, etc.). Excellent problem solving skills and attention to detail. Ability to communicate findings and recommendations effectively to clients. Why Join Darkshield? Work with a passionate and expert cybersecurity team. Engage in challenging and diverse projects. Support for professional development, including training and certification assistance. Flexible working arrangements, including remote options. A collaborative and innovative work environment.
27/07/2026
Full time
About Darkshield Darkshield is an expert cybersecurity agency based in York, UK. We help organisations navigate an increasingly complex digital landscape by providing expert services in penetration testing, vulnerability assessment, managed security, and more. Our mission is to protect businesses by delivering tailored, cutting edge cybersecurity solutions that keep them resilient and ahead of cyber threats. The Role We are looking for an experienced Penetration Tester to join our team. You will conduct security assessments and ethical hacking activities to identify vulnerabilities in client systems. This role requires a deep understanding of attack techniques, security frameworks, and risk mitigation strategies. Key Responsibilities Conduct penetration testing on networks, applications, and infrastructure. Identify, analyse, and report security vulnerabilities. Simulate cyberattacks to evaluate security defences. Develop security testing methodologies and improve existing processes. Collaborate with clients to provide security recommendations and mitigation strategies. Stay up to date with the latest security threats, exploits, and hacking techniques. Assist in security awareness training and red team exercises. Provide clear and actionable reports to both technical and non technical audiences. Requirements Proven experience in penetration testing and ethical hacking. Proficiency in tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Kali Linux. Strong knowledge of web application, network, and infrastructure security. Experience with scripting and automation using Python, Bash, or PowerShell. Certifications such as OSCP, OSCE, CEH, or similar are highly desirable. Understanding of regulatory compliance standards (ISO 27001, GDPR, NIST, etc.). Excellent problem solving skills and attention to detail. Ability to communicate findings and recommendations effectively to clients. Why Join Darkshield? Work with a passionate and expert cybersecurity team. Engage in challenging and diverse projects. Support for professional development, including training and certification assistance. Flexible working arrangements, including remote options. A collaborative and innovative work environment.
Lead Penetration Tester - Cloud & App Security
Manchester Digital Manchester, Lancashire
A leading financial technology company in Manchester is seeking an experienced Penetration Tester to conduct assessments on its core banking platform. The role focuses on Cloud and Application Security, requiring strong skills in penetration testing and communication. Candidates should have over 5 years of experience, knowledge of secure code reviews, and proficiency in tools like AWS. The position allows for hybrid working and offers a range of benefits including enhanced pension schemes and private medical insurance.
27/07/2026
Full time
A leading financial technology company in Manchester is seeking an experienced Penetration Tester to conduct assessments on its core banking platform. The role focuses on Cloud and Application Security, requiring strong skills in penetration testing and communication. Candidates should have over 5 years of experience, knowledge of secure code reviews, and proficiency in tools like AWS. The position allows for hybrid working and offers a range of benefits including enhanced pension schemes and private medical insurance.
Senior Penetration Tester
Manchester Digital Manchester, Lancashire
About the Role As an experienced Penetration Tester at Starling, you'll be joining an established team, working with talented cyber security professionals to ensure our services are designed, developed and operated securely. This is a collaborative role - you'll directly interact with multiple areas of the business to understand requirements, conduct research, perform security testing, and report issues aligned to our risk framework. Being an internal tester, you'll gain a strong understanding of how technology works at Starling to enable in-depth testing. You'll also support remediation processes, seeing your findings lead to tangible security improvements. We understand the importance of knowledge and expertise remaining current, so we'll actively support your advancement through research and training. In turn, you'll help us continuously improve our processes, methodologies and tools to maintain the highest standard of testing. Responsibilities Scoping and performing mobile, web application, cloud and infrastructure penetration tests. Collaborating with engineering teams to facilitate secure development, including: Reviewing and analysing proposed technical solutions to identify appropriate security controls. Conducting code reviews of features and critical security components. Performing in-depth practical security testing. Advising on the remediation of security issues and identifying solutions to address root causes. Automating security testing and developing internal tooling to achieve continuous assurance. Identifying and implementing improvements to the team's internal processes and procedures. Mentoring less experienced team members, leading by example in technical assessments, and promoting a collaborative approach to security across Starling. Requirements We're open minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Ideally, we would like: 5+ years technical information security experience. Experience in mobile, web application, cloud and infrastructure penetration testing. Technical knowledge - we don't expect mastery of every area, but are looking for a good foundation in the following domains: Mobile security (iOS and Android) Web application security Networking and associated protocols Cloud security (AWS and GCP) Containers and Kubernetes A desire to learn, and the ability to apply technical security knowledge to new and unfamiliar areas. Penetration testing qualifications (e.g. CREST Certified Tester, OSCP) or equivalent industry experience. Experience performing code reviews or code-assisted testing, particularly in Java and Go. Experience in automation of security testing (e.g. using Python or Go). Excellent verbal and written communication skills. Benefits 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing Equal Opportunity Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
27/07/2026
Full time
About the Role As an experienced Penetration Tester at Starling, you'll be joining an established team, working with talented cyber security professionals to ensure our services are designed, developed and operated securely. This is a collaborative role - you'll directly interact with multiple areas of the business to understand requirements, conduct research, perform security testing, and report issues aligned to our risk framework. Being an internal tester, you'll gain a strong understanding of how technology works at Starling to enable in-depth testing. You'll also support remediation processes, seeing your findings lead to tangible security improvements. We understand the importance of knowledge and expertise remaining current, so we'll actively support your advancement through research and training. In turn, you'll help us continuously improve our processes, methodologies and tools to maintain the highest standard of testing. Responsibilities Scoping and performing mobile, web application, cloud and infrastructure penetration tests. Collaborating with engineering teams to facilitate secure development, including: Reviewing and analysing proposed technical solutions to identify appropriate security controls. Conducting code reviews of features and critical security components. Performing in-depth practical security testing. Advising on the remediation of security issues and identifying solutions to address root causes. Automating security testing and developing internal tooling to achieve continuous assurance. Identifying and implementing improvements to the team's internal processes and procedures. Mentoring less experienced team members, leading by example in technical assessments, and promoting a collaborative approach to security across Starling. Requirements We're open minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Ideally, we would like: 5+ years technical information security experience. Experience in mobile, web application, cloud and infrastructure penetration testing. Technical knowledge - we don't expect mastery of every area, but are looking for a good foundation in the following domains: Mobile security (iOS and Android) Web application security Networking and associated protocols Cloud security (AWS and GCP) Containers and Kubernetes A desire to learn, and the ability to apply technical security knowledge to new and unfamiliar areas. Penetration testing qualifications (e.g. CREST Certified Tester, OSCP) or equivalent industry experience. Experience performing code reviews or code-assisted testing, particularly in Java and Go. Experience in automation of security testing (e.g. using Python or Go). Excellent verbal and written communication skills. Benefits 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing Equal Opportunity Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
Senior Penetration Tester: Cloud Mobile & Web Security
Manchester Digital Manchester, Lancashire
A leading digital bank in Manchester is seeking an experienced Penetration Tester to join their team. You will conduct mobile, web application, cloud, and infrastructure penetration tests while collaborating with engineering teams to enhance security practices. Ideal candidates will have over five years of experience in technical information security, expertise in various security domains, and qualifications like CREST or OSCP. The position includes a range of benefits that support both professional and personal growth.
27/07/2026
Full time
A leading digital bank in Manchester is seeking an experienced Penetration Tester to join their team. You will conduct mobile, web application, cloud, and infrastructure penetration tests while collaborating with engineering teams to enhance security practices. Ideal candidates will have over five years of experience in technical information security, expertise in various security domains, and qualifications like CREST or OSCP. The position includes a range of benefits that support both professional and personal growth.
Penetration Tester - Engine by Starling
Manchester Digital Manchester, Lancashire
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success. Hybrid Working We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. About the Role We are looking for an experienced Penetration Tester who can bridge the gap between deep technical exploitation and real-world business risk. This isn't just about running scanners and handing over a PDF; it's about adversarial empathy, understanding how our systems and services work so you can show us how they may be compromised. While you will sit within the Information Security team, you won't be siloed; you will be "dropped in" to test across various business domains, working side-by-side with Infrastructure Engineers and Software Developers and in collaboration with all parts of the Information Security Team. Your approach is to move beyond finding 'bugs' to helping out teams build inherently resilient systems. As an early member of our internal Pentesting capability, you won't just follow a manual, you will help write it. A key aspect of this role involves: Collaborating with your peers to design a continuous testing framework that evolves with our tech stack. Sharing knowledge with the wider technical faculty to elevate our collective security posture. Additionally, we understand the importance of knowledge and expertise remaining current and you shall support the continued advancement of our penetration testing through research, design and implementation of new solutions, including automation. Responsibilities End-to-End Assessments: Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security. Code Review: Performing manual secure code reviews to identify logic flaws and security anti-patterns. Threat Modelling: Participate in sessions with different teams to identify design flaws before code is written. Risk Contextualisation: Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine's risk management framework. Cloud Security: Collaborating with Infrastructure teams to audit and secure cloud configurations. Autonomous Execution: Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains. Remediation: Providing clear, actionable remediation advice that balances security requirements with engineering velocity. Strategic Reporting: Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership. Requirements We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Technical Skills Ideally, we would like: Experience: 5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs. Tooling: Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail. Cloud Native: Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS. Code Fluency: Ability to conduct code reviews in multiple languages, primarily Java and Go. Mobile: Experience testing Mobile Applications (iOS and Android). SDLC: You have a working understanding of how software is architected, built and deployed. Scripting: You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc. Soft Skills Communication: Exceptional written and spoken communication skills: the ability to communicate complex technical issues to engineers and business risk to executives. Proactivity: A self-starting nature. You don't wait for a ticket to find a vulnerability. Got downtime? You're digging into codebases, closing off retesting items and generally getting it done. Independence: Ability to work independently while remaining a collaborative partner to the wider engineering team. Adaptability: Engine is evolving. You are able to evolve and develop as our requirements shift over time. Nice to have Infrastructure as Code (IaC): Experience auditing Terraform or CloudFormation templates. DevSecOps: Familiarity with integrating security tooling (DAST/SAST) into CI/CD pipelines. 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About Us You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems. Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
27/07/2026
Full time
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success. Hybrid Working We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. About the Role We are looking for an experienced Penetration Tester who can bridge the gap between deep technical exploitation and real-world business risk. This isn't just about running scanners and handing over a PDF; it's about adversarial empathy, understanding how our systems and services work so you can show us how they may be compromised. While you will sit within the Information Security team, you won't be siloed; you will be "dropped in" to test across various business domains, working side-by-side with Infrastructure Engineers and Software Developers and in collaboration with all parts of the Information Security Team. Your approach is to move beyond finding 'bugs' to helping out teams build inherently resilient systems. As an early member of our internal Pentesting capability, you won't just follow a manual, you will help write it. A key aspect of this role involves: Collaborating with your peers to design a continuous testing framework that evolves with our tech stack. Sharing knowledge with the wider technical faculty to elevate our collective security posture. Additionally, we understand the importance of knowledge and expertise remaining current and you shall support the continued advancement of our penetration testing through research, design and implementation of new solutions, including automation. Responsibilities End-to-End Assessments: Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security. Code Review: Performing manual secure code reviews to identify logic flaws and security anti-patterns. Threat Modelling: Participate in sessions with different teams to identify design flaws before code is written. Risk Contextualisation: Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine's risk management framework. Cloud Security: Collaborating with Infrastructure teams to audit and secure cloud configurations. Autonomous Execution: Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains. Remediation: Providing clear, actionable remediation advice that balances security requirements with engineering velocity. Strategic Reporting: Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership. Requirements We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Technical Skills Ideally, we would like: Experience: 5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs. Tooling: Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail. Cloud Native: Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS. Code Fluency: Ability to conduct code reviews in multiple languages, primarily Java and Go. Mobile: Experience testing Mobile Applications (iOS and Android). SDLC: You have a working understanding of how software is architected, built and deployed. Scripting: You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc. Soft Skills Communication: Exceptional written and spoken communication skills: the ability to communicate complex technical issues to engineers and business risk to executives. Proactivity: A self-starting nature. You don't wait for a ticket to find a vulnerability. Got downtime? You're digging into codebases, closing off retesting items and generally getting it done. Independence: Ability to work independently while remaining a collaborative partner to the wider engineering team. Adaptability: Engine is evolving. You are able to evolve and develop as our requirements shift over time. Nice to have Infrastructure as Code (IaC): Experience auditing Terraform or CloudFormation templates. DevSecOps: Familiarity with integrating security tooling (DAST/SAST) into CI/CD pipelines. 25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About Us You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems. Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
Royal London
Penetration Tester - Hybrid Role, Enterprise Security
Royal London
Royal London in Alderley Park (Wilmslow) or Glasgow is seeking a Penetration Tester to join the Attack Surface Management team. Hybrid work (50% home/50% office) and a permanent contract. You will scope, deliver and report on penetration tests across systems, networks and applications, simulating real-world cyber attacks to identify vulnerabilities and strengthen Royal London's defences. Expect to apply ethical hacking practices and communicate risks to stakeholders.
27/07/2026
Full time
Royal London in Alderley Park (Wilmslow) or Glasgow is seeking a Penetration Tester to join the Attack Surface Management team. Hybrid work (50% home/50% office) and a permanent contract. You will scope, deliver and report on penetration tests across systems, networks and applications, simulating real-world cyber attacks to identify vulnerabilities and strengthen Royal London's defences. Expect to apply ethical hacking practices and communicate risks to stakeholders.
Penetration Tester
Darktrace Ltd.
Penetration TesterApplylocations: London Office, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: JR102006Darktrace is a global leader in AI-driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI. Today, our customers depend on us to stay ahead. At Darktrace, we are energized by that responsibility. We work across teams and rally around a shared goal. We own outcomes end to end - step in, step up and see things through without waiting to be asked. We make decisions with urgency, say the hard thing, and hold each other to high standards with care and directness. We move first and learn fast anticipating where our customers are going next, continuously challenging ourselves. We invest in the skills, learning and opportunities that help people deliver at the level their roles demand, and reward the aptitude and curiosity to grow beyond them.Our Values: Own It Win as One Raise Our Bar Move First. Learn Fast Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in the London office. What will I be doing: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments, Simulating real-world attack scenarios to assess system and infrastructure resilience, Producing detailed technical reports and executive summaries for stakeholders, Collaborating with internal teams to validate findings and support remediation efforts, Staying up to date with emerging threats, vulnerabilities, and offensive security techniques. What experience do I need: To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills, The ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.As a growing business strengthening its governance and controls, this role plays a part in supporting high standards of integrity and accountability. Darktrace is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran or military status, or any other characteristic protected by applicable federal, state, or local law. Darktrace is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. If you require a reasonable accommodation to participate in the application or interview process, please contact your Talent Partner. Our Growth is Creating Great Opportunities! Our team is expanding, and we want to hire the most talented people we can. Continued success depends on it! Once you've had a chance to explore our current open positions, apply to the ones you feel suit you best and keep track of both your progress in the selection process, and new postings that might interest you! Thanks for your interest in working on our team!
27/07/2026
Full time
Penetration TesterApplylocations: London Office, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: JR102006Darktrace is a global leader in AI-driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI. Today, our customers depend on us to stay ahead. At Darktrace, we are energized by that responsibility. We work across teams and rally around a shared goal. We own outcomes end to end - step in, step up and see things through without waiting to be asked. We make decisions with urgency, say the hard thing, and hold each other to high standards with care and directness. We move first and learn fast anticipating where our customers are going next, continuously challenging ourselves. We invest in the skills, learning and opportunities that help people deliver at the level their roles demand, and reward the aptitude and curiosity to grow beyond them.Our Values: Own It Win as One Raise Our Bar Move First. Learn Fast Job D escription : As a Penetration Tester within the internal cybersecurity team, you'll play a key role in identifying and mitigating security risks across the organisation's digital landscape. This position requires hands-on experience in offensive security and a deep understanding of network, application, and cloud-based vulnerabilities.You'll be responsible for conducting thorough penetration tests, simulating real-world attacks, and delivering actionable insights to both security and development teams. Collaboration and continuous learning are central to the role, ensuring our defences stay ahead of emerging threats.Please note this is a hybrid role, with a compulsory attendance of 2 days a week in the London office. What will I be doing: Performing penetration tests on web applications, networks, APIs, mobile apps, and cloud environments, Simulating real-world attack scenarios to assess system and infrastructure resilience, Producing detailed technical reports and executive summaries for stakeholders, Collaborating with internal teams to validate findings and support remediation efforts, Staying up to date with emerging threats, vulnerabilities, and offensive security techniques. What experience do I need: To succeed in this role, you'll need a solid background in penetration testing or offensive security, along with hands-on experience using industry-standard tools and frameworks. A strong grasp of security principles and methodologies is essential, as is the ability to communicate findings clearly and effectively. Other qualifications and skills include: Proficiency with tools like Burp Suite, Nmap, Metasploit, Nessus, and Kali Linux, plus scripting skills in Python, Bash, or PowerShell, Strong understanding of OWASP Top 10, MITRE ATT&CK, CVSS scoring, and familiarity with cloud platforms (AWS, Azure, GCP) and container security, Relevant certifications such as OSCP, CREST CRT, or eCPPT are highly desirable, along with excellent written and verbal communication skills, The ability to mentor junior testers and contribute to internal tooling. Benefits: 23 days' holiday + all public holidays, rising to 25 days after 2 years of service, Additional day off for your birthday, Private medical insurance which covers you, your cohabiting partner and children, Life insurance of 4 times your base salary, Salary sacrifice pension scheme, Enhanced family leave, Confidential Employee Assistance Program, Cycle to work scheme.As a growing business strengthening its governance and controls, this role plays a part in supporting high standards of integrity and accountability. Darktrace is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran or military status, or any other characteristic protected by applicable federal, state, or local law. Darktrace is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. If you require a reasonable accommodation to participate in the application or interview process, please contact your Talent Partner. Our Growth is Creating Great Opportunities! Our team is expanding, and we want to hire the most talented people we can. Continued success depends on it! Once you've had a chance to explore our current open positions, apply to the ones you feel suit you best and keep track of both your progress in the selection process, and new postings that might interest you! Thanks for your interest in working on our team!
Penetration Tester - Web, Cloud & App Security (Hybrid)
Darktrace Ltd.
Darktrace Ltd. seeks a Penetration Tester to identify security risks across the organisation's digital landscape. The role focuses on hands-on testing of web apps, networks, APIs, mobile apps and cloud environments, delivering actionable insights to security and development teams. The candidate will simulate real-world attacks, produce technical and executive reports, and mentor junior testers while staying current with emerging threats and attack techniques.
27/07/2026
Full time
Darktrace Ltd. seeks a Penetration Tester to identify security risks across the organisation's digital landscape. The role focuses on hands-on testing of web apps, networks, APIs, mobile apps and cloud environments, delivering actionable insights to security and development teams. The candidate will simulate real-world attacks, produce technical and executive reports, and mentor junior testers while staying current with emerging threats and attack techniques.
Picture More Ltd
Cyber Security Engineer
Picture More Ltd
Overview Cyber Security Engineer - Global Law Firm Hybrid (3 days onsite) Join a global law firm as a hands-on Cyber Security Engineer and play a key role in a growing SecOps function protecting a modern Microsoft and cloud environment. This is a highly technical role focused on incident response, SIEM optimisation, vulnerability management, and security engineering, helping drive a Zero Trust journey and supporting ISO 27001 & CIS controls. Responsibilities Lead and support incident response, threat monitoring and root-cause analysis Tune and optimise SIEM & CrowdStrike EDR for maximum effectiveness Drive vulnerability management, remediation and risk reduction Secure cloud and infrastructure across Intune, Entra ID, Palo Alto, Cisco ISE, Mimecast and more Implement key security controls including MFA, SSO, PAM, WAF, DDoS, VPN & firewalls Collaborate with engineers and penetration testers to strengthen the firm's security posture
26/07/2026
Full time
Overview Cyber Security Engineer - Global Law Firm Hybrid (3 days onsite) Join a global law firm as a hands-on Cyber Security Engineer and play a key role in a growing SecOps function protecting a modern Microsoft and cloud environment. This is a highly technical role focused on incident response, SIEM optimisation, vulnerability management, and security engineering, helping drive a Zero Trust journey and supporting ISO 27001 & CIS controls. Responsibilities Lead and support incident response, threat monitoring and root-cause analysis Tune and optimise SIEM & CrowdStrike EDR for maximum effectiveness Drive vulnerability management, remediation and risk reduction Secure cloud and infrastructure across Intune, Entra ID, Palo Alto, Cisco ISE, Mimecast and more Implement key security controls including MFA, SSO, PAM, WAF, DDoS, VPN & firewalls Collaborate with engineers and penetration testers to strengthen the firm's security posture
Lead Cyber Security Consultant - Remote & Onsite PenTesting
Nomios
Nomios is looking for a skilled Penetration Tester to lead a team and manage client engagements in the UK. The role involves complex infrastructure penetration tests and requires significant experience in the field. Candidates should possess relevant certifications and strong communication skills. This position offers hybrid working options and focuses on professional growth, well-being, and diversity. Join Nomios to contribute to a collaborative technology environment while maintaining high standards.
25/07/2026
Full time
Nomios is looking for a skilled Penetration Tester to lead a team and manage client engagements in the UK. The role involves complex infrastructure penetration tests and requires significant experience in the field. Candidates should possess relevant certifications and strong communication skills. This position offers hybrid working options and focuses on professional growth, well-being, and diversity. Join Nomios to contribute to a collaborative technology environment while maintaining high standards.
Cyber Security Consultant (Penetration Tester)
Moore Kingston Smith LLP
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
25/07/2026
Full time
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
Cyber Security Consultant (Penetration Tester)
Moore Kingston Smith
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
25/07/2026
Full time
Cyber Security Consultant (Penetration Tester) Department: Cyber Employment Type: Permanent - Full Time Location: City, London Compensation: £45,000 - £55,000 / year Description Moore Kingston Smith is seeking an experienced Cyber Security Consultant specialising in penetration testing to join our client-facing advisory team. You will join an NCSC-recognised cyber security team within our Risk Advisory practice, supporting a diverse portfolio of clients across multiple sectors. This is a hands on role focused on delivering penetration tests across web applications, APIs, and internal and external network infrastructure. You will also support Cyber Essentials Plus assessments and wider technical security reviews, including vulnerability assessments, configuration reviews against recognised benchmarks, and cloud security reviews. You will identify and safely validate security weaknesses, explain the associated business risks clearly, and provide practical remediation advice tailored to each client. Technical delivery will account for at least 70% of the role and will remain the core focus. Depending on your experience, interests and business requirements, there may also be opportunities to contribute to broader cyber security engagements, including cyber maturity assessments, security control reviews, audit readiness activities and security design advisory work. Typically, this would represent up to 30% of your time and provides an opportunity to broaden your consulting expertise while supporting clients across a wider range of security challenges. We are looking for a proactive consultant with strong technical fundamentals, sound professional judgement and a genuine interest in helping clients improve their security posture. This role offers the opportunity to deepen your offensive security expertise while contributing to the continued growth of a collaborative and commercially focused cyber security practice. Key Responsibilities Lead and support penetration testing engagements across web applications, APIs, and internal and external network infrastructure. Work with clients to define objectives, agree scope and rules of engagement, and plan testing that meets their assurance needs. Apply manual and tool assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting clients through to certification in line with current NCSC and IASME scheme requirements. Deliver wider technical security assessments, including vulnerability assessments, cloud security reviews, and build and configuration reviews against CIS Benchmarks and vendor hardening guidance. Produce clear, high quality deliverables and present findings to technical and non technical stakeholders. Apply appropriate risk ratings, explain business impact, and support clients with remediation and retesting. Support general advisory engagements such as cyber risk assessments, security control reviews, audit readiness, remediation planning and security design advice. Build strong client relationships and contribute to business development, supporting proposals, scoping, tenders and thought leadership, and identifying opportunities to expand our services. Maintain current knowledge of the threat landscape, emerging attack techniques, testing methodologies, and scheme requirements, while contributing to peer review and quality assurance. Contribute to the continuous improvement of our methodologies, tooling, delivery processes, and technical capability. Skills, Knowledge and Expertise Essential Professional experience delivering client facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and/or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux, Burp Suite, Nmap, and Qualys or Nessus. Familiarity with recognised penetration testing methodologies and frameworks, together with the ability to script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP/IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments such as vulnerability assessments and configuration reviews against recognised benchmarks such as CIS. Working knowledge of the Cyber Essentials and Cyber Essentials Plus schemes. Existing assessor experience is beneficial; appropriate training will be provided where required. Ability to manage engagements within agreed scope, rules of engagement, timescales, budget, and quality standards, while maintaining clear testing evidence and protecting client systems and data. Strong written communication skills, including the ability to produce clear, accurate, and actionable technical reports. Strong verbal communication and stakeholder management skills, with the ability to explain technical findings, risk, and business impact to technical and non technical audiences. A proactive, client oriented mindset and a commitment to continuous learning, confident working with clients ranging from SMEs and scale ups to larger enterprises. Desirable A recognised practical penetration testing certification, such as CREST CRT, OSCP, OSWE, CSTM or an equivalent qualification. Experience in additional testing disciplines such as mobile application, wireless or cloud penetration testing, or phishing and social engineering assessments. Experience with public cloud and SaaS platforms such as AWS, Azure, GCP or Microsoft 365, or hands on security or IT engineering experience such as hardening systems and implementing technical controls. An interest in, or experience of, broader advisory work such as cyber risk assessments, security control reviews, audit readiness, or working knowledge of a recognised framework such as ISO/IEC 27001, NIST, or CIS Controls. Benefits
Penetration tester
AMARIS GROUP SA Rocester, Staffordshire
Job description You will join Amaris Consulting within our Automotive teams in Rocester. Responsibilities 1) Penetration testing and adversarial assessment Plan and execute penetration tests on the products with digital elements: ECUs, telematics units, in vehicle networks (CAN, J1939, LIN), diagnostic interfaces (UDS/OBD), bootloaders, connected services and mobile/cloud backends. Use threat intelligence and TARA outputs to prioritise attack paths and test scenarios. Conduct hardware level assessments: JTAG/UART access, debug interface analysis, firmware extraction and analysis, side channel awareness. Test software components, APIs, update mechanisms and cryptographic implementations as required. 2) Testing evidence and programme assurance Produce clear, technically detailed reports: vulnerability description, reproduction steps, severity rating, affected products/versions, and recommended remediation. Ensure test outputs meet the coverage and evidence expectations defined by the Senior Engineer - Cybersecurity Compliance for programme assurance. Align findings with ISO/SAE 21434 verification and validation requirements and relevant compliance evidence packs. 3) Collaboration with vulnerability management Feed confirmed findings directly into the vulnerability management process, with sufficient detail for triage, CVSS scoring and remediation tracking. Support the Vulnerability Management Engineer in assessing exploitability of CVEs or supplier reported issues where hands on validation is needed. Contribute to SBOM informed testing priorities as component level intelligence evolves. Capture lessons learned from test engagements and feed them into internal standards, TARA guidance and cybersecurity requirements. Stay current with automotive and embedded system attack research, tooling, CVE/CWE trends and threat actor techniques relevant to off highway machinery. Support uplift of engineering teams through knowledge sharing on common vulnerability patterns and secure design. Qualifications and experience Essential Hands on penetration testing experience in embedded systems, OT/ICS, automotive or connected products (3+ years) Practical experience with automotive protocols: CAN, J1939, LIN, UDS, OBD II Hardware assessment skills: JTAG, UART, logic analysis, firmware extraction Familiarity with ISO/SAE 21434 and its verification and validation requirements Ability to write clear, technically precise test reports that engineers and compliance stakeholders can both use Strong analytical approach: rigorous, evidence based, reproducible Desired Experience in Tier 1 or OEM sectors (on highway or off highway) Knowledge of IEC 62443 and CRA requirements, including Article 14 reporting context Familiarity with TARA and threat modelling outputs (attack trees, STRIDE, EVITA) Experience with tools such as CANalyzer, Wireshark, IDA Pro, Ghidra, Burp Suite, OpenOCD, GreatFET or equivalent Awareness of SBOM formats and their role in vulnerability identification Relevant certifications: OSCP, CEH, or automotive/embedded specific equivalents (e.g. TÜV Rheinland Cybersecurity) About you You're methodical. You document everything and your reports are good enough to hold up in a compliance audit. You're curious. You read CVE disclosures, follow automotive security research, and probably have test hardware at home. You can work across disciplines. Engineering, compliance, suppliers, sometimes legal. You adapt the message without losing the accuracy. You're pragmatic. You understand that findings need to land somewhere useful, and you care about closure as much as discovery. What We Offer An international community bringing together 110+ different nationalities. An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities. A robust training system with our internal Academy and 250+ available modules. A vibrant workplace that frequently gathers for internal events, including afterworks and team buildings. The opportunity to contribute to high impact governance, assurance, and change initiatives for key clients. At Mantu, sustainability is part of everything we do. You'll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you'll be empowered to design and lead projects that create real social or environmental impact, with the company's full support. Who are we? Amaris Consulting is an independent technology consulting firm providing guidance and solutions to businesses. With more than 1000 clients across the globe, we have been rolling out solutions in major projects for over a decade - this is made possible by an international team of 7,600 people spread across 5 continents and more than 60 countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We're focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your stepping stone to cross rivers of change, meet challenges and achieve all your projects with success. Amaris Consulting is proud to be an equal opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.
25/07/2026
Full time
Job description You will join Amaris Consulting within our Automotive teams in Rocester. Responsibilities 1) Penetration testing and adversarial assessment Plan and execute penetration tests on the products with digital elements: ECUs, telematics units, in vehicle networks (CAN, J1939, LIN), diagnostic interfaces (UDS/OBD), bootloaders, connected services and mobile/cloud backends. Use threat intelligence and TARA outputs to prioritise attack paths and test scenarios. Conduct hardware level assessments: JTAG/UART access, debug interface analysis, firmware extraction and analysis, side channel awareness. Test software components, APIs, update mechanisms and cryptographic implementations as required. 2) Testing evidence and programme assurance Produce clear, technically detailed reports: vulnerability description, reproduction steps, severity rating, affected products/versions, and recommended remediation. Ensure test outputs meet the coverage and evidence expectations defined by the Senior Engineer - Cybersecurity Compliance for programme assurance. Align findings with ISO/SAE 21434 verification and validation requirements and relevant compliance evidence packs. 3) Collaboration with vulnerability management Feed confirmed findings directly into the vulnerability management process, with sufficient detail for triage, CVSS scoring and remediation tracking. Support the Vulnerability Management Engineer in assessing exploitability of CVEs or supplier reported issues where hands on validation is needed. Contribute to SBOM informed testing priorities as component level intelligence evolves. Capture lessons learned from test engagements and feed them into internal standards, TARA guidance and cybersecurity requirements. Stay current with automotive and embedded system attack research, tooling, CVE/CWE trends and threat actor techniques relevant to off highway machinery. Support uplift of engineering teams through knowledge sharing on common vulnerability patterns and secure design. Qualifications and experience Essential Hands on penetration testing experience in embedded systems, OT/ICS, automotive or connected products (3+ years) Practical experience with automotive protocols: CAN, J1939, LIN, UDS, OBD II Hardware assessment skills: JTAG, UART, logic analysis, firmware extraction Familiarity with ISO/SAE 21434 and its verification and validation requirements Ability to write clear, technically precise test reports that engineers and compliance stakeholders can both use Strong analytical approach: rigorous, evidence based, reproducible Desired Experience in Tier 1 or OEM sectors (on highway or off highway) Knowledge of IEC 62443 and CRA requirements, including Article 14 reporting context Familiarity with TARA and threat modelling outputs (attack trees, STRIDE, EVITA) Experience with tools such as CANalyzer, Wireshark, IDA Pro, Ghidra, Burp Suite, OpenOCD, GreatFET or equivalent Awareness of SBOM formats and their role in vulnerability identification Relevant certifications: OSCP, CEH, or automotive/embedded specific equivalents (e.g. TÜV Rheinland Cybersecurity) About you You're methodical. You document everything and your reports are good enough to hold up in a compliance audit. You're curious. You read CVE disclosures, follow automotive security research, and probably have test hardware at home. You can work across disciplines. Engineering, compliance, suppliers, sometimes legal. You adapt the message without losing the accuracy. You're pragmatic. You understand that findings need to land somewhere useful, and you care about closure as much as discovery. What We Offer An international community bringing together 110+ different nationalities. An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities. A robust training system with our internal Academy and 250+ available modules. A vibrant workplace that frequently gathers for internal events, including afterworks and team buildings. The opportunity to contribute to high impact governance, assurance, and change initiatives for key clients. At Mantu, sustainability is part of everything we do. You'll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you'll be empowered to design and lead projects that create real social or environmental impact, with the company's full support. Who are we? Amaris Consulting is an independent technology consulting firm providing guidance and solutions to businesses. With more than 1000 clients across the globe, we have been rolling out solutions in major projects for over a decade - this is made possible by an international team of 7,600 people spread across 5 continents and more than 60 countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We're focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your stepping stone to cross rivers of change, meet challenges and achieve all your projects with success. Amaris Consulting is proud to be an equal opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.
Automotive Embedded Security Penetration Tester
AMARIS GROUP SA Rocester, Staffordshire
Amaris Consulting, Rocester, UK, is seeking a cybersecurity tester specialized in embedded automotive systems. You will perform penetration testing on ECUs, CAN/J1939 networks, and OTA/update mechanisms, producing precise reports for engineering and compliance teams. Responsibilities include evidence driven testing, applying ISO/SAE 21434 standards, and contributing to vulnerability management triage while staying abreast of automotive threat research and best practices.
25/07/2026
Full time
Amaris Consulting, Rocester, UK, is seeking a cybersecurity tester specialized in embedded automotive systems. You will perform penetration testing on ECUs, CAN/J1939 networks, and OTA/update mechanisms, producing precise reports for engineering and compliance teams. Responsibilities include evidence driven testing, applying ISO/SAE 21434 standards, and contributing to vulnerability management triage while staying abreast of automotive threat research and best practices.
National Physical Laboratory
Senior Penetration Tester: Telecoms & Hardware Security Lead
National Physical Laboratory Birmingham, Staffordshire
National Physical Laboratory is seeking a senior security tester to lead assessments of complex hardware, software, and telecoms systems. You will perform hands-on penetration testing in an in-house lab, using advanced techniques including fuzzing, and clearly communicate vulnerabilities to diverse audiences. You will develop automation scripts, generate remediation-focused reports, and mentor junior colleagues while helping shape the overall testing strategy and security posture of the
25/07/2026
Full time
National Physical Laboratory is seeking a senior security tester to lead assessments of complex hardware, software, and telecoms systems. You will perform hands-on penetration testing in an in-house lab, using advanced techniques including fuzzing, and clearly communicate vulnerabilities to diverse audiences. You will develop automation scripts, generate remediation-focused reports, and mentor junior colleagues while helping shape the overall testing strategy and security posture of the
National Physical Laboratory
Senior Penetration Tester
National Physical Laboratory Birmingham, Staffordshire
About the Role Salary for UKTL specialist roles are benchmarked against the external market and may include additional compensation to recognise in-demand technical expertise. Dive Deep. Make an Impact. Build Secure Systems. You're driven by curiosity and a desire to understand how things really work - and how they can be made more secure. Whether dissecting telecoms protocols, exploring enterprise systems, or analysing hardware, you take a hands-on, analytical approach to solving complex challenges. In this role, you'll join a collaborative and inclusive team where your expertise is valued, your ideas are heard, and your work directly contributes to strengthening real-world systems. You'll have the freedom to explore, experiment, and grow - while helping shape the security of next-generation networks. As a senior member of the team, you'll also play an important role in supporting and mentoring others, helping to develop the next generation of security testing specialists. What You'll Be Doing Lead and deliver security assessments across complex hardware, software, and telecoms systems. Conduct hands-on penetration testing within a dedicated in-house lab environment, ensuring safe and controlled testing. Apply advanced testing techniques - including both positive and negative approaches (e.g. fuzzing) - to rigorously assess network functions and protocols. Identify, investigate, and clearly articulate vulnerabilities and security risks to both technical and non-technical audiences. Develop scripts and automate testing processes to improve efficiency, consistency, and scalability. Produce high-quality, insightful technical reports that support remediation and strengthen security posture. Mentor and support junior team members through hands-on guidance and knowledge sharing. Contribute to the development of test strategies and help shape the direction of security assessments. Successful Applicants must be able to commute to the UKTL offices in Birmingham at least twice a week We strive to offer a great work life balance - if you are looking for full time, part time or flexible options, we will try to make this work where business possible. This will be dependent on the kind of role you do and part of the business you work in. About You You'll thrive in this role if you: Have strong experience in penetration testing, with a solid understanding of exploitation techniques and how they apply in real-world environments. Enjoy deep technical problem solving and working across complex, evolving systems. Bring a collaborative mindset - sharing knowledge, supporting others, and contributing fresh ideas. Are passionate about security testing and committed to continuous learning and staying ahead of emerging threats. Have a background in areas such as networking, infrastructure, software development, or telecoms (preferred but not essential). What You'll Learn You'll bring solid experience - and we'll help you take it even further. Whether you already have knowledge of telecoms protocols such as Diameter, HTTP/2, SCTP, and NGAP, or demonstrate a strong ability to learn them quickly, we'll support your growth every step of the way. You'll gain access to leading training platforms and work towards industry-recognised certifications, helping you continuously develop your expertise. We actively recruit citizens of all backgrounds, but the nature of our work in this specific area means that nationality, residency and security requirements are more tightly defined than others. To work in this role, you will need to hold an SC clearance with no restrictions. You are welcome to apply without already holding SC clearance; however, you will not be able to start in post until the clearance has been successfully granted. About Us UKTL is building leading edge Telecoms testing facilities to keep our telecommunications networks safe, accelerate the roll-out of new technologies, and grow our world leading telecoms sector to maintain resiliency and security. Successful candidates will join a state-of-the-art facility and be supporting the team conducting testing and research on the latest technologies and innovations in the industry. You will work alongside our infrastructure and Cybersecurity professionals to ensure that the UK's world class Telecoms infrastructure grows in a resilient and secure manner underpinning growth in other industry sectors. As a trusted and independent national capability, UKTL interacts with standards bodies, Academia, and Government Departments as well as Communications Service Providers and equipment vendors. The National Physical Laboratory (NPL) is a world-leading centre of excellence that provides cutting-edge measurement science, engineering and technology to underpin prosperity and quality of life in the UK. Find out more about what it is like working here - The measure of us - Overview. NPL and DSIT have strong commitments to diversity and equality of opportunity, and welcome applications from candidates irrespective of their background, gender, race, sexual orientation, religion, or age, providing they meet the required criteria. Applications from women, disabled and black, Asian and minority ethnic candidates in particular are encouraged. All disabled candidates (as defined by the Equality Act 2010) who satisfy the minimum criteria for the role will be guaranteed an interview under the Disability Confident Scheme. At NPL, we believe our success is a result of the diversity and talent of our people. We strive to nurture and respect individuals to ensure everyone feels valued by treating everyone on the basis of their own individual merits and abilities regardless of their own or perceived identity, as part of our commitment to diversity & inclusion, we ensure we're creating an environment where all our colleagues feel supported and welcome. More about this on our Diversity & Inclusion page. We offer a wealth of above industry standard benefits, such as enhanced pension scheme, flexible working, and more that can be found here. Our values are at the heart of what we do, and they shape the way we interact, develop our people and celebrate success. To ensure everyone has an equal chance, we're always willing to make reasonable adjustments to the recruitment process. If you would like to discuss, please contact us.
25/07/2026
Full time
About the Role Salary for UKTL specialist roles are benchmarked against the external market and may include additional compensation to recognise in-demand technical expertise. Dive Deep. Make an Impact. Build Secure Systems. You're driven by curiosity and a desire to understand how things really work - and how they can be made more secure. Whether dissecting telecoms protocols, exploring enterprise systems, or analysing hardware, you take a hands-on, analytical approach to solving complex challenges. In this role, you'll join a collaborative and inclusive team where your expertise is valued, your ideas are heard, and your work directly contributes to strengthening real-world systems. You'll have the freedom to explore, experiment, and grow - while helping shape the security of next-generation networks. As a senior member of the team, you'll also play an important role in supporting and mentoring others, helping to develop the next generation of security testing specialists. What You'll Be Doing Lead and deliver security assessments across complex hardware, software, and telecoms systems. Conduct hands-on penetration testing within a dedicated in-house lab environment, ensuring safe and controlled testing. Apply advanced testing techniques - including both positive and negative approaches (e.g. fuzzing) - to rigorously assess network functions and protocols. Identify, investigate, and clearly articulate vulnerabilities and security risks to both technical and non-technical audiences. Develop scripts and automate testing processes to improve efficiency, consistency, and scalability. Produce high-quality, insightful technical reports that support remediation and strengthen security posture. Mentor and support junior team members through hands-on guidance and knowledge sharing. Contribute to the development of test strategies and help shape the direction of security assessments. Successful Applicants must be able to commute to the UKTL offices in Birmingham at least twice a week We strive to offer a great work life balance - if you are looking for full time, part time or flexible options, we will try to make this work where business possible. This will be dependent on the kind of role you do and part of the business you work in. About You You'll thrive in this role if you: Have strong experience in penetration testing, with a solid understanding of exploitation techniques and how they apply in real-world environments. Enjoy deep technical problem solving and working across complex, evolving systems. Bring a collaborative mindset - sharing knowledge, supporting others, and contributing fresh ideas. Are passionate about security testing and committed to continuous learning and staying ahead of emerging threats. Have a background in areas such as networking, infrastructure, software development, or telecoms (preferred but not essential). What You'll Learn You'll bring solid experience - and we'll help you take it even further. Whether you already have knowledge of telecoms protocols such as Diameter, HTTP/2, SCTP, and NGAP, or demonstrate a strong ability to learn them quickly, we'll support your growth every step of the way. You'll gain access to leading training platforms and work towards industry-recognised certifications, helping you continuously develop your expertise. We actively recruit citizens of all backgrounds, but the nature of our work in this specific area means that nationality, residency and security requirements are more tightly defined than others. To work in this role, you will need to hold an SC clearance with no restrictions. You are welcome to apply without already holding SC clearance; however, you will not be able to start in post until the clearance has been successfully granted. About Us UKTL is building leading edge Telecoms testing facilities to keep our telecommunications networks safe, accelerate the roll-out of new technologies, and grow our world leading telecoms sector to maintain resiliency and security. Successful candidates will join a state-of-the-art facility and be supporting the team conducting testing and research on the latest technologies and innovations in the industry. You will work alongside our infrastructure and Cybersecurity professionals to ensure that the UK's world class Telecoms infrastructure grows in a resilient and secure manner underpinning growth in other industry sectors. As a trusted and independent national capability, UKTL interacts with standards bodies, Academia, and Government Departments as well as Communications Service Providers and equipment vendors. The National Physical Laboratory (NPL) is a world-leading centre of excellence that provides cutting-edge measurement science, engineering and technology to underpin prosperity and quality of life in the UK. Find out more about what it is like working here - The measure of us - Overview. NPL and DSIT have strong commitments to diversity and equality of opportunity, and welcome applications from candidates irrespective of their background, gender, race, sexual orientation, religion, or age, providing they meet the required criteria. Applications from women, disabled and black, Asian and minority ethnic candidates in particular are encouraged. All disabled candidates (as defined by the Equality Act 2010) who satisfy the minimum criteria for the role will be guaranteed an interview under the Disability Confident Scheme. At NPL, we believe our success is a result of the diversity and talent of our people. We strive to nurture and respect individuals to ensure everyone feels valued by treating everyone on the basis of their own individual merits and abilities regardless of their own or perceived identity, as part of our commitment to diversity & inclusion, we ensure we're creating an environment where all our colleagues feel supported and welcome. More about this on our Diversity & Inclusion page. We offer a wealth of above industry standard benefits, such as enhanced pension scheme, flexible working, and more that can be found here. Our values are at the heart of what we do, and they shape the way we interact, develop our people and celebrate success. To ensure everyone has an equal chance, we're always willing to make reasonable adjustments to the recruitment process. If you would like to discuss, please contact us.
Penetration Tester
Barlowe LLP
We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Role As a Penetration Tester, you will lead and conduct penetration tests and vulnerability assessments across a wide range of internal systems and security controls. Your work will directly strengthen our overall security posture through continuous testing, actionable insights and collaboration on remediation strategies. Responsibilities Perform in-depth penetration testing across a variety of technologies, including Kubernetes, Jenkins and Windows Domain Services. Deliver practical, impactful remediation advice to Control Owners based on identified vulnerabilities. Support business and application owners in assessing and improving the effectiveness of their security controls. Provide technical consulting and assurance to Risk, Compliance and Detection Engineering teams, including control assessments and configuration reviews. Maintain and enhance the team's operational tooling, automation and system integrations. Mentor and support less experienced team members, fostering knowledge sharing and growth. Qualifications Proven expertise across the full penetration testing lifecycle, from scoping and execution to reporting and stakeholder debriefs. Deep understanding of vulnerability assessment practices, including effective remediation strategies for both infrastructure and application level security. Strong background in technical security roles across diverse environments; familiarity with DevOps technologies. Experience validating the effectiveness of security controls through both manual and automated approaches. Engineering experience, particularly in building automation and tooling to streamline team output. Proficiency in development and scripting tools commonly used in DevSecOps, including Python, Jenkins and Ansible. Relevant security certifications with OSCP mandatory and CRT or OSEP desirable. Strong communication and interpersonal skills, with an emphasis on clear and concise written output. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days annual leave and 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. We are committed to cultivating and preserving an inclusive work environment. We value diversity of experience and opinions, and we want to ensure applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section. G Research is passionate about the intersection of finance, technology, and the future. We offer a dynamic, flexible and highly stimulating culture where worlds beating ideas are cultivated and rewarded, and we are proud to employ the best in their field and nurture talent in our collaborative working environment.
25/07/2026
Full time
We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Role As a Penetration Tester, you will lead and conduct penetration tests and vulnerability assessments across a wide range of internal systems and security controls. Your work will directly strengthen our overall security posture through continuous testing, actionable insights and collaboration on remediation strategies. Responsibilities Perform in-depth penetration testing across a variety of technologies, including Kubernetes, Jenkins and Windows Domain Services. Deliver practical, impactful remediation advice to Control Owners based on identified vulnerabilities. Support business and application owners in assessing and improving the effectiveness of their security controls. Provide technical consulting and assurance to Risk, Compliance and Detection Engineering teams, including control assessments and configuration reviews. Maintain and enhance the team's operational tooling, automation and system integrations. Mentor and support less experienced team members, fostering knowledge sharing and growth. Qualifications Proven expertise across the full penetration testing lifecycle, from scoping and execution to reporting and stakeholder debriefs. Deep understanding of vulnerability assessment practices, including effective remediation strategies for both infrastructure and application level security. Strong background in technical security roles across diverse environments; familiarity with DevOps technologies. Experience validating the effectiveness of security controls through both manual and automated approaches. Engineering experience, particularly in building automation and tooling to streamline team output. Proficiency in development and scripting tools commonly used in DevSecOps, including Python, Jenkins and Ansible. Relevant security certifications with OSCP mandatory and CRT or OSEP desirable. Strong communication and interpersonal skills, with an emphasis on clear and concise written output. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days annual leave and 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. We are committed to cultivating and preserving an inclusive work environment. We value diversity of experience and opinions, and we want to ensure applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section. G Research is passionate about the intersection of finance, technology, and the future. We offer a dynamic, flexible and highly stimulating culture where worlds beating ideas are cultivated and rewarded, and we are proud to employ the best in their field and nurture talent in our collaborative working environment.
Lead Penetration Tester - Kubernetes & DevSecOps
Barlowe LLP
G-Research is seeking a hands-on Penetration Tester to lead tests and vulnerability assessments across internal systems and security controls. Your work will strengthen our security posture through continuous testing and remediation collaboration. You will perform tests across Kubernetes, Jenkins and Windows Domain Services, deliver remediation guidance, mentor teammates, and help build automation and tooling with Python, Ansible and related DevSecOps practices.
25/07/2026
Full time
G-Research is seeking a hands-on Penetration Tester to lead tests and vulnerability assessments across internal systems and security controls. Your work will strengthen our security posture through continuous testing and remediation collaboration. You will perform tests across Kubernetes, Jenkins and Windows Domain Services, deliver remediation guidance, mentor teammates, and help build automation and tooling with Python, Ansible and related DevSecOps practices.
Offensive Security Manager
Barlowe LLP
Overview We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Key Responsibilities Leading, developing and growing a team of offensive security engineers and penetration testers. Owning and delivering the offensive security testing programme across the firm's highest priority systems, balancing recurring assessments with testing of new and changing services. Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required. Driving offensive testing methodologies, from scope definition through to safe validation of real world attack paths and control effectiveness. Establishing attack chain validation and continuous purple teaming with detection and response teams. Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling. Overseeing physical and social engineering assessment where appropriate. Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement. Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility. Qualifications Strong hands on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure. Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems. Experience defining testing scope, rules of engagement and threat led, attack chain based assessments. Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing. Experience leading or developing technical teams, including performance management and coaching. Strong judgement in prioritising work, balancing risk, impact and competing demands. Experience building teams and evolving ways of working as the function matures. Strong communication skills, with the ability to explain offensive findings and drive remediation. Ability to influence technical decisions through credibility, evidence and collaboration. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days' annual leave. 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. G-Research is committed to cultivating and preserving an inclusive work environment. We place great value on diversity of experience and opinions and want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section.
25/07/2026
Full time
Overview We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas take time to evolve. Together we're building a world class platform to amplify our teams' most powerful ideas. Security is foundational to this mission and must be delivered in a way that supports how our engineering teams build and operate complex systems at scale. Take the next step in your career. Key Responsibilities Leading, developing and growing a team of offensive security engineers and penetration testers. Owning and delivering the offensive security testing programme across the firm's highest priority systems, balancing recurring assessments with testing of new and changing services. Managing testing intake, prioritisation and resourcing, including coordinating external testing partners where required. Driving offensive testing methodologies, from scope definition through to safe validation of real world attack paths and control effectiveness. Establishing attack chain validation and continuous purple teaming with detection and response teams. Introducing automated assurance capabilities, including breach and attack simulation and adversary emulation tooling. Overseeing physical and social engineering assessment where appropriate. Reporting meaningful security metrics to demonstrate control effectiveness and drive continuous improvement. Building strong working relationships across engineering, risk and incident response teams, communicating findings and influencing decisions through evidence and technical credibility. Qualifications Strong hands on experience in offensive security and penetration testing across networks, web and APIs, cloud and infrastructure. Experience with CI/CD, Kubernetes and identity systems, with exposure to AI or agentic systems. Experience defining testing scope, rules of engagement and threat led, attack chain based assessments. Familiarity with automation, breach and attack simulation tooling or other approaches to scaling offensive testing. Experience leading or developing technical teams, including performance management and coaching. Strong judgement in prioritising work, balancing risk, impact and competing demands. Experience building teams and evolving ways of working as the function matures. Strong communication skills, with the ability to explain offensive findings and drive remediation. Ability to influence technical decisions through credibility, evidence and collaboration. Benefits Highly competitive compensation plus annual discretionary bonus. Lunch provided via Just Eat for Business and dedicated barista bar. 35 days' annual leave. 9% company pension contributions. Informal dress code and excellent work life balance. Comprehensive healthcare and life assurance. Cycle to work scheme. Monthly company events. G-Research is committed to cultivating and preserving an inclusive work environment. We place great value on diversity of experience and opinions and want to ensure that applicants receive a recruitment experience that enables them to perform at their best. If you have a disability or special need that requires accommodation, please let us know in the relevant section.
Senior/Principal Penetration Tester / Experienced Red Team Consultant
Rootshell Security
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.
23/07/2026
Full time
Senior/Principal Penetration Tester / Experienced Red Team Consultant Testing Team United Kingdom Remote working options Full Time About the role Rootshell Security is seeking an experienced Senior / Principal Penetration Tester / Red Team Consultant to join our rapidly expanding Offensive Security team. This role is suited to a highly capable security professional with extensive experience delivering complex penetration testing and adversary simulation engagements across a range of sectors, including critical national infrastructure, financial services, and government organisations. You will be responsible for delivering advanced Red Team operations, intelligence-led security assessments, and bespoke attack simulations that help our clients understand their true resilience against modern threat actors. The position involves a combination of remote engagements and on site client activities across the United Kingdom. Rootshell Security is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status. Please do not apply if you are based outside the UK and/or are not eligible to apply for UK Security Clearance. Role responsibilities Lead and deliver advanced penetration testing and Red Team engagements Conduct intelligence-led adversary emulation and attack simulation exercises Deliver engagements aligned to recognised frameworks including TIBER-EU, CBEST, DORA, GBEST and STAR-FS Perform threat led security assessments against complex enterprise environments Develop Red Team infrastructure, tooling, attack paths and operational plans Conduct phishing, social engineering and physical assessment activities where authorised Support pre sales activities including technical scoping and solution design Produce high-quality technical reports and executive level findings Contribute to the development of Rootshell Security methodologies, research and innovation Skills we are looking for Mandatory Requirements Must be eligible to apply for UK Security Clearance Must be permanently based within the United Kingdom Must have several years of provable commercial experience delivering Red Team engagements Excellent working knowledge of the MITRE ATT&CK Framework Demonstrable experience delivering engagements aligned to TIBER-EU, CBEST, DORA and other threat led testing frameworks Strong knowledge of adversary emulation, attack path development and operational security Excellent report writing and client communication skills Strong network, infrastructure, Active Directory and cloud attack experience Experience operating against Azure, AWS and hybrid enterprise environments Certifications Must hold or have previously held a recognised Red Team certification demonstrating advanced offensive security capability, Typically CREST or CyberScheme Currently holds or has held Team Leader certifications in either Infrastructure and/or Applications Currently holds professional title of Principal / Chartered or would be eligible to apply Social engineering and phishing operation experience Physical intrusion testing experience Threat intelligence and Purple Team experience Malware analysis or custom tooling development Experience briefing senior stakeholders and board level audiences Proficiency in Python, PowerShell or C# development Company benefits Long-term career progression opportunities Continuous technical and non-technical training Regular attendance at industry conferences, events and community meetups Exposure to a diverse range of engagements across multiple sectors Dedicated research and innovation time Opportunity to influence Rootshell's offensive security capabilities and methodologies Mentoring and career development from senior leadership Recognition and reward for innovation, technical excellence and client impact Equality, Diversity, and Inclusion at Rootshell Security We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We believe that a diverse team drives innovation and excellence, and we welcome applications from individuals of all backgrounds, experiences, and perspectives. As a proud holder of the Bronze Award under the Defence Employer Recognition Scheme (ERS), we actively support the Armed Forces community, aligning with the principles of the Armed Forces Covenant. We recognise the valuable skills and experiences that service personnel, reservists, and veterans bring to the workplace and encourage them to apply. Rootshell Security is an equal opportunities employer. We do not discriminate based on age, disability, gender, gender identity, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sexual orientation, or any other characteristic protected by law. If you require any reasonable adjustments during the recruitment process, please let us know-we are happy to support you.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board